Pub. L. 114-328, div. A, tit. XVI, subtit. C, sec. 1649 (as amended)

EVALUATION OF CYBER VULNERABILITIES OF F-35 AIRCRAFT AND SUPPORT SYSTEMS.

Year: 2025Length: 329 wordsOfficial source
SEC. 1649. EVALUATION OF CYBER VULNERABILITIES OF F-35 AIRCRAFT AND SUPPORT SYSTEMS. (a) Evaluation and Report.— (1) Evaluation.—Not later than 120 days after the date of the enactment of this Act, the Secretary of Defense shall complete an evaluation of the cyber vulnerabilities of the F-35 aircraft and the support systems of the aircraft under section 1647(a)(1) of the National Defense Authorization Act for Fiscal Year 2016 (Public Law 114-92; 129 Stat. 1118). (2) Report.—Not later than 180 days after the date of the enactment of this Act, the Secretary shall submit to the congressional defense committees a report on the evaluation completed under paragraph (1) that includes— (A) the findings of the Secretary with respect to the evaluation; (B) identification of any major information assurance deficiencies relating to the F-35 aircraft or the support systems of the aircraft (including the autonomic logistics information system); and (C) a cyber vulnerability mitigation strategy for F-35 aircraft and the support systems of the aircraft. (3) Waiver prohibited.—Notwithstanding section 1647(a)(2) of the National Defense Authorization Act for Fiscal Year 2016 (Public Law 114-92; 129 Stat. 1118), the Secretary may not waive the requirements of paragraphs (1) and (2). (b) [10 U.S.C. 2224 note] Tools and Solutions for Assessing and Mitigating Cyber Vulnerabilities.—Section 1647 of the National Defense Authorization Act for Fiscal Year 2016 (Public Law 114-92; 129 Stat. 1118) is amended— (1) by redesignating subsections (d) and (e) as subsections (e) and (f), respectively; and (2) by inserting after subsection (c) the following new subsection: “(d) Tools and Solutions for Assessing and Mitigating Cyber Vulnerabilities. In addition to carrying out the evaluation of cyber vulnerabilities of major weapon systems of the Department under this section, the Secretary may— “(1) develop tools to improve the detection and evaluation of cyber vulnerabilities; “(2) conduct non-recurring engineering for the design of solutions to mitigate cyber vulnerabilities; and “(3) establish Department-wide information repositories to share findings relating to the evaluation and mitigation of cyber vulnerabilities.” .
Cross-references to the US Code
10 U.S.C. 2224 note
Public laws referenced
114-92
Pub. L. 114-328, div. A, tit. XVI, subtit. C, sec. 1649 (as amended): EVALUATION OF CYBER VULNERABILITIES OF F-35 AIRCRAFT AND SUPPORT SYSTEMS. | Justis AI