§2200e. Definitions — Inbound Citations
10 U.S.C. § 2200e
Cited by 210 provisions in release 119-102.
Citations to §2200e(1)
-
(9) One of the Assistant Secretaries is the Assistant Secretary of Defense for Cyber Policy. The principal duty of the Assistant Secretary shall be the overall supervision of policy of the Department of Defense for cyber. The Assistant Secretary is the Principal Cyber Advisor described in section 392a(a) of this title.
-
(H) has the responsibilities for policy, oversight, and guidance for the architecture and programs related to the information technology, networking, information assurance, cybersecurity, and cyber capability architectures of the Department.
-
(i) developing, adopting, or publishing standards for information technology, networking, or cyber capabilities to which any military department or defense agency would need to adhere in order to run such capabilities on defense networks; and
-
(1) With the advice and assistance of the Chairman of the Joint Chiefs of Staff, the President, through the Secretary of Defense, shall establish under section 161 of this title a unified combatant command for cyber operations forces (hereinafter in this section referred to as the “United States Cyber Command”).
-
(2) The principal mission of the United States Cyber Command is to direct, synchronize, and coordinate military cyberspace planning and operations to defend and advance national interests in collaboration with domestic and international partners.
-
(1) Active and reserve cyber forces of the armed forces shall be assigned to the United States Cyber Command through the Global Force Management Process, as approved by the Secretary of Defense.
-
(2) Cyber forces not assigned to United States Cyber Command remain assigned to combatant commands or service-retained.
-
(c) The Commander of the United States Cyber Command shall hold the grade of general or, in the case of an officer of the Navy, admiral while serving in that position, without vacating that officer’s permanent grade. The Commander of such Command shall be appointed to that grade by the President, by and with the advice and consent of the Senate, for service in that position.
-
(1) In addition to the authority prescribed in section 164(c) of this title, the Commander of the United States Cyber Command shall be responsible for, and shall have the authority to conduct, all affairs of such Command relating to cyber operations activities.
-
(A) Subject to the authority, direction, and control of the Principal Cyber Advisor to the Secretary of Defense under section 392a(a) of this title, the Commander of such Command shall be responsible for, and shall have the authority to conduct, the following functions relating to cyber operations activities (whether or not relating to the United States Cyber Command):(i) Developing strategy, doctrine, and tactics.(ii) Preparing and submitting to the Secretary of Defense program recommendations and budget proposals for cyber operations forces and for other forces assigned to the United States Cyber Command.(iii) Exercising authority, direction, and control over the expenditure of funds—(I) for forces assigned directly to the United States Cyber Command; and(II) for cyber operations forces assigned to unified combatant commands other than the United States Cyber Command, with respect to all matters covered by section 807 of the National Defense Authorization Act for Fiscal Year 2016 (Public Law 114–92; 129 Stat. 886; 10 U.S.C. 2224 note) and, with respect to a matter not covered by such section, to the extent directed by the Secretary of Defense.(iv) Training and certification of assigned joint forces.(v) Conducting specialized courses of instruction for commissioned and noncommissioned officers.(vi) Validating requirements.(vii) Establishing priorities for requirements.(viii) Ensuring the interoperability of equipment and forces.(ix) Formulating and submitting requirements for intelligence support.
-
(ii) Preparing and submitting to the Secretary of Defense program recommendations and budget proposals for cyber operations forces and for other forces assigned to the United States Cyber Command.
-
(I) for forces assigned directly to the United States Cyber Command; and
-
(II) for cyber operations forces assigned to unified combatant commands other than the United States Cyber Command, with respect to all matters covered by section 807 of the National Defense Authorization Act for Fiscal Year 2016 (Public Law 114–92; 129 Stat. 886; 10 U.S.C. 2224 note) and, with respect to a matter not covered by such section, to the extent directed by the Secretary of Defense.
-
(B) The authority, direction, and control exercised by the Principal Cyber Advisor for purposes of this section is authority, direction, and control with respect to the administration and support of the United States Cyber Command, including readiness and organization of cyber operations forces, cyber operations-peculiar equipment and resources, and civilian personnel.
-
(C) Nothing in this section shall be construed as providing the Principal Cyber Advisor authority, direction, and control of operational matters that are subject to the operational chain of command of the combatant commands or the exercise of authority, direction, and control of personnel, resources, equipment, and other matters that are not cyber-operations peculiar and that are in the purview of the armed forces.
-
(3) The Commander of the United States Cyber Command shall be responsible for—(A) ensuring the combat readiness of forces assigned to the United States Cyber Command; and(B) monitoring the preparedness to carry out assigned missions of cyber forces assigned to unified combatant commands other than the United States Cyber Command.
-
(A) ensuring the combat readiness of forces assigned to the United States Cyber Command; and
-
(B) monitoring the preparedness to carry out assigned missions of cyber forces assigned to unified combatant commands other than the United States Cyber Command.
-
(1) In addition to the activities of a combatant command for which funding may be requested under section 166(b) of this title, the Commander of the United States Cyber Command shall, subject to the authority, direction, and control of the Assistant Secretary of Defense for Cyber Policy, be responsible for directly controlling and managing the planning, programming, budgeting, and execution of resources to train, equip, operate, and sustain the Cyber Mission Force.
-
(2) The responsibilities assigned to the Commander of the United States Cyber Command pursuant to paragraph (1) shall include the following:(A) Preparation of a program objective memorandum and budget estimate submission for the resources required to train, equip, operate, and sustain the Cyber Mission Force.(B) Preparation of budget materials pertaining to the United States Cyber Command for inclusion in the budget justification materials that are submitted to Congress in support of the budget of the Department of Defense for a fiscal year, as submitted with the budget of the President under section 1105(a) of title 31, United States Code, that is separate from any other military department or component of the Department of Defense.
-
(B) Preparation of budget materials pertaining to the United States Cyber Command for inclusion in the budget justification materials that are submitted to Congress in support of the budget of the Department of Defense for a fiscal year, as submitted with the budget of the President under section 1105(a) of title 31, United States Code, that is separate from any other military department or component of the Department of Defense.
-
(3) The responsibilities assigned to the Commander of the United States Cyber Command pursuant to paragraph (1) shall not include the following:(B) Funding for facility support that is provided by the military departments.
-
(f) The Council shall collect and assess (consistent with the provision of classified information and intelligence sources and methods) all reports and assessments otherwise conducted by the intelligence community (as defined in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4))) regarding foreign threats, including cyber threats, to the command, control, and communications system for the national leadership of the United States and the vulnerabilities of such system to such threats.
-
(1) a major force program category for the five-year defense plan of the Department of Defense for the training, manning, and equipping of the cyber mission forces and the cyberspace operations forces; and
-
(a) The Secretary of Defense shall designate a component of the Department of Defense to receive reports of cyber incidents from contractors in accordance with this section and section 393 of this title or from other governmental entities.
-
(b) The Secretary of Defense shall establish procedures that require an operationally critical contractor to report in a timely manner to component designated under subsection (a) each time a cyber incident occurs with respect to a network or information system of such operationally critical contractor.
-
(2) The procedures established pursuant to subsection (a) shall require each operationally critical contractor to rapidly report to the component of the Department designated pursuant to subsection (d)(2)(A) on each cyber incident with respect to any network or information systems of such contractor. Each such report shall include the following:(A) An assessment by the contractor of the effect of the cyber incident on the ability of the contractor to meet the contractual requirements of the Department.(B) The technique or method used in such cyber incident.(C) A sample of any malicious software, if discovered and isolated by the contractor, involved in such cyber incident.(D) A summary of information compromised by such cyber incident.
-
(A) An assessment by the contractor of the effect of the cyber incident on the ability of the contractor to meet the contractual requirements of the Department.
-
(B) The technique or method used in such cyber incident.
-
(C) A sample of any malicious software, if discovered and isolated by the contractor, involved in such cyber incident.
-
(D) A summary of information compromised by such cyber incident.
-
(B) that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;
-
(D) for national security purposes, including cyber situational awareness and defense purposes.
-
(1) No cause of action shall lie or be maintained in any court against any operationally critical contractor, and such action shall be promptly dismissed, for compliance with this section and contract requirements established pursuant to Defense Federal Acquisition Regulation Supplement clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, that is conducted in accordance with procedures established pursuant to subsection (b) and such contract requirements.
-
(1) The term “cyber incident” means actions taken through the use of computer networks that result in an actual or potentially adverse effect on an information system or the information residing therein.
-
(a) Not later than 15 days after the date on which the Secretary of Defense submits to Congress the defense budget materials (as defined in section 239 of this title) for a fiscal year, the Commander of the United States Cyber Command shall submit to the congressional defense committees a report containing the following:(1) An evaluation of whether each military department is meeting the requirements established by the Commander and validated by the Office of the Secretary of Defense, and is effectively implementing the plan required by section 1534 of the National Defense Authorization Act for Fiscal Year 2023, and the requirements established pursuant to section 1533 of such Act.(2) For each military department evaluated under paragraph (1)—(A) a certification that the military department is meeting such requirements; or(B) a detailed explanation regarding how the military department is not meeting such requirements.
-
(3) The adequacy of the policies and procedures relating to the assignment and assignment length of members of the Army, Navy, Air Force, Marine Corps, or Space Force to the Cyber Mission Force.
-
(4) The efficacy of the military department in filling key work roles within the Cyber Mission Force, including the proper force mix of civilian, military, and contractor personnel, and the means necessary to meet requirements established by the Commander and validated by the Secretary of Defense.
-
(7) In coordination with the Principal Cyber Advisor of the Department of Defense, an evaluation of the use by the military department of the shared lexicon of the Department of Defense specific to cyberspace activities.
-
(8) The readiness of personnel serving in the Cyber Mission Force and the cyberspace operations forces to accomplish assigned missions.
-
(2) The Commanders of the United States Cyber Command, United States European Command, United States Indo-Pacific Command, United States Northern Command, United States Strategic Command, United States Space Command, United States Transportation Command.
-
(8) The Principal Cyber Advisor of the Department of Defense.
-
(9) The Principal Cyber Advisors of the military departments.
-
(C) Offensive cyber operations.
-
(A) The evaluation of cyber vulnerabilities of major weapon systems of the Department of Defense required under section 1647 of the National Defense Authorization Act for Fiscal Year 2016 (Public Law 114–92; 129 Stat. 1118).
-
(B) The evaluation of cyber vulnerabilities of critical infrastructure of the Department of Defense required under section 1650 of the National Defense Authorization Act for Fiscal Year 2017 (Public Law 114–328; 10 U.S.C. 2224 note).
-
(C) The activities of the cyber protection teams of the Department of Defense.
-
(1) the evaluation of cyber vulnerabilities of each major weapon system of the Department of Defense and related mitigation activities under section 1647 of the National Defense Authorization Act for Fiscal Year 2016 (Public Law 114–92; 129 Stat. 1118);
-
(2) the evaluation of cyber vulnerabilities of the critical infrastructure of the Department of Defense under section 1650 of the National Defense Authorization Act for Fiscal Year 2017 (Public Law 114–328; 10 U.S.C. 2224 note);
-
(4) the assessments of the vulnerabilities to and mission risks presented by radio-frequency enabled cyber attacks with respect to the operational technology embedded in weapons systems, aircraft, ships, ground vehicles, space systems, sensors, and datalink networks of the Department of Defense under section 1559 of the National Defense Authorization Act for Fiscal Year 2023; and
-
(1) designate a senior official from among the personnel of the Department of Defense to act as the executive agent for cyber and information technology test ranges; and(2) designate a senior official from among the personnel of the Department of Defense to act as the executive agent for cyber and information technology training ranges.
-
(1) designate a senior official from among the personnel of the Department of Defense to act as the executive agent for cyber and information technology test ranges; and
-
(2) designate a senior official from among the personnel of the Department of Defense to act as the executive agent for cyber and information technology training ranges.
-
(1) The Secretary of Defense shall prescribe the roles, responsibilities, and authorities of the executive agents designated under subsection (a). Such roles, responsibilities, and authorities shall include the development of a biennial integrated plan for cyber and information technology test and training resources.
-
(A) Developing and maintaining a comprehensive list of cyber and information technology ranges, test facilities, test beds, and other means of testing, training, and developing software, personnel, and tools for accommodating the mission of the Department. Such list shall include resources from both governmental and nongovernmental entities.
-
(i) establishing the priorities for cyber and information technology ranges to meet Department objectives;(ii) enforcing standards to meet requirements specified by the United States Cyber Command, the training community, and the research, development, testing, and evaluation community;(iii) identifying and offering guidance on the opportunities for integration amongst the designated cyber and information technology ranges regarding test, training, and development functions;(iv) finding opportunities for cost reduction, integration, and coordination improvements for the appropriate cyber and information technology ranges;(v) adding or consolidating cyber and information technology ranges in the future to better meet the evolving needs of the cyber strategy and resource requirements of the Department;
-
(i) establishing the priorities for cyber and information technology ranges to meet Department objectives;
-
(ii) enforcing standards to meet requirements specified by the United States Cyber Command, the training community, and the research, development, testing, and evaluation community;
-
(v) adding or consolidating cyber and information technology ranges in the future to better meet the evolving needs of the cyber strategy and resource requirements of the Department;
-
(i) may add or consolidate cyber and information technology ranges in the future to better meet the evolving needs of the cyber strategy and resource requirements of the Department;(ii) coordinates with interagency and industry partners on cyber and information technology range issues;(iii) allows for integrated closed loop testing in a secure environment of cyber and electronic warfare capabilities;(iv) supports science and technology development, experimentation, testing and training; and(v) provides for interconnection with other existing cyber ranges and other kinetic range facilities in a distributed manner.
-
(i) may add or consolidate cyber and information technology ranges in the future to better meet the evolving needs of the cyber strategy and resource requirements of the Department;
-
(iii) allows for integrated closed loop testing in a secure environment of cyber and electronic warfare capabilities;
-
(v) provides for interconnection with other existing cyber ranges and other kinetic range facilities in a distributed manner.
-
(D) Certifying all cyber range investments of the Department of Defense.
-
(3) The executive agents designated under subsection (a), in consultation with the Chief Information Officer of the Department of Defense, shall jointly select a standard language from open-source candidates for representing and communicating cyber event and threat data. Such language shall be machine-readable for the Joint Information Environment and associated test and training ranges.
-
(1) There is a Principal Cyber Advisor in the Department of Defense.
-
(2) The Principal Cyber Advisor shall be responsible for the following:(B) Overall integration of Cyber Operations Forces activities relating to cyberspace operations, including associated policy and operational considerations, resources, personnel, technology development and transition, and acquisition.(C) Assessing and overseeing the implementation of the cyber strategy of the Department and execution of the cyber posture review of the Department on behalf of the Secretary.(D) Coordinating activities pursuant to subparagraphs (A) and (B) of paragraph (3) with the Principal Information Operations Advisor, the Chief Information Officer of the Department, and other officials as determined by the Secretary of Defense, to ensure the integration of activities in support of cyber, information, and electromagnetic spectrum operations.(E) Such other matters relating to the offensive military cyber forces of the Department as the Secretary shall specify for the purposes of this subsection.
-
(B) Overall integration of Cyber Operations Forces activities relating to cyberspace operations, including associated policy and operational considerations, resources, personnel, technology development and transition, and acquisition.
-
(C) Assessing and overseeing the implementation of the cyber strategy of the Department and execution of the cyber posture review of the Department on behalf of the Secretary.
-
(D) Coordinating activities pursuant to subparagraphs (A) and (B) of paragraph (3) with the Principal Information Operations Advisor, the Chief Information Officer of the Department, and other officials as determined by the Secretary of Defense, to ensure the integration of activities in support of cyber, information, and electromagnetic spectrum operations.
-
(E) Such other matters relating to the offensive military cyber forces of the Department as the Secretary shall specify for the purposes of this subsection.
-
(3) Consistent with section 911 of the National Defense Authorization Act for Fiscal Year 2017 (Public Law 114–328; 10 U.S.C. 111 note), the Principal Cyber Advisor shall—(A) integrate the cyber expertise and perspectives of appropriate organizations within the Office of the Secretary of Defense, Joint Staff, military departments, the Defense Agencies and Field Activities, and combatant commands, by establishing and maintaining a full-time cross-functional team of subject matter experts from those organizations; and(B) select team members, and designate a team leader, from among those personnel nominated by the heads of such organizations.
-
(A) integrate the cyber expertise and perspectives of appropriate organizations within the Office of the Secretary of Defense, Joint Staff, military departments, the Defense Agencies and Field Activities, and combatant commands, by establishing and maintaining a full-time cross-functional team of subject matter experts from those organizations; and
-
(A) The Secretary of Defense, acting through the Under Secretary of Defense (Comptroller), shall require the Secretaries of the military departments and the heads of the Defense agencies with responsibilities associated with any activity specified in paragraph (2) to transmit the proposed budget for such activities for a fiscal year and for the period covered by the future-years defense program submitted to Congress under section 221 of this title for that fiscal year to the Principal Cyber Advisor for review under subparagraph (B) before submitting the proposed budget to the Under Secretary of Defense (Comptroller).
-
(B) The Principal Cyber Advisor shall review each proposed budget transmitted under subparagraph (A) and, not later than January 31 of the year preceding the fiscal year for which the budget is proposed, shall submit to the Secretary of Defense a report containing the comments of the Principal Cyber Advisor with respect to all such proposed budgets, together with the certification of the Principal Cyber Advisor regarding whether each proposed budget is adequate.
-
(C) Not later than March 31 of each year, the Secretary of Defense shall submit to Congress a report specifying each proposed budget that the Principal Cyber Advisor did not certify to be adequate. The report of the Secretary shall include the following matters:(i) A discussion of the actions that the Secretary proposes to take, together with any recommended legislation that the Secretary considers appropriate, to address the inadequacy of the proposed budgets specified in the report.(ii) Any additional comments that the Secretary considers appropriate regarding the inadequacy of the proposed budgets.
-
(B) In carrying out duties under this section, the officer designated pursuant to paragraph (1) shall be subject to the authority, direction, and control of, and shall report directly to, the Assistant Secretary of Defense for Cyber Policy.
-
(A) The duties of the officer designated pursuant to paragraph (1) as Senior Military Advisor for Cyber Policy are as follows:(i) To serve as the principal uniformed military advisor on military cyber forces and activities to the Assistant Secretary of Defense for Cyber Policy.(ii) To assess and advise the Assistant Secretary of Defense for Cyber Policy on aspects of policy relating to military cyberspace operations, resources, personnel, cyber force readiness, cyber workforce development, and defense of Department of Defense networks.(iii) To advocate, in consultation with the Joint Staff, and senior officers of the Armed Forces and the combatant commands, for consideration of military issues within the Office of the Assistant Secretary of Defense for Cyber Policy, including coordination and synchronization of Department cyber forces and activities.
-
(iii) To advocate, in consultation with the Joint Staff, and senior officers of the Armed Forces and the combatant commands, for consideration of military issues within the Office of the Assistant Secretary of Defense for Cyber Policy, including coordination and synchronization of Department cyber forces and activities.
-
(B) The duties of the officer designated pursuant to paragraph (1) as Deputy Principal Cyber Advisor are as follows:(i) To synchronize, coordinate, and oversee implementation of the Cyber Strategy of the Department of Defense and other relevant policy and planning.(ii) To advise the Secretary of Defense on cyber programs, projects, and activities of the Department, including with respect to policy, training, resources, personnel, manpower, and acquisitions and technology.(iii) To oversee implementation of Department policy and operational directives on cyber programs, projects, and activities, including with respect to resources, personnel, manpower, and acquisitions and technology.(iv) To assist in the overall supervision of Department cyber activities relating to offensive missions.(v) To assist in the overall supervision of Department defensive cyber operations, including activities of component-level cybersecurity service providers and the integration of such activities with activities of the Cyber Mission Force.(vi) To advise senior leadership of the Department on, and advocate for, investment in capabilities to execute Department missions in and through cyberspace.(vii) To identify shortfalls in capabilities to conduct Department missions in and through cyberspace, and make recommendations on addressing such shortfalls in the Program Budget Review process.(viii) To coordinate and consult with stakeholders in the cyberspace domain across the Department in order to identify other issues on cyberspace for the attention of senior leadership of the Department.(ix) On behalf of the Principal Cyber Advisor, to lead the cross-functional team established pursuant to section 932(c)(3) of the National Defense Authorization Act for Fiscal Year 2014 (10 U.S.C. 2224 note)1 in order to synchronize and coordinate military and civilian cyber forces and activities of the Department.
-
(i) To synchronize, coordinate, and oversee implementation of the Cyber Strategy of the Department of Defense and other relevant policy and planning.
-
(ii) To advise the Secretary of Defense on cyber programs, projects, and activities of the Department, including with respect to policy, training, resources, personnel, manpower, and acquisitions and technology.
-
(iii) To oversee implementation of Department policy and operational directives on cyber programs, projects, and activities, including with respect to resources, personnel, manpower, and acquisitions and technology.
-
(iv) To assist in the overall supervision of Department cyber activities relating to offensive missions.
-
(ix) On behalf of the Principal Cyber Advisor, to lead the cross-functional team established pursuant to section 932(c)(3) of the National Defense Authorization Act for Fiscal Year 2014 (10 U.S.C. 2224 note)1 in order to synchronize and coordinate military and civilian cyber forces and activities of the Department.
-
(v) To assist in the overall supervision of Department defensive cyber operations, including activities of component-level cybersecurity service providers and the integration of such activities with activities of the Cyber Mission Force.
-
(A) Not later than 270 days after the date of the enactment of this Act, each of the secretaries of the military departments, in consultation with the service chiefs, shall appoint an independent Principal Cyber Advisor for each service to act as the principal advisor to the relevant secretary on all cyber matters affecting that military service.
-
(B) Each Principal Cyber Advisor position under subparagraph (A) shall—(i) be a senior civilian leadership position, filled by a senior member of the Senior Executive Service, not lower than the equivalent of a 3-star general officer, or by exception a comparable military officer with extensive cyber experience;(ii) exclusively occupy the Principal Cyber Advisor position and not assume any other position or responsibility in the relevant military department;(iii) be independent of the relevant service’s chief information officer; and(iv) report directly to and advise the secretary of the relevant military department and advise the relevant service’s senior uniformed officer.
-
(i) be a senior civilian leadership position, filled by a senior member of the Senior Executive Service, not lower than the equivalent of a 3-star general officer, or by exception a comparable military officer with extensive cyber experience;
-
(ii) exclusively occupy the Principal Cyber Advisor position and not assume any other position or responsibility in the relevant military department;
-
(C) Each of the secretaries of the military departments shall notify the Committees on Armed Services of the Senate and House of Representatives of his or her Principal Cyber Advisor appointment. In the case that the appointee is a military officer, the notification shall include a justification for the selection and an explanation of the appointee’s ability to execute the responsibilities of the Principal Cyber Advisor.
-
(2) Each Principal Cyber Advisor under paragraph (1) shall be responsible for advising both the secretary of the relevant military department and the senior uniformed military officer of the relevant military service and implementing the Department of Defense Cyber Strategy within the service by coordinating and overseeing the execution of the service’s policies and programs relevant to the following:(A) The recruitment, resourcing, and training of military cyberspace operations forces, assessment of these forces against standardized readiness metrics, and maintenance of these forces at standardized readiness levels.(B) Acquisition of offensive, defensive, and Department of Defense Information Networks cyber capabilities for military cyberspace operations.(C) Cybersecurity management and operations.(D) Acquisition of cybersecurity tools and capabilities, including those used by cybersecurity service providers.(E) Evaluating, improving, and enforcing a culture of cybersecurity warfighting and accountability for cybersecurity and cyberspace operations.(F) Cybersecurity and related supply chain risk management of the industrial base.(G) Cybersecurity of Department of Defense information systems, information technology services, and weapon systems, including the incorporation of cybersecurity threat information as part of secure development processes, cybersecurity testing, and the mitigation of cybersecurity risks.
-
(B) Acquisition of offensive, defensive, and Department of Defense Information Networks cyber capabilities for military cyberspace operations.
-
(3) To ensure service compliance with the Department of Defense Cyber Strategy, each Principal Cyber Advisor under paragraph (1) shall work in close coordination with the following:(A) Service chief information officers.(D) Department of Defense Chief Information Officer.(E) Defense Digital Service.
-
(A) Each of the secretaries of the military departments shall require service components with responsibilities associated with cyberspace operations forces, offensive or defensive cyberspace operations and capabilities, and cyberspace issues relevant to the duties specified in paragraph (2) to transmit the proposed budget for such responsibilities for a fiscal year and for the period covered by the future-years defense program submitted to Congress under section 221 of title 10, United States Code, for that fiscal year to the relevant service’s Principal Cyber Advisor for review under subparagraph (B) before submitting the proposed budget to the department’s comptroller.
-
(B) Each Principal Cyber Advisor under paragraph (1)(A) shall review each proposed budget transmitted under subparagraph (A) and submit to the secretary of the relevant military department a report containing the comments of the Principal Cyber Advisor with respect to all such proposed budgets, together with the certification of the Principal Cyber Advisor regarding whether each proposed budget is adequate.
-
(C) Not later than March 31 of each year, each of the secretaries of the military departments shall submit to the congressional defense committees a report specifying each proposed budget for the subsequent fiscal year contained in the most-recent report submitted under subparagraph (B) that the Principal Cyber Advisor did not certify to be adequate. The report of the secretary shall include a discussion of the actions that the secretary took or proposes to take, together with any additional comments that the Secretary considers appropriate regarding the adequacy or inadequacy of the proposed budgets.
-
(5) Not later than February 1, 2021, and biannually thereafter, each Principal Cyber Advisor under paragraph (1) shall brief the Committees on Armed Services of the Senate and House of Representatives on that Advisor’s activities and ability to perform the functions specified in paragraph (2).
-
(F) The Commander of the United States Cyber Command.
-
(B) that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;
-
(D) for national security purposes, including cyber situational awareness and defense purposes.
-
(a) The Secretary of Defense shall develop, prepare, and coordinate; make ready all armed forces for purposes of; and, when appropriately authorized to do so, conduct, military cyber activities or operations in cyberspace, including clandestine military activities or operations in cyberspace, to defend the United States and its allies, including in response to malicious cyber activity carried out against the United States or a United States person by a foreign power.
-
(e) Nothing in this section may be construed to limit the authority of the Secretary to conduct military activities or operations in cyberspace, including clandestine military activities or operations in cyberspace, to authorize specific military activities or operations, or to alter or otherwise affect the War Powers Resolution (50 U.S.C. 1541 et seq.), the Authorization for Use of Military Force (Public Law 107–40; 50 U.S.C. 1541 note), or reporting of sensitive military cyber activities or operations required by section 395 of this title.
-
(ii) to deter, safeguard, or defend against attacks or malicious cyber activities against the United States or Department of Defense information, networks, systems, installations, facilities, or other assets; or
-
(a) Except as provided in subsection (d), the Secretary of Defense shall promptly submit to the congressional defense committees notice in writing of any sensitive military cyber operation conducted under this title no later than 48 hours following such operation.
-
(3) In the event of an unauthorized disclosure of a sensitive military cyber operation covered by this section, the Secretary shall ensure, to the maximum extent practicable, that the congressional defense committees are notified immediately of the sensitive military cyber operation concerned. The notification under this paragraph may be verbal or written, but in the event of a verbal notification a written notification, signed by the Secretary, or the Secretary’s designee, shall be provided by not later than 48 hours after the provision of the verbal notification.
-
(1) In this section, the term “sensitive military cyber operation” means an action described in paragraph (2) that—(A) is carried out by the armed forces of the United States;(B) is intended to achieve a cyber effect against a foreign terrorist organization or a country, including its armed forces and the proxy forces of that country located elsewhere—(i) with which the armed forces of the United States are not involved in hostilities (as that term is used in section 4 of the War Powers Resolution (50 U.S.C. 1543)); or(ii) with respect to which the involvement of the armed forces of the United States in hostilities has not been acknowledged publicly by the United States; and(i) is determined to—(I) have a medium or high collateral effects estimate;(II) have a medium or high intelligence gain or loss;(III) have a medium or high probability of political retaliation, as determined by the political military assessment contained within the associated concept of operations;(IV) have a medium or high probability of detection when detection is not intended; or(V) result in medium or high collateral effects; or(ii) is a matter the Secretary determines to be appropriate.
-
(B) is intended to achieve a cyber effect against a foreign terrorist organization or a country, including its armed forces and the proxy forces of that country located elsewhere—(i) with which the armed forces of the United States are not involved in hostilities (as that term is used in section 4 of the War Powers Resolution (50 U.S.C. 1543)); or(ii) with respect to which the involvement of the armed forces of the United States in hostilities has not been acknowledged publicly by the United States; and
-
(A) An offensive cyber operation.
-
(B) A defensive cyber operation.
-
(1) With respect to a cyber capability that is intended for use as a weapon, on a quarterly basis, the aggregated results of all reviews of the capability for legality under international law pursuant to Department of Defense Directive 5000.01 carried out by any military department concerned.
-
(2) The use as a weapon of any cyber capability that has been approved for such use under international law by a military department no later than 48 hours following such use.
-
(3) In the event of an unauthorized disclosure of a cyber capability covered by this section, the Secretary shall ensure, to the maximum extent practicable, that the congressional defense committees are notified immediately of the cyber capability concerned. The notification under this paragraph may be verbal or written, but in the event of a verbal notification a written notification shall be provided by not later than 48 hours after the provision of the verbal notification.
-
(a) The Secretary of Defense may, with the concurrence of the Secretary of State, provide cyber capabilities and related information developed or procured by the Department of Defense to foreign countries or organizations described in subsection (b) without compensation, to meet operational imperatives if the Secretary of Defense determines that the provision of such cyber capabilities is in the national security interests of the United States.
-
(A) a list of foreign countries that the Secretary of Defense considers suitable for sharing of cyber capabilities and related information under the authority established under subsection (a); and
-
(2) Notification under paragraph (1) shall include a certification that the provision of the cyber capabilities was in the national security interests of the United States.
-
(1) The Secretary of Defense shall maintain performance metrics to track the results of sharing cyber capabilities and related information with foreign operational partners under a pilot program authorized by subsection (a).
-
(A) Whom the cyber capability was used against.
-
(B) The effect of the cyber capability, including whether and how the transfer of the cyber capability improved the operational cyber posture of the United States and achieved operational objectives of the United States, or had no effect.
-
(D) A mitigation plan to balance and offset the gaps and shortfalls identified under subparagraph (C), including with respect to spaceborne, airborne, ground, maritime, and cyber intelligence, surveillance, and reconnaissance capabilities.
-
(2) The Under Secretary of Defense for Intelligence and Security shall provide to the congressional defense committees and the congressional intelligence committees a briefing on short-, mid-, and long-term strategies to address the validated intelligence and counterintelligence requirements of the relevant combatant commands, including with respect to spaceborne, airborne, ground, maritime, and cyber intelligence, surveillance, and reconnaissance capabilities.
-
(a) Not later than October 1, 2026, the Secretary of Defense, in consultation with the Director of National Intelligence, shall ensure that the Department of Defense has a dedicated cyber intelligence capability in support of the military cyber operations requirements for the warfighting missions of the United States Cyber Command, the other combatant commands, the military departments, the Defense Agencies, the Joint Staff, and the Office of the Secretary of Defense with respect to foundational, scientific and technical, and all-source intelligence on cyber technology development, capabilities, concepts of operation, operations, and plans and intentions of cyber threat actors.
-
(2) The Secretary shall carry out subsection (a) using funds made available for the United States Cyber Command under the Military Intelligence Program.
-
(3) The National Security Agency may not provide information technology services for the dedicated cyber intelligence capability under subsection (a) unless such services are provided under the Military Intelligence Program or the Information Systems Security Program.
-
(3) Each report required by this subsection shall include an assessment by each commander of a geographic or functional combatant command of the readiness of the command to conduct operations in a multidomain battle that integrates ground, sea, air, space, cyber, and special operations forces.
-
(a) The Under Secretary of Defense for Policy, the Commander of United States Cyber Command, and the Chairman of the Joint Chiefs of Staff, or designees from each of their offices, shall provide to the congressional defense committees quarterly briefings on all offensive and significant defensive military operations in cyberspace, including clandestine cyber activities, carried out by the Department of Defense during the immediately preceding quarter.
-
(2) An update, set forth for each applicable geographic and functional command, that describes defensive cyber operations executed to protect or defend forces, networks, and equipment in the area of operations of that command.
-
(5) An overview of the readiness of the Cyber Mission Forces to perform assigned missions that—(A) addresses all of the abilities of such Forces to conduct cyberspace operations based on capability and capacity of personnel, equipment, training, and equipment condition—(i) using both quantitative and qualitative metrics; and(ii) in a way that is common to all military departments; and(B) is consistent with readiness reporting pursuant to section 482 of this title.
-
(a) Not less frequently than annually, the Commander of the United States Strategic Command and the Commander of the United States Cyber Command (in this section referred to collectively as the “Commanders”) shall jointly conduct an assessment of the cyber resiliency of the nuclear command and control system.
-
(1) conduct an assessment of the sufficiency and resiliency of the nuclear command and control system to operate through a cyber attack from the Russian Federation, the People’s Republic of China, or any other country or entity the Commanders identify as a potential threat; and
-
(B) A statement of the degree of confidence of each of the Commanders in the mission assurance of the nuclear deterrent against a top tier cyber threat.
-
(ii) with respect to cyber intrusions of contractor networks known or suspected to have resulted in the loss or compromise of design information regarding the nuclear command, control, and communications system; or
-
(A) The term “anomaly” means a malicious, suspicious or abnormal cyber incident that potentially threatens the national security or interests of the United States, or that is likely to result in demonstrable harm to the national security of the United States.
-
(A) Any procedures developed pursuant to paragraph (3)(A) shall include appropriate safeguards, as determined by the Secretary, concerning cyber security of Department of Defense systems and operational security of Department personnel.
-
(A) establish, as positions in the excepted service, such qualified positions in the Department of Defense as the Secretary determines necessary to carry out the responsibilities of the United States Cyber Command, including—(i) positions held by staff of the headquarters of the United States Cyber Command;(ii) positions held by elements of the United States Cyber Command enterprise relating to cyberspace operations, including elements assigned to the Joint Task Force-Department of Defense Information Networks;(iii) positions held by elements of the military departments supporting the United States Cyber Command;(iv) positions held in combatant commands, defense agencies, and field activities supporting the United States Cyber Command; and(v) up to 500 positions not otherwise described in clauses (i) through (iv) that the Secretary determines are hard-to-fill, highly skilled positions critical to cyberspace planning and operations in defense of, and which advance, U.S. national interests in collaboration with domestic and international partners.
-
(i) positions held by staff of the headquarters of the United States Cyber Command;
-
(ii) positions held by elements of the United States Cyber Command enterprise relating to cyberspace operations, including elements assigned to the Joint Task Force-Department of Defense Information Networks;
-
(iii) positions held by elements of the military departments supporting the United States Cyber Command;
-
(iv) positions held in combatant commands, defense agencies, and field activities supporting the United States Cyber Command; and
-
(3) An assessment of the anticipated workforce needs of the United States Cyber Command across the future-years defense plan.
-
(II) the effect of such authorities on recruitment and retention in the Cyber Excepted Service.
-
(5) The term “qualified position” means a position, designated by the Secretary for the purpose of this section, in which the individual occupying such position performs, manages, or supervises functions that execute the responsibilities of the United States Cyber Command relating to cyber operations.
-
(a) The Secretary of Defense may permit eligible private sector employees to receive instruction at the Defense Cyber Investigations Training Academy operating under the direction of the Defense Cyber Crime Center. No more than the equivalent of 200 full-time student positions may be filled at any one time by private sector employees enrolled under this section, on a yearly basis. Upon successful completion of the course of instruction in which enrolled, any such private sector employee may be awarded an appropriate certification or diploma.
-
(2) the course offerings at the Defense Cyber Investigations Training Academy continue to be determined solely by the needs of the Department of Defense.
-
(d) The Secretary of Defense shall charge private sector employees enrolled under this section tuition at a rate that is at least equal to the rate charged for employees of the United States. In determining tuition rates, the Secretary shall include overhead costs of the Defense Cyber Investigations Training Academy.
-
(e) While receiving instruction at the Defense Cyber Investigations Training Academy, students enrolled under this section, to the extent practicable, are subject to the same regulations governing academic performance, attendance, norms of behavior, and enrollment as apply to Government civilian employees receiving instruction at the Academy.
-
(f) Amounts received by the Defense Cyber Investigations Training Academy for instruction of students enrolled under this section shall be retained by the Academy to defray the costs of such instruction. The source, and the disposition, of such funds shall be specifically identified in records of the Academy.
-
(a) The Secretary of Defense, acting through the Chief Information Officer of the Department of Defense, shall establish an office to establish, maintain, and oversee the activities of the Department of Defense that pertain to the relationship between the Department and academia, including with entities involved in primary, secondary, or postsecondary education, with respect to cyber-related matters (in this section referred to as the “Office”).
-
(A) Serving as the consolidated focal point for engagements carried out between the Department of Defense and academia with respect to cyber-related matters.
-
(C) Conducting ongoing analysis, as determined necessary by the Director, of the performance of cyber-related educational scholarships, camps, support efforts, and volunteer partnerships of the Department of Defense.
-
(D) Identifying actions the Secretary of Defense may take to improve the cyber skills of personnel within the Department of Defense through participation by such personnel in covered academic engagement programs, for the purposes of assisting the Secretary in cyber-related matters and meeting the long-term national defense needs of the United States for personnel proficient in such skills.
-
(E) Managing funds and resources for the National Centers for Academic Excellence in Cybersecurity program, the Department of Defense Cyber Scholarship Program, the National Defense University College of Information and Cyberspace, the University Consortium for Cybersecurity, the senior military colleges, and other educational partnerships between academic institutions and active components of the Armed Forces.
-
(e) In carrying out this section, the Director of the Office may, under any provision of this chapter or any other provision of this title providing for the support of educational programs in cyber-related matters (and unless otherwise specified in such provision)—(1) enter into contracts and cooperative agreements, including for the purpose of supporting academic and hands-on programs for individuals transitioning into the cyber field of the Department;(2) make grants of financial assistance, including to civilian and military students;(3) provide cash awards and other items;(4) accept voluntary services; and(5) support national competition judging, other educational event activities, and associated award ceremonies in connection with covered academic engagement programs.
-
(1) enter into contracts and cooperative agreements, including for the purpose of supporting academic and hands-on programs for individuals transitioning into the cyber field of the Department;
-
(3) An academic partnership focused on establishing cyber talent among the personnel referred to in paragraph (2).
-
(a) To encourage the recruitment and retention of Department of Defense personnel who have the computer and network security skills necessary to meet the cyber requirements of the Department of Defense, the Secretary of Defense may carry out programs in accordance with this chapter to provide financial support for education in disciplines relevant to those requirements at institutions of higher education.
-
(1) who is pursuing an associate, baccalaureate, advanced degree, or certificate in a cyber discipline referred to in section 2200(a) of this title at an institution of higher education; and
-
(1) Not less than 50 percent of the amount available for financial assistance under this section for a fiscal year shall be available only for providing financial assistance for the pursuit of degrees referred to in subsection (a) at institutions of higher education that have established, improved, or are administering programs of education in cyber disciplines under the grant program established in section 2200b of this title, as determined by the Secretary of Defense.
-
(1) may, without regard to any provision of title 5 governing appointments in the competitive service, appoint to a cyber position in the Department of Defense in the excepted service an individual who has successfully completed an academic program for which a scholarship under this section was awarded and who, under the terms of the agreement for such scholarship, at the time of such appointment owes a service commitment to the Department; and
-
(a) The Secretary of Defense may provide grants of financial assistance to institutions of higher education to support the establishment, improvement, or administration of programs of education in cyber disciplines referred to in section 2200(a) of this title.
-
(8) The Commander of United States Cyber Command.
-
(v) appropriate actions are taken to ensure that any such ground monitoring stations do not pose a cyber espionage or other threat, including intelligence or counterintelligence, to the national security of the United States; and
-
(1) means the reasonable and proper costs of the armed forces for fuel, transportation, force protection (including cyber protection), training ammunition, utilities, and medical and maintenance services, including services required to maintain infrastructure, pre-positioned stocks, and equipment in good working order; and
-
(B) The inclusion of existing databases on cyber vulnerabilities when selecting such tools and solutions.
-
(C) The need for such tools and methods to provide continuous analysis, monitoring, and mitigation of cyber vulnerabilities in covered projects.
-
(B) may include operational headquarters facilities, airfields and supporting infrastructure, harbor facilities supporting naval vessels, munitions production and storage facilities, missile fields, radars, satellite control facilities, cyber operations facilities, space launch facilities, operational communications facilities, and biological defense facilities; and
-
(i) In the case of any cyber capability that, as determined in writing by the Secretary of Defense, is urgently needed to eliminate a deficiency that as the result of a cyber attack has resulted in critical mission failure, the loss of life, property destruction, or economic effects, or if left unfilled is likely to result in critical mission failure, the loss of life, property destruction, or economic effects, the Secretary may use the procedures developed under this section in order to accomplish the urgent acquisition and deployment of the needed offensive or defensive cyber capability.
-
(9) The Commander of United States Cyber Command may carry out a program of personnel management authority provided in subsection (b) in order to facilitate the recruitment of eminent experts in computer science, data science, engineering, mathematics, and computer network exploitation within the headquarters of United States Cyber Command and the Cyber National Mission Force.
-
(I) in the case of United States Cyber Command, appoint computer scientists, data scientists, engineers, mathematicians, and computer network exploitation specialists to a total of not more than 10 scientific and engineering positions in the Command;
-
(8) The Combat Capabilities Development Command Command, Control, Communications, Computers, Cyber, Intelligence, Surveillance, and Reconnaissance Center.
-
(B) a prioritized list of gaps or vulnerabilities in the national technology and industrial base (including vulnerabilities related to the current and projected impacts of extreme weather and to cyber attacks or disruptions), including—(i) a description of mitigation strategies necessary to address such gaps or vulnerabilities;(ii) the identification of the Secretary concerned or the head of the Defense Agency responsible for addressing such gaps or vulnerabilities; and(iii) a proposed timeline for action to address such gaps or vulnerabilities; and
-
(7) A plan for the research and development, deployment, and lifecycle sustainment of the technologies employed within the nuclear security enterprise to address physical and cyber security threats during the five fiscal years following the date of the report, together with—(A) for each site in the nuclear security enterprise, a description of the technologies deployed to address the physical and cybersecurity threats posed to that site;(B) for each site and for the nuclear security enterprise, the methods used by the Administration to establish priorities among investments in physical and cybersecurity technologies; and(C) a detailed description of how the funds identified for each program element specified pursuant to paragraph (1) in the budget for the Administration for each fiscal year during that five-fiscal-year period will help carry out that plan.
-
(A) a concise statement regarding the adequacy of the science-based tools and methods, including with respect to cyber assurance, being used to determine the matters covered by the assessments;
-
(B) that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;
-
(D) for national security purposes, including cyber situational awareness and defense purposes.
Citations to §2200e(3)
-
(1) in the case of a scholarship, the institution at which the recipient pursues a degree is a Center of Academic Excellence in Cyber Education; and
-
(2) in the case of a grant, the recipient is a Center of Academic Excellence in Cyber Education.