Pub. L. 107-217, tit. XIV, subtit. III, ch. 113, subch. III, sec. 11332
Federal computer system security training and plan
§ 11332. Federal computer system security training and plan (a) Definitions.—In this section, the terms “computer system”, “federal agency”, “federal computer system”, “operator of a federal computer system”, and “sensitive information” have the meanings given those terms in section 20(d) of the National Institute of Standards and Technology Act (15 U.S.C. 278g-3(d)). (b) Training.— (1) In general.—Each federal agency shall provide for mandatory periodic training in computer security awareness and accepted computer security practice of all employees who are involved with the management, use, or operation of each federal computer system within or under the supervision of the agency. The training shall be- (A) provided in accordance with the guidelines developed pursuant to section 20(a)(5) of the Act (15 U.S.C. 278g-3(a)(5)) and the regulations prescribed under paragraph (3) for federal civilian employees; or (B) provided by an alternative training program that the head of the agency approves after determining that the alternative training program is at least as effective in accomplishing the objectives of the guidelines and regulations. (2) Training objectives.—Training under this subsection shall be designed— (A) to enhance employees’ awareness of the threats to, and vulnerability of, computer systems; and (B) to encourage the use of improved computer security practices. (3) Regulations.—The Director of the Office of Personnel Management shall maintain regulations that establish the procedures and scope of the training to be provided federal civilian employees under this subsection and the manner in which the training is to be carried out. (c) Plan.— (1) In general.—Consistent with standards, guidelines, policies, and regulations prescribed pursuant to section 11331 of this title, each federal agency shall maintain a plan for the security and privacy of each federal computer system the agency identifies as being within or under its supervision and as containing sensitive information. The plan must be commensurate with the risk and magnitude of the harm resulting from the loss, misuse, or unauthorized access to, or modification of, the information contained in the system. (2) Revision and review.—The plan shall be revised annually as necessary and is subject to disapproval by the Director of the Office of Management and Budget. 116 STAT. 1245 (d) Handling of Information Not Affected.—This section does not— (1) constitute authority to withhold information sought pursuant to section 552 of title 5; or (2) authorize a federal agency to limit, restrict, regulate, or control the collection, maintenance, disclosure, use, transfer, or sale of any information (regardless of the medium in which the information may be maintained) that is— (A) privately owned information; (B) disclosable under section 552 of title 5 or another law requiring or authorizing the public disclosure of information; or (C) public domain information.