Pub. L. 116-283, div. A, tit. XVII, sec. 1747 (as amended)
ENSURING CYBER RESILIENCY OF NUCLEAR COMMAND AND CONTROL SYSTEM.
SEC. 1747. [10 U.S.C. 499 note] ENSURING CYBER RESILIENCY OF NUCLEAR COMMAND AND CONTROL SYSTEM.
(a) Plan for Implementation of Findings and Recommendations From First Annual Assessment of Cyber Resiliency of Nuclear Command and Control System.—Not later than October 1, 2021, the Secretary of Defense shall submit to the congressional defense committees a comprehensive plan, including a schedule and resourcing plan, for the implementation of the findings and recommendations included in the first report submitted under section 499(c)(3) of title 10, United States Code.
(b) Concept of Operations and Oversight Mechanism for Cyber Defense of Nuclear Command and Control System.—Not later than October 1, 2021, the Secretary shall develop and establish—
(1) a concept of operations for defending the nuclear command and control system against cyber attacks, including specification of the—
(A) roles and responsibilities of relevant entities within the Office of the Secretary, the military services, combatant commands, the Defense Agencies, and the Department of Defense Field Activities; and
(B) cybersecurity capabilities to be acquired and employed and operational tactics, techniques, and procedures, including cyber protection team and sensor deployment strategies, to be used to monitor, defend, and mitigate vulnerabilities in nuclear command and control systems; and
(2) an oversight mechanism or governance model for overseeing the implementation of the concept of operations developed and established under paragraph (1), related development, systems engineering, and acquisition activities and programs, and the plan required by subsection (a), including specification of the—
(A) roles and responsibilities of relevant entities within the Office of the Secretary, the military services, combatant commands, the Defense Agencies, and the Department of Defense Field Activities in overseeing the defense of the nuclear command and control system against cyber attacks;
(B) responsibilities and authorities of the Strategic Cybersecurity Program in overseeing and, as appropriate, executing—
(i) vulnerability assessments; and
(ii) development, systems engineering, and acquisition activities; and
(C) processes for coordination of activities, policies, and programs relating to the cybersecurity and defense of the nuclear command and control system.
- Cross-references to the US Code
- 10 U.S.C. 499 note