2021 US Code
Title 10 - Armed Forces
Subtitle A - General Military Law
Part I - Organization and General Military Powers
Chapter 24 - Nuclear Posture
Sec. 499 - Annual assessment of cyber resiliency of nuclear command and control system

Download PDF
Citation 10 U.S.C. § 499 (2021)
Section Name §499. Annual assessment of cyber resiliency of nuclear command and control system
Section Text

(a) In General.—Not less frequently than annually, the Commander of the United States Strategic Command and the Commander of the United States Cyber Command (in this section referred to collectively as the "Commanders") shall jointly conduct an assessment of the cyber resiliency of the nuclear command and control system.

(b) Elements.—In conducting the assessment required by subsection (a), the Commanders shall—

(1) conduct an assessment of the sufficiency and resiliency of the nuclear command and control system to operate through a cyber attack from the Russian Federation, the People's Republic of China, or any other country or entity the Commanders identify as a potential threat; and

(2) develop recommendations for mitigating any concerns of the Commanders resulting from the assessment.


(c) Reports Required.—(1) For each assessment conducted under subsection (a), the Commanders shall jointly submit to the Chairman of the Joint Chiefs of Staff, for submission to the Council on Oversight of the National Leadership Command, Control, and Communications System established under section 171a of this title, a report on the assessment that includes the following:

(A) The recommendations developed under subsection (b)(2).

(B) A statement of the degree of confidence of each of the Commanders in the mission assurance of the nuclear deterrent against a top tier cyber threat.

(C) A detailed description of the approach used to conduct the assessment required by subsection (a) and the technical basis of conclusions reached in conducting that assessment.

(D) Any other comments of the Commanders.


(2) The Council shall submit to the Secretary of Defense each report required by paragraph (1) and any comments of the Council on each report.

(3) Not later than 90 days after the date of the submission of a report under paragraph (1), the Secretary of Defense shall submit to the congressional defense committees the report, any comments of the Council on the report under paragraph (2), and any comments of the Secretary on the report.

(d) Quarterly Briefings.—Not less than once every quarter, the Deputy Secretary of Defense and the Vice Chairman of the Joint Chiefs of Staff shall jointly provide to the Committees on Armed Services of the House of Representatives and the Senate a briefing on any known or suspected critical intelligence parameter breaches that were identified during the previous quarter, including an assessment of any known or suspected impacts of such breaches to the mission effectiveness of military capabilities as of the date of the briefing or thereafter.

(e) Termination.—The requirements of this section shall terminate on December 31, 2027.

Source Credit

(Added Pub. L. 115–91, div. A, title XVI, §1651(a), Dec. 12, 2017, 131 Stat. 1756; amended Pub. L. 117–81, div. A, title XV, §1534, Dec. 27, 2021, 135 Stat. 2054.)


Editorial Notes EDITORIAL NOTES AMENDMENTS

2021—Subsec. (c). Pub. L. 117–81, §1534(1), substituted "Reports" for "Report" in heading.

Subsec. (c)(1). Pub. L. 117–81, §1534(2), substituted "For each assessment conducted under subsection (a), the Commanders" for "The Commanders" and "the assessment" for "the assessment required by subsection (a)" in introductory provisions.

Subsec. (c)(2). Pub. L. 117–81, §1534(3), which directed substitution of "each report" for "the report", was executed by making the substitution in both places it appeared, to reflect the probable intent of Congress.

Subsec. (c)(3). Pub. L. 117–81, §1534(4), substituted "Not later than 90 days after the date of the submission of a report under paragraph (1), the Secretary" for "The Secretary" and struck out "required by paragraph (1)" before ", any comments".


STATUTORY NOTES AND RELATED SUBSIDIARIES ENSURING CYBER RESILIENCY OF NUCLEAR COMMAND AND CONTROL SYSTEM

Pub. L. 116–283, div. A, title XVII, §1747, Jan. 1, 2021, 134 Stat. 4140, provided that:

"(a) Plan for Implementation of Findings and Recommendations From First Annual Assessment of Cyber Resiliency of Nuclear Command and Control System.—Not later than October 1, 2021, the Secretary of Defense shall submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a comprehensive plan, including a schedule and resourcing plan, for the implementation of the findings and recommendations included in the first report submitted under section 499(c)(3) of title 10, United States Code.

"(b) Concept of Operations and Oversight Mechanism for Cyber Defense of Nuclear Command and Control System.—Not later than October 1, 2021, the Secretary shall develop and establish—

"(1) a concept of operations for defending the nuclear command and control system against cyber attacks, including specification of the—

"(A) roles and responsibilities of relevant entities within the Office of the Secretary, the military services, combatant commands, the Defense Agencies, and the Department of Defense Field Activities; and

"(B) cybersecurity capabilities to be acquired and employed and operational tactics, techniques, and procedures, including cyber protection team and sensor deployment strategies, to be used to monitor, defend, and mitigate vulnerabilities in nuclear command and control systems; and

"(2) an oversight mechanism or governance model for overseeing the implementation of the concept of operations developed and established under paragraph (1), related development, systems engineering, and acquisition activities and programs, and the plan required by subsection (a), including specification of the—

"(A) roles and responsibilities of relevant entities within the Office of the Secretary, the military services, combatant commands, the Defense Agencies, and the Department of Defense Field Activities in overseeing the defense of the nuclear command and control system against cyber attacks;

"(B) responsibilities and authorities of the Strategic Cybersecurity Program in overseeing and, as appropriate, executing—

"(i) vulnerability assessments; and

"(ii) development, systems engineering, and acquisition activities; and

"(C) processes for coordination of activities, policies, and programs relating to the cybersecurity and defense of the nuclear command and control system."

Publication Title United States Code, 2018 Edition, Supplement 3, Title 10 - ARMED FORCES
Category Bills and Statutes
Collection United States Code
SuDoc Class Number Y 1.2/5:
Contained Within Title 10 - ARMED FORCES
Subtitle A - General Military Law
PART I - ORGANIZATION AND GENERAL MILITARY POWERS
CHAPTER 24 - NUCLEAR POSTURE
Sec. 499 - Annual assessment of cyber resiliency of nuclear command and control system
Contains section 499
Date 2021
Laws In Effect As Of Date January 3, 2022
Positive Law Yes
Disposition standard
Statutes at Large References 131 Stat. 1756
134 Stat. 4140
135 Stat. 2054
Public Law References Public Law 115-91, Public Law 116-283, Public Law 117-81
Disclaimer: These codes may not be the most recent version. United States may have more current or accurate information. We make no warranties or guarantees about the accuracy, completeness, or adequacy of the information contained on this site or the information linked to on the state site. Please check official sources.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.