Pub. L. 107-314, div. A, tit. III, subtit. F, sec. 352
POLICY REGARDING ACQUISITION OF INFORMATION ASSURANCE AND INFORMATION ASSURANCE-ENABLED INFORMATION TECHNOLOGY PRODUCTS.
SEC. 352. POLICY REGARDING ACQUISITION OF INFORMATION ASSURANCE AND INFORMATION ASSURANCE-ENABLED INFORMATION TECHNOLOGY PRODUCTS. (a) Establishment of Policy.—The Secretary of Defense shall establish a policy to limit the acquisition of information assurance and information assurance-enabled information technology products to those products that have been evaluated and validated in accordance with appropriate criteria, schemes, or programs. (b) Waiver.—As part of the policy, the Secretary of Defense shall authorize specified officials of the Department of Defense to waive the limitations of the policy upon a determination in writing that application of the limitations to the acquisition of a particular information assurance or information assurance-enabled information technology product would not be in the national security interest of the United States. (c) Implementation.—The Secretary of Defense shall ensure that the policy is uniformly implemented throughout the Department of Defense.