Pub. L. 111-383, div. A, tit. IX, subtit. D, sec. 935
REPORTS ON DEPARTMENT OF DEFENSE PROGRESS IN DEFENDING THE DEPARTMENT AND THE DEFENSE INDUSTRIAL BASE FROM CYBER EVENTS.
SEC. 935. REPORTS ON DEPARTMENT OF DEFENSE PROGRESS IN DEFENDING THE DEPARTMENT AND THE DEFENSE INDUSTRIAL BASE FROM CYBER EVENTS.(a) Reports on Progress Required.—Not later than 180 days after the date of the enactment of this Act, and March 1 every year thereafter through 2015, the Secretary of Defense shall submit to the congressional defense committees a report on the progress of the Department of Defense in defending the Department and the defense industrial base from cyber events (such as attacks, intrusions, and theft).(b) Elements.—Each report under subsection (a) shall include the following:(1) In the case of the first report, a baseline for measuring the progress of the Department of Defense in defending the Department and the defense industrial base from cyber events, including definitions of significant cyber events, an appropriate categorization of various types of cyber events, the basic methods used in various cyber events, the vulnerabilities exploited in such cyber events, and the metrics to be utilized to determine whether the Department is or is not making progress against an evolving cyber threat.(2) An ongoing assessment of such baseline against key cyber defense strategies (described in subsection (c)) to determine implementation progress.(3)(A) A description of the nature and scope of significant cyber events against the Department and the defense industrial base during the preceding year, including, for each such event, a description of the intelligence or other Department data acquired, the extent of the corruption or compromise of Department information or weapon systems, and the impact of such event on the Department generally and on operational capabilities.(B) For any such event that has been investigated by or on behalf of the Damage Assessment Management Office, 124 STAT. 4340 a synopsis of each damage assessment report, with emphasis on actions needing remediation.(4) A comparative assessment of the offensive cyber warfare capabilities of current representative potential United States adversaries and nations with advanced cyber warfare capabilities with the capacity of the United States to defend—(A) military networks and mission capabilities; and(B) critical infrastructure.(5) A comparative assessment of the offensive cyber warfare capabilities of the United States with the capacity of current representative potential United States adversaries and nations with advanced cyber warfare capabilities to defend against cyber attacks.(6) A comparative assessment of the degree of dependency of current representative potential United States adversaries, nations with advanced cyber warfare capabilities, and the United States on networks that can be attacked through cyberspace.(7) A description of known or suspected identified supply chain vulnerabilities, including known or suspected supply chain attacks, and actions to remediate such vulnerabilities.(c) Key Cyber Defense Strategies.—For purposes of subsection (b)(2), key cyber defense strategies include the following:(1) Relevant valid Homeland Security Presidential Directives and National Security Presidential Directives.(2) The Comprehensive National Cybersecurity Initiative.(3) The National Military Strategy for Cyberspace Operations implementation plan.(d) Performance of Certain Assessments.—The comparative assessment of critical infrastructure required by subsection (b)(4)(B) shall be performed by the Secretary of Homeland Security, in coordination with the Secretary of Defense and the heads of other agencies of the Government with specific responsibility for critical infrastructure.(e) Form.—Each report under this section shall be submitted in unclassified form, but may include a classified annex.