Pub. L. 110-417, tit. II, subtit. E, sec. 254

TRUSTED DEFENSE SYSTEMS.

EnactedYear: 2008Length: 834 wordsOfficial source
SEC. 254. TRUSTED DEFENSE SYSTEMS.(a) Vulnerability Assessment Required.—The Secretary of Defense shall conduct an assessment of selected covered acquisition programs to identify vulnerabilities in the supply chain of each program’s electronics and information processing systems that potentially compromise the level of trust in the systems. Such assessment shall—(1) identify vulnerabilities at multiple levels of the electronics and information processing systems of the selected programs, including microcircuits, software, and firmware;(2) prioritize the potential vulnerabilities and effects of the various elements and stages of the system supply chain to identify the most effective balance of investments to minimize the effects of compromise;(3) provide recommendations regarding ways of managing supply chain risk for covered acquisition programs; and(4) identify the appropriate lead person, and supporting elements, within the Department of Defense for the development of an integrated strategy for managing risk in the supply chain for covered acquisition programs.(b) Assessment of Methods for Verifying the Trust of Semiconductors Procured From Commercial Sources.—The Under Secretary of Defense for Acquisition, Technology, and Logistics, in consultation with appropriate elements of the Department of Defense, the intelligence community, private industry, and academia, shall conduct an assessment of various methods of verifying the trust of semiconductors procured by the Department of Defense from commercial sources for use in mission-critical components of potentially vulnerable defense systems. The assessment shall include the following:(1) An identification of various methods of verifying the trust of semiconductors, including methods under development at the Defense Agencies, government laboratories, institutions of higher education, and in the private sector.(2) A determination of the methods identified under paragraph (1) that are most suitable for the Department of Defense.(3) An assessment of the additional research and technology development needed to develop methods of verifying the trust of semiconductors that meet the needs of the Department of Defense.(4) Any other matters that the Under Secretary considers appropriate.(c) Strategy Required.—(1) In general.—The lead person identified under subsection (a)(4), in cooperation with the supporting elements also identified under such subsection, shall develop an integrated strategy—122 STAT. 4403(A) for managing risk—(i) in the supply chain of electronics and information processing systems for covered acquisition programs; and(ii) in the procurement of semiconductors; and(B) that ensures dependable, continuous, long-term access and trust for all mission-critical semiconductors procured from both foreign and domestic sources.(2) Requirements.—At a minimum, the strategy shall—(A) address the vulnerabilities identified by the assessment under subsection (a);(B) reflect the priorities identified by such assessment;(C) provide guidance for the planning, programming, budgeting, and execution process in order to ensure that covered acquisition programs have the necessary resources to implement all appropriate elements of the strategy;(D) promote the use of verification tools, as appropriate, for ensuring trust of commercially acquired systems;(E) increase use of trusted foundry services, as appropriate; and(F) ensure sufficient oversight in implementation of the plan.(d) Policies and Actions for Assuring Trust in Integrated Circuits.—Not later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall—(1) develop policy requiring that trust assurance be a high priority for covered acquisition programs in all phases of the electronic component supply chain and integrated circuit development and production process, including design and design tools, fabrication of the semiconductors, packaging, final assembly, and test;(2) develop policy requiring that programs whose electronics and information systems are determined to be vital to operational readiness or mission effectiveness are to employ trusted foundry services to fabricate their custom designed integrated circuits, unless the Secretary specifically authorizes otherwise;(3) incorporate the strategies and policies of the Department of Defense regarding development and use of trusted integrated circuits into all relevant Department directives and instructions related to the acquisition of integrated circuits and programs that use such circuits; and(4) take actions to promote the use and development of tools that verify the trust in all phases of the integrated circuit development and production process of mission-critical parts acquired from non-trusted sources.(e) Submission to Congress.—Not later than 12 months after the date of the enactment of this Act, the Secretary of Defense shall submit to the congressional defense committees—(1) the assessments required by subsections (a) and (b);(2) the strategy required by subsection (c); and(3) a description of the policies developed and actions taken under subsection (d).(f) Definitions.—In this section:(1) The term “covered acquisition programs” means an acquisition program of the Department of Defense that is a major system for purposes of section 2302(5) of title 10, United States Code.122 STAT. 4404(2) The terms “trust” and “trusted” refer, with respect to electronic and information processing systems, to the ability of the Department of Defense to have confidence that the systems function as intended and are free of exploitable vulnerabilities, either intentionally or unintentionally designed or inserted as part of the system at any time during its life cycle.(3) The term “trusted foundry services” means the program of the National Security Agency and the Department of Defense, or any similar program approved by the Secretary of Defense, for the development and manufacture of integrated circuits for critical defense systems in secure industrial environments.
Pub. L. 110-417, tit. II, subtit. E, sec. 254: TRUSTED DEFENSE SYSTEMS. | Justis AI