Pub. L. 111-383, div. A, tit. II, subtit. B, sec. 215

DEMONSTRATION AND PILOT PROJECTS ON CYBERSECURITY.

EnactedYear: 2011Length: 654 wordsOfficial source
SEC. 215. DEMONSTRATION AND PILOT PROJECTS ON CYBERSECURITY.(a) Demonstration Projects on Processes for Application of Commercial Technologies to Cybersecurity Requirements.—(1) Projects required.—The Secretary of Defense and the Secretaries of the military departments shall jointly carry out demonstration projects to assess the feasibility and advisability of using various business models and processes to rapidly and effectively identify innovative commercial technologies and apply such technologies to Department of Defense and other cybersecurity requirements.(2) Scope of projects.—Any demonstration project under paragraph (1) shall be carried out in such a manner as to contribute to the cyber policy review of the President and the Comprehensive National Cybersecurity Initiative.(b) Pilot Programs on Cybersecurity Required.—The Secretary of Defense shall support or conduct pilot programs on cybersecurity with respect to the following areas:(1) Threat sensing and warning for information networks worldwide.(2) Managed security services for cybersecurity within the defense industrial base, military departments, and combatant commands.(3) Use of private processes and infrastructure to address threats, problems, vulnerabilities, or opportunities in cybersecurity.(4) Processes for securing the global supply chain.(5) Processes for threat sensing and security of cloud computing infrastructure.(c) Reports.—124 STAT. 4166(1) Reports required.—Not later than 240 days after the date of the enactment of this Act, and annually thereafter at or about the time of the submittal to Congress of the budget of the President for a fiscal year (as submitted pursuant to section 1105(a) of title 31, United States Code), the Secretary of Defense shall, in coordination with the Secretary of Homeland Security, submit to Congress a report on any demonstration projects carried out under subsection (a), and on the pilot projects carried out under subsection (b), during the preceding year.(2) Elements.—Each report under this subsection shall include the following:(A) A description and assessment of any activities under the demonstration projects and pilot projects referred to in paragraph (1) during the preceding year.(B) For the pilot projects supported or conducted under subsection (b)(2)—(i) a quantitative and qualitative assessment of the extent to which managed security services covered by the pilot project could provide effective and affordable cybersecurity capabilities for components of the Department of Defense and for entities in the defense industrial base, and an assessment whether such services could be expanded rapidly to a large scale without exceeding the ability of the Federal Government to manage such expansion; and(ii) an assessment of whether managed security services are compatible with the cybersecurity strategy of the Department of Defense with respect to conducting an active, in-depth defense under the direction of United States Cyber Command.(C) For the pilot projects supported or conducted under subsection (b)(3)—(i) a description of any performance metrics established for purposes of the pilot project, and a description of any processes developed for purposes of accountability and governance under any partnership under the pilot project; and(ii) an assessment of the role a partnership such as a partnership under the pilot project would play in the acquisition of cyberspace capabilities by the Department of Defense, including a role with respect to the development and approval of requirements, approval and oversight of acquiring capabilities, test and evaluation of new capabilities, and budgeting for new capabilities.(D) For the pilot projects supported or conducted under subsection (b)(4)—(i) a framework and taxonomy for evaluating practices that secure the global supply chain, as well as practices for securely operating in an uncertain or compromised supply chain;(ii) an assessment of the viability of applying commercial practices for securing the global supply chain; and124 STAT. 4167(iii) an assessment of the viability of applying commercial practices for securely operating in an uncertain or compromised supply chain.(E) For the pilot projects supported or conducted under subsection (b)(5)—(i) an assessment of the capabilities of Federal Government providers to offer secure cloud computing environments; and(ii) an assessment of the capabilities of commercial providers to offer secure cloud computing environments to the Federal Government.(3) Form.—Each report under this subsection shall be submitted in unclassified form, but may include a classified annex.
Pub. L. 111-383, div. A, tit. II, subtit. B, sec. 215: DEMONSTRATION AND PILOT PROJECTS ON CYBERSECURITY. | Justis AI