Pub. L. 111-383, div. A, tit. IX, subtit. D, sec. 931
CONTINUOUS MONITORING OF DEPARTMENT OF DEFENSE INFORMATION SYSTEMS FOR CYBERSECURITY.
SEC. 931. CONTINUOUS MONITORING OF DEPARTMENT OF DEFENSE INFORMATION SYSTEMS FOR CYBERSECURITY.(a) In General.—The Secretary of Defense shall direct the Chief Information Officer of the Department of Defense to work, in coordination with the Chief Information Officers of the military departments and the Defense Agencies and with senior cybersecurity and information assurance officials within the Department of Defense and otherwise within the Federal Government, to achieve, to the extent practicable, the following:(1) The continuous prioritization of the policies, principles, standards, and guidelines developed under section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) with agencies and offices operating or exercising control of national security systems (including the National Security Agency) based upon the evolving threat of information security 124 STAT. 4335 incidents with respect to national security systems, the vulnerability of such systems to such incidents, and the consequences of information security incidents involving such systems.(2) The automation of continuous monitoring of the effectiveness of the information security policies, procedures, and practices within the information infrastructure of the Department of Defense, and the compliance of that infrastructure with such policies, procedures, and practices, including automation of—(A) management, operational, and technical controls of every information system identified in the inventory required under section 3505(c) of title 44, United States Code; and(B) management, operational, and technical controls relied on for evaluations under section 3545 of title 44, United States Code.(b) Definitions.—In this section:(1) The term “information security incident” means an occurrence that—(A) actually or potentially jeopardizes the confidentiality, integrity, or availability of an information system or the information such system processes, stores, or transmits; or(B) constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies with respect to an information system.(2) The term “information infrastructure” means the underlying framework, equipment, and software that an information system and related assets rely on to process, transmit, receive, or store information electronically.(3) The term “national security system” has the meaning given that term in section 3542(b)(2) of title 44, United States Code.