Pub. L. 116-283, div. A, tit. XVII, sec. 1727 (as amended)

REPORTING REQUIREMENTS FOR CROSS DOMAIN INCIDENTS AND EXEMPTIONS TO POLICIES FOR INFORMATION TECHNOLOGY.

Year: 2025Length: 333 wordsOfficial source
SEC. 1727. [10 U.S.C. 2224 note] REPORTING REQUIREMENTS FOR CROSS DOMAIN INCIDENTS AND EXEMPTIONS TO POLICIES FOR INFORMATION TECHNOLOGY. (a) Incident Reporting.— (1) In general.—Effective beginning on the date of the enactment of this Act, the Secretary of Defense and the secretaries of the military services shall submit to the congressional defense committees a monthly report in writing that documents each instance or indication of a cross-domain incident within the Department of Defense. (2) Procedures.—The Secretary of Defense shall submit to the congressional defense committees procedures for complying with the requirements of paragraph (1) consistent with the national security of the United States and the protection of operational integrity. The Secretary shall promptly notify such committees in writing of any changes to such procedures at least 14 days prior to the adoption of any such changes. (3) Definition.—In this subsection, the term “cross domain incident” means any unauthorized connection of any duration between software, hardware, or both that is either used on, or designed for use on a network or system built for classified data, and systems not accredited or authorized at the same or higher classification level, including systems on the public internet, regardless of whether the unauthorized connection is later determined to have resulted in the exfiltration, exposure, or spillage of data across the cross domain connection. (b) Exemptions to Policy for Information Technology.—Not later than six months after the date of the enactment of this Act and biannually thereafter, the Secretary of Defense and the secretaries of the military services shall submit to the congressional defense committees a report in writing that enumerates and details each current exemption to information technology policy, interim Authority To Operate (ATO) order, or both. Each such report shall include other relevant information pertaining to each such exemption, including relating to the following: (1) Risk categorization. (2) Duration. (3) Estimated time remaining. (c) Termination Date.—The requirement of the Secretary of Defense to submit a monthly report under subsection (a) shall terminate on December 31, 2025.
Cross-references to the US Code
10 U.S.C. 2224 note
Pub. L. 116-283, div. A, tit. XVII, sec. 1727 (as amended): REPORTING REQUIREMENTS FOR CROSS DOMAIN INCIDENTS AND EXEMPTIONS TO POLICIES FOR INFORMATION TECHNOLOGY. | Justis AI