Pub. L. 119-60, div. A, tit. XV, subtit. E, sec. 1545 (as amended)
ANNUAL REPORT ON MISSION ASSURANCE COORDINATION BOARD ACTIVITIES.
SEC. 1545. ANNUAL REPORT ON MISSION ASSURANCE COORDINATION BOARD ACTIVITIES.
(a) Annual Report Required.—Not later than December 1, 2026, and annually thereafter until December 1, 2031, the co-chairs of the Mission Assurance Coordination Board shall jointly provide to the congressional defense committees a report on the activities of the Board during the one-year period preceding the submission of the report.
(b) Report Elements.—Each annual report required by subsection (a) shall include the following:
(1) An identification of each covered assessment conducted during the period covered the report, including the entity conducting the assessment and key findings of the assessment.
(2) A detailed explanation of each covered assessments described in paragraph (1) resulting in the identification of risks categorized as high or significant, including recommendations for measures to mitigate such risks and an explanation of the resources required to implement such measures.
(3) An identification of any cybersecurity risks affecting multiple systems or organizations of the Department of Defense identified by a covered assessment described in paragraph (1).
(4) An assessment of the cybersecurity posture of the operational technology, industrial control systems, and base infrastructure of the Department of Defense, including an identification of vulnerabilities in legacy systems of the Department
and the integrity of the segmentation of the network of the Department, and any associated recommended activities to remediate cybersecurity risks identified by such assessment.
(5) A description of the status of the cyber resilience and recovery capabilities of the Department of Defense for physical infrastructure systems and the dependencies of such systems, including an assessment of the power generation and distribution systems, water treatment facilities, HVAC controls, and physical security systems of the Department, and any associated recommended activities to remediate cybersecurity and physical security risk identified by a covered assessment described in paragraph (1).
(6) Independent input from the commanders of military installation on the potential effects on readiness of any vulnerabilities identified pursuant paragraphs (1), (2). or (3).
(7) Recommendations for incorporating recommendations identified in paragraph (5) for efforts to mitigate any identified cybersecurity risks identified under paragraph (3) into ongoing exercises of the Department of Defense to support remediation of any such cybersecurity risks.
(8) A method of tracking the progress of the Department of Defense in closing any risks identified in an assessment identified under paragraph (1) that are categorized as high or significant across the period of the most recent future-years defense program submitted to Congress under section 221 of title 10, United States Code, including the use of visualization tools or dashboard.
(9) Any recommendations for changes to critical nodes or assets identified pursuant to an assessment identified under paragraph (1), or changes to the risk level or priority of such nodes or assets.
(c) Definitions.—In this section—
(1) the term “covered assessment” means an assessment required by, and reviewed by the Board pursuant to, Department of Defense Instruction 3020.45 (or any successor instruction); and
(2) the terms “Board” and “Mission Assurance Coordination Board” mean the Mission Assurance Coordination Board established pursuant to Department of Defense Instruction 3020.45 (or any successor instruction), or any successor organization.