Pub. L. 114-113, div. N, tit. IV, sec. 406 (as amended)

FEDERAL COMPUTER SECURITY.

Year: 2026Length: 576 wordsOfficial source
SEC. 406. FEDERAL COMPUTER SECURITY. (a) Definitions.—In this section: (1) Covered system.—The term “covered system” shall mean a national security system as defined in section 11103 of title 40, United States Code, or a Federal computer system that provides access to personally identifiable information. (2) Covered agency.—The term “covered agency” means an agency that operates a covered system. (3) Logical access control.—The term “logical access control” means a process of granting or denying specific requests to obtain and use information and related information processing services. (4) Multi-factor authentication.—The term “multi-factor authentication” means the use of not fewer than 2 authentication factors, such as the following: (A) Something that is known to the user, such as a password or personal identification number. (B) An access device that is provided to the user, such as a cryptographic identification device or token. (C) A unique biometric characteristic of the user. (5) Privileged user.—The term “privileged user” means a user who has access to system control, monitoring, or administrative functions. (b) Inspector General Reports on Covered Systems.— (1) In general.—Not later than 240 days after the date of enactment of this Act, the Inspector General of each covered agency shall submit to the appropriate committees of jurisdiction in the Senate and the House of Representatives a report, which shall include information collected from the covered agency for the contents described in paragraph (2) regarding the Federal computer systems of the covered agency. (2) Contents.—The report submitted by each Inspector General of a covered agency under paragraph (1) shall include, with respect to the covered agency, the following: (A) A description of the logical access policies and practices used by the covered agency to access a covered system, including whether appropriate standards were followed. (B) A description and list of the logical access controls and multi-factor authentication used by the covered agency to govern access to covered systems by privileged users. (C) If the covered agency does not use logical access controls or multi-factor authentication to access a covered system, a description of the reasons for not using such logical access controls or multi-factor authentication. (D) A description of the following information security management practices used by the covered agency regarding covered systems: (i) The policies and procedures followed to conduct inventories of the software present on the covered systems of the covered agency and the licenses associated with such software. (ii) What capabilities the covered agency utilizes to monitor and detect exfiltration and other threats, including— (I) data loss prevention capabilities; (II) forensics and visibility capabilities; or (III) digital rights management capabilities. (iii) A description of how the covered agency is using the capabilities described in clause (ii). (iv) If the covered agency is not utilizing capabilities described in clause (ii), a description of the reasons for not utilizing such capabilities. (E) A description of the policies and procedures of the covered agency with respect to ensuring that entities, including contractors, that provide services to the covered agency are implementing the information security management practices described in subparagraph (D). (3) Existing review.—The reports required under this subsection may be based in whole or in part on an audit, evaluation, or report relating to programs or practices of the covered agency, and may be submitted as part of another report, including the report required under section 3555 of title 44, United States Code. (4) Classified information.—Reports submitted under this subsection shall be in unclassified form, but may include a classified annex.
Pub. L. 114-113, div. N, tit. IV, sec. 406 (as amended): FEDERAL COMPUTER SECURITY. | Justis AI