2014 US Code
Title 44 - Public Printing and Documents (Sections 101 - 4104)
Chapter 35 - Coordination of Federal Information Policy (Sections 3501 - 3558)
Subchapter II - Information Security (Sections 3551 - 3558)
Sec. 3551 - Purposes

View Metadata
Metadata
Publication TitleUnited States Code, 2012 Edition, Supplement 2, Title 44 - PUBLIC PRINTING AND DOCUMENTS
CategoryBills and Statutes
CollectionUnited States Code
SuDoc Class NumberY 1.2/5:
Contained WithinTitle 44 - PUBLIC PRINTING AND DOCUMENTS
CHAPTER 35 - COORDINATION OF FEDERAL INFORMATION POLICY
SUBCHAPTER II - INFORMATION SECURITY
Sec. 3551 - Purposes
Containssection 3551
Date2014
Laws In Effect As Of DateJanuary 5, 2015
Positive LawYes
Dispositionstandard
Source CreditAdded Pub. L. 113-283, §2(a), Dec. 18, 2014, 128 Stat. 3073.
Statutes at Large References127 Stat. 377
128 Stat. 3073, 247-289, 259, 278
Public and Private LawsPublic Law 107-347, Public Law 113-6, Public Law 113-76, Public Law 113-283

Download PDF


44 U.S.C. § 3551 (2014)
§3551. Purposes

The purposes of this subchapter are to—

(1) provide a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support Federal operations and assets;

(2) recognize the highly networked nature of the current Federal computing environment and provide effective governmentwide management and oversight of the related information security risks, including coordination of information security efforts throughout the civilian, national security, and law enforcement communities;

(3) provide for development and maintenance of minimum controls required to protect Federal information and information systems;

(4) provide a mechanism for improved oversight of Federal agency information security programs, including through automated security tools to continuously diagnose and improve security;

(5) acknowledge that commercially developed information security products offer advanced, dynamic, robust, and effective information security solutions, reflecting market solutions for the protection of critical information infrastructures important to the national defense and economic security of the nation that are designed, built, and operated by the private sector; and

(6) recognize that the selection of specific technical hardware and software information security solutions should be left to individual agencies from among commercially developed products.

(Added Pub. L. 113–283, §2(a), Dec. 18, 2014, 128 Stat. 3073.)

PRIOR PROVISIONS

Provisions similar to this section were contained in sections 3531 and 3541 of this title prior to repeal by Pub. L. 113–283.

CYBERSECURITY IMPROVEMENTS TO AGENCY INFORMATION SYSTEMS

Pub. L. 113–76, div. F, title V, §554, Jan. 17, 2014, 128 Stat. 278, provided that:

"(a) Of the amounts made available by this Act [div. F of Pub. L. 113–76 (128 Stat. 247–289), see Tables for classification] for National Protection and Programs Directorate, 'Infrastructure Protection and Information Security' [128 Stat. 259], $166,000,000 for the 'Federal Network Security' program, project, and activity shall be used to deploy on Federal systems technology to improve the information security of agency information systems covered by [former] section 3543(a) of title 44, United States Code [see now 44 U.S.C. 3553]: Provided, That funds made available under this section shall be used to assist and support Government-wide and agency-specific efforts to provide adequate, risk-based, and cost-effective cybersecurity to address escalating and rapidly evolving threats to information security, including the acquisition and operation of a continuous monitoring and diagnostics program, in collaboration with departments and agencies, that includes equipment, software, and Department of Homeland Security supplied services: Provided further, That not later than April 1, 2014, and quarterly thereafter, the Under Secretary of Homeland Security of the National Protection and Programs Directorate shall submit to the Committees on Appropriations of the Senate and the House of Representatives a report on the obligation and expenditure of funds made available under this section: Provided further, That continuous monitoring and diagnostics software procured by the funds made available by this section shall not transmit to the Department of Homeland Security any personally identifiable information or content of network communications of other agencies' users: Provided further, That such software shall be installed, maintained, and operated in accordance with all applicable privacy laws and agency-specific policies regarding network content.

"(b) Funds made available under this section may not be used to supplant funds provided for any such system within an agency budget.

"(c) Not later than July 1, 2014, the heads of all Federal agencies shall submit to the Committees on Appropriations of the Senate and the House of Representatives expenditure plans for necessary cybersecurity improvements to address known vulnerabilities to information systems described in subsection (a).

"(d) Not later than October 1, 2014, and quarterly thereafter, the head of each Federal agency shall submit to the Director of the Office of Management and Budget a report on the execution of the expenditure plan for that agency required by subsection (c): Provided, That the Director of the Office of Management and Budget shall summarize such execution reports and annually submit such summaries to Congress in conjunction with the annual progress report on implementation of the E-Government Act of 2002 (Public Law 107–347) [see Tables for classification], as required by section 3606 of title 44, United States Code.

"(e) This section shall not apply to the legislative and judicial branches of the Federal Government and shall apply to all Federal agencies within the executive branch except for the Department of Defense, the Central Intelligence Agency, and the Office of the Director of National Intelligence."

Similar provisions were contained in the following prior appropriation act:

Pub. L. 113–6, div. D, title V, §558, Mar. 26, 2013, 127 Stat. 377.

Disclaimer: These codes may not be the most recent version. The United States Government Printing Office may have more current or accurate information. We make no warranties or guarantees about the accuracy, completeness, or adequacy of the information contained on this site or the information linked to on the US site. Please check official sources.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.