2015 US Code
Title 42 - The Public Health and Welfare (Sections 1 - 18445)
Chapter 159 - Space Exploration, Technology, and Science (Sections 18301 - 18445)
Subchapter XI - Other Matters (Sections 18441 - 18445)
Sec. 18445 - Information security

View Metadata
Metadata
Publication TitleUnited States Code, 2012 Edition, Supplement 3, Title 42 - THE PUBLIC HEALTH AND WELFARE
CategoryBills and Statutes
CollectionUnited States Code
SuDoc Class NumberY 1.2/5:
Contained WithinTitle 42 - THE PUBLIC HEALTH AND WELFARE
CHAPTER 159 - SPACE EXPLORATION, TECHNOLOGY, AND SCIENCE
SUBCHAPTER XI - OTHER MATTERS
Sec. 18445 - Information security
Containssection 18445
Date2015
Laws In Effect As Of DateJanuary 3, 2016
Positive LawNo
Dispositionstandard
Source CreditPub. L. 111-267, title XII, §1207, Oct. 11, 2010, 124 Stat. 2844.
Statutes at Large References124 Stat. 2844
128 Stat. 3073
Public and Private LawsPublic Law 111-267, Public Law 113-283

Download PDF


42 U.S.C. § 18445 (2015)
§18445. Information security(a) Monitoring risk(1) Update on system implementation

Not later than 120 days after October 11, 2010, and on a biennial basis thereafter, the chief information officer of NASA, in coordination with other national security agencies, shall provide to the appropriate committees of Congress—

(A) an update on efforts to implement a system to provide dynamic, comprehensive, real-time information regarding risk of unauthorized remote, proximity, and insider use or access, for all information infrastructure under the responsibility of the chief information officer, and mission-related networks, including contractor networks;

(B) an assessment of whether the system has demonstrably and quantifiably reduced network risk compared to alternative methods of measuring security; and

(C) an assessment of the progress that each center and facility has made toward implementing the system.

(2) Existing assessments

The assessments required of the Inspector General under section 3545 1 of title 44 shall evaluate the effectiveness of the system described in this subsection.

(b) Information security awareness and education(1) In general

In consultation with the Department of Education, other national security agencies, and other agency directorates, the chief information officer shall institute an information security awareness and education program for all operators and users of NASA information infrastructure, with the goal of reducing unauthorized remote, proximity, and insider use or access.

(2) Program requirements

(A) The program shall include, at a minimum, ongoing classified and unclassified threat-based briefings, and automated exercises and examinations that simulate common attack techniques.

(B) All agency employees and contractors engaged in the operation or use of agency information infrastructure shall participate in the program.

(C) Access to NASA information infrastructure shall only be granted to operators and users who regularly satisfy the requirements of the program.

(D) The chief human capital officer of NASA, in consultation with the chief information officer, shall create a system to reward operators and users of agency information infrastructure for continuous high achievement in the program.

(c) Information infrastructure defined

In this section, the term "information infrastructure" means the underlying framework that information systems and assets rely on to process, transmit, receive, or store information electronically, including programmable electronic devices and communications networks and any associated hardware, software, or data.

(Pub. L. 111–267, title XII, §1207, Oct. 11, 2010, 124 Stat. 2844.)

REFERENCES IN TEXT

Section 3545 of title 44, referred to in subsec. (a)(2), was repealed by Pub. L. 113–283, §2(a), Dec. 18, 2014, 128 Stat. 3073. Provisions similar to section 3545 of title 44 are now contained in section 3555 of title 44, as enacted by Pub. L. 113–283.

1 See References in Text note below.

Disclaimer: These codes may not be the most recent version. The United States Government Printing Office may have more current or accurate information. We make no warranties or guarantees about the accuracy, completeness, or adequacy of the information contained on this site or the information linked to on the US site. Please check official sources.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.