---
kind: "section"
citation: "38 U.S.C. § 5722"
title: "38"
title_heading: "Veterans’ Benefits"
number: "5722"
heading: "Policy"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/38/5722"
units:
  - "Part IV — General Administrative Provisions"
  - "Chapter 57 — Records and Investigations"
  - "Subchapter III — Information Security"
---

# §5722. Policy

- (a) **In General.—** The security of [Department](/usc/38/101.md?p=1) information and [information systems](/usc/38/5727.md?p=13) is vital to the success of the mission of the [Department](/usc/38/101.md?p=1). To that end, the [Secretary](/usc/38/101.md?p=1) shall establish and maintain a comprehensive [Department](/usc/38/101.md?p=1)-wide [information security](/usc/38/5727.md?p=11) program to provide for the development and maintenance of cost-effective security controls needed to protect [Department](/usc/38/101.md?p=1) information, in any media or format, and [Department](/usc/38/101.md?p=1) [information systems](/usc/38/5727.md?p=13).
- (b) **Elements.—** The [Secretary](/usc/38/101.md?p=1) shall ensure that the [Department](/usc/38/101.md?p=1) [information security](/usc/38/5727.md?p=11) program includes the following elements:
  - (1) Periodic assessments of the risk and magnitude of harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of information and [information systems](/usc/38/5727.md?p=13) that support the operations and assets of the [Department](/usc/38/101.md?p=1).
  - (2) Policies and procedures that—
    - (A) are based on risk assessments;
    - (B) cost-effectively reduce security risks to an acceptable level; and
    - (C) ensure that [information security](/usc/38/5727.md?p=11) is addressed throughout the life cycle of each [Department](/usc/38/101.md?p=1) [information system](/usc/38/5727.md?p=13).
  - (3) Selection and effective implementation of minimum, mandatory technical, operational, and management security controls, or other compensating countermeasures, to protect the [confidentiality](/usc/38/5727.md?p=2), [integrity](/usc/38/5727.md?p=14), and [availability](/usc/38/5727.md?p=1) of each [Department](/usc/38/101.md?p=1) system and its information.
  - (4) [Subordinate plans](/usc/38/5727.md?p=20) for providing adequate security for networks, facilities, systems, or groups of [information systems](/usc/38/5727.md?p=13), as appropriate.
  - (5) Annual security awareness [training](/usc/38/5727.md?p=21) for all [Department](/usc/38/101.md?p=1) employees, contractors, and all other users of [VA sensitive data](/usc/38/5727.md?p=23) and [Department](/usc/38/101.md?p=1) [information systems](/usc/38/5727.md?p=13) that identifies the [information security](/usc/38/5727.md?p=11) risks associated with the activities of such employees, contractors, and users and the responsibilities of such employees, contractors, and users to comply with [Department](/usc/38/101.md?p=1) policies and procedures designed to reduce such risks.
  - (6) Periodic testing and evaluation of the effectiveness of security controls based on risk, including triennial certification testing of all management, operational, and technical controls, and annual testing of a subset of those controls for each [Department](/usc/38/101.md?p=1) system.
  - (7) A process for planning, developing, implementing, evaluating, and documenting remedial actions to address deficiencies in [information security](/usc/38/5727.md?p=11) policies, procedures, and practices.
  - (8) Procedures for detecting, immediately reporting, and responding to [security incidents](/usc/38/5727.md?p=18), including mitigating risks before substantial damage is done as well as notifying and consulting with the US-Computer Emergency Readiness Team of the [Department](/usc/38/101.md?p=1) of Homeland Security, law enforcement agencies, the Inspector General of the [Department](/usc/38/101.md?p=1), and other offices as appropriate.
  - (9) Plans and procedures to ensure continuity of operations for [Department](/usc/38/101.md?p=1) systems.
- (c) **Compliance With Certain Requirements.—** The [Secretary](/usc/38/101.md?p=1) shall comply with the provisions of subchapter III of [chapter 35](/usc/44/chch35.md) of title 44 and other related [information security requirements](/usc/38/5727.md?p=12) promulgated by the National Institute of Standards and Technology and the Office of Management and Budget that define [Department](/usc/38/101.md?p=1) [information system](/usc/38/5727.md?p=13) mandates.

## Source credit

(Added Pub. L. 109–461, title IX, § 902(a), Dec. 22, 2006, 120 Stat. 3450.)
