Pub. L. 110-422, tit. X, sec. 1001
REVIEW OF INFORMATION SECURITY CONTROLS.
SEC. 1001. REVIEW OF INFORMATION SECURITY CONTROLS.(a) Report on Controls.—Not later than one year after the date of enactment of this Act, the Comptroller General shall transmit to the Committee on Science and Technology of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate a review of information security controls that protect NASA’s information technology resources and information from inadvertent or deliberate misuse, fraudulent use, disclosure, modification, or destruction. The review shall focus on networks servicing NASA’s mission directorates. In assessing these controls, the review shall evaluate—(1) the network’s ability to limit, detect, and monitor access to resources and information, thereby safeguarding and protecting them from unauthorized access;(2) the physical access to network resources; and(3) the extent to which sensitive research and mission data is encrypted.(b) Restricted Report on Intrusions.—Not later than one year after the date of enactment of this Act, and in conjunction with the report described in subsection (a), the Comptroller General shall transmit to the Committee on Science and Technology of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate a restricted report detailing results of vulnerability assessments conducted by the Government Accountability Office on NASA’s network resources. Intrusion attempts during such vulnerability assessments shall be divulged to NASA senior management prior to their application. The report shall put vulnerability assessment results in the context of unauthorized accesses or attempts during the prior two years and the corrective actions, recent or ongoing, that NASA has implemented in conjunction with other Federal authorities to prevent such intrusions.