---
kind: "section"
citation: "38 U.S.C. § 5723"
title: "38"
title_heading: "Veterans’ Benefits"
number: "5723"
heading: "Responsibilities"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/38/5723"
units:
  - "Part IV — General Administrative Provisions"
  - "Chapter 57 — Records and Investigations"
  - "Subchapter III — Information Security"
---

# §5723. Responsibilities

- (a) **Secretary of Veterans Affairs.—** In accordance with the provisions of subchapter III of [chapter 35](/usc/44/chch35.md) of title 44, the [Secretary](/usc/38/101.md?p=1) is responsible for the following:
  - (1) Ensuring that the [Department](/usc/38/101.md?p=1) adopts a [Department](/usc/38/101.md?p=1)-wide [information security](/usc/38/5727.md?p=11) program and otherwise complies with the provisions of subchapter III of [chapter 35](/usc/44/chch35.md) of title 44 and other related [information security requirements](/usc/38/5727.md?p=12).
  - (2) Ensuring that [information security](/usc/38/5727.md?p=11) protections are commensurate with the risk and magnitude of the potential harm to [Department](/usc/38/101.md?p=1) information and [information systems](/usc/38/5727.md?p=13) resulting from unauthorized access, use, disclosure, disruption, modification, or destruction.
  - (3) Ensuring that [information security](/usc/38/5727.md?p=11) management processes are integrated with [Department](/usc/38/101.md?p=1) strategic and operational planning processes.
  - (4) Ensuring that the Under [Secretaries](/usc/38/101.md?p=1), Assistant [Secretaries](/usc/38/101.md?p=1), and other key officials of the [Department](/usc/38/101.md?p=1) provide adequate security for the information and [information systems](/usc/38/5727.md?p=13) under their control.
  - (5) Ensuring enforcement and compliance with the requirements imposed on the [Department](/usc/38/101.md?p=1) under the provisions of subchapter III of chapter 35 of title 44.
  - (6) Ensuring that the [Department](/usc/38/101.md?p=1) has trained program and staff office personnel sufficient to assist in complying with all the provisions of subchapter III of [chapter 35](/usc/44/chch35.md) of title 44 and other related [information security requirements](/usc/38/5727.md?p=12).
  - (7) Ensuring that the Assistant [Secretary](/usc/38/101.md?p=1) for Information and Technology, in coordination with the Under [Secretaries](/usc/38/101.md?p=1), Assistant [Secretaries](/usc/38/101.md?p=1), and other key officials of the [Department](/usc/38/101.md?p=1) report to Congress, the Office of Management and Budget, and other entities as required by law and Executive Branch direction on the effectiveness of the [Department](/usc/38/101.md?p=1) [information security](/usc/38/5727.md?p=11) program, including remedial actions.
  - (8) Notifying officials other than officials of the [Department](/usc/38/101.md?p=1) of [data breaches](/usc/38/5727.md?p=4) when required under this subchapter.
  - (9) Ensuring that the Assistant [Secretary](/usc/38/101.md?p=1) for Information and Technology has the authority and control necessary to develop, approve, implement, integrate, and oversee the policies, procedures, processes, activities, and systems of the [Department](/usc/38/101.md?p=1) relating to subchapter III of [chapter 35](/usc/44/chch35.md) of title 44, including the management of all related mission applications, [information resources](/usc/38/5727.md?p=10), personnel, and infrastructure.
  - (10) Submitting to the Committees on [Veterans](/usc/38/101.md?p=2)’ Affairs of the Senate and House of Representatives, the Committee on Government Reform of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs of the Senate, not later than March 1 each year, a report on the compliance of the [Department](/usc/38/101.md?p=1) with subchapter III of [chapter 35](/usc/44/chch35.md) of title 44, with the information in such report displayed in the aggregate and separately for each Administration, office, and facility of the [Department](/usc/38/101.md?p=1).
  - (11) Taking appropriate action to ensure that the budget for any fiscal year, as submitted by the President to Congress under [section 1105 of title 31](/usc/31/1105.md), sets forth separately the amounts required in the budget for such fiscal year for compliance by the [Department](/usc/38/101.md?p=1) with Federal law and regulations governing [information security](/usc/38/5727.md?p=11), including this subchapter and subchapter III of chapter 35 of title 44.
  - (12) Providing [notice](/usc/38/5100.md?p=2) to the Director of the Office of Management and Budget, the Inspector General of the [Department](/usc/38/101.md?p=1), and such other Federal agencies as the [Secretary](/usc/38/101.md?p=1) considers appropriate of a presumptive [data breach](/usc/38/5727.md?p=4) of which [notice](/usc/38/5100.md?p=2) is provided the [Secretary](/usc/38/101.md?p=1) under [subsection (b)(16)](#b-16) if, in the opinion of the Assistant [Secretary](/usc/38/101.md?p=1) for Information and Technology, the breach involves the information of twenty or more individuals.
- (b) **Assistant Secretary for Information and Technology.—** The Assistant [Secretary](/usc/38/101.md?p=1) for Information and Technology, as the Chief Information Officer of the [Department](/usc/38/101.md?p=1), is responsible for the following:
  - (1) Establishing, maintaining, and monitoring [Department](/usc/38/101.md?p=1)-wide [information security](/usc/38/5727.md?p=11) policies, procedures, [control techniques](/usc/38/5727.md?p=3), [training](/usc/38/5727.md?p=21), and inspection requirements as elements of the [Department](/usc/38/101.md?p=1) [information security](/usc/38/5727.md?p=11) program.
  - (2) Issuing policies and handbooks to provide direction for implementing the elements of the [information security](/usc/38/5727.md?p=11) program to all [Department](/usc/38/101.md?p=1) organizations.
  - (3) Approving all policies and procedures that are related to [information security](/usc/38/5727.md?p=11) for those areas of responsibility that are currently under the management and the oversight of other [Department](/usc/38/101.md?p=1) organizations.
  - (4) Ordering and enforcing [Department](/usc/38/101.md?p=1)-wide compliance with and execution of any [information security](/usc/38/5727.md?p=11) policy.
  - (5) Establishing minimum mandatory technical, operational, and management [information security](/usc/38/5727.md?p=11) control requirements for each [Department](/usc/38/101.md?p=1) system, consistent with risk, the processes identified in standards of the National Institute of Standards and Technology, and the responsibilities of the Assistant [Secretary](/usc/38/101.md?p=1) to operate and maintain all [Department](/usc/38/101.md?p=1) systems currently creating, processing, collecting, or disseminating data on behalf of [Department](/usc/38/101.md?p=1) [information owners](/usc/38/5727.md?p=9).
  - (6) Establishing standards for access to [Department](/usc/38/101.md?p=1) [information systems](/usc/38/5727.md?p=13) by organizations and individual employees, and to deny access as appropriate.
  - (7) Directing that any incidents of failure to comply with established [information security](/usc/38/5727.md?p=11) policies be immediately reported to the Assistant [Secretary](/usc/38/101.md?p=1).
  - (8) Reporting any compliance failure or policy violation directly to the appropriate Under [Secretary](/usc/38/101.md?p=1), Assistant [Secretary](/usc/38/101.md?p=1), or other key official of the [Department](/usc/38/101.md?p=1) for appropriate administrative or disciplinary action.
  - (9) Reporting any compliance failure or policy violation directly to the appropriate Under [Secretary](/usc/38/101.md?p=1), Assistant [Secretary](/usc/38/101.md?p=1), or other key official of the [Department](/usc/38/101.md?p=1) along with taking action to correct the failure or violation.
  - (10) Requiring any key official of the [Department](/usc/38/101.md?p=1) who is so notified to report to the Assistant [Secretary](/usc/38/101.md?p=1) with respect to an action to be taken in response to any compliance failure or policy violation reported by the Assistant [Secretary](/usc/38/101.md?p=1).
  - (11) Ensuring that the Chief Information Officers and [Information Security](/usc/38/5727.md?p=11) Officers of the [Department](/usc/38/101.md?p=1) comply with all cyber security directives and mandates, and ensuring that these staff members have all necessary authority and means to direct full compliance with such directives and mandates relating to the acquisition, operation, maintenance, or use of information technology resources from all facility staff.
  - (12) Establishing the [VA National Rules of Behavior](/usc/38/5727.md?p=22) for appropriate use and protection of the information which is used to support [Department](/usc/38/101.md?p=1) missions and functions.
  - (13) Establishing and providing supervision over an effective incident reporting system.
  - (14) Submitting to the [Secretary](/usc/38/101.md?p=1), at least once every quarter, a report on any deficiency in the compliance with subchapter III of [chapter 35](/usc/44/chch35.md) of title 44 of the [Department](/usc/38/101.md?p=1) or any Administration, office, or facility of the [Department](/usc/38/101.md?p=1).
  - (15) Reporting immediately to the [Secretary](/usc/38/101.md?p=1) on any significant deficiency in the compliance described by [paragraph (14)](#b-14).
  - (16) Providing immediate [notice](/usc/38/5100.md?p=2) to the [Secretary](/usc/38/101.md?p=1) of any presumptive [data breach](/usc/38/5727.md?p=4).
- (c) **Associate Deputy Assistant Secretary for Cyber and Information Security.—** In accordance with the provisions of subchapter III of [chapter 35](/usc/44/chch35.md) of title 44, the Associate Deputy Assistant [Secretary](/usc/38/101.md?p=1) for Cyber and [Information Security](/usc/38/5727.md?p=11), as the Senior [Information Security](/usc/38/5727.md?p=11) Officer of the [Department](/usc/38/101.md?p=1), is responsible for carrying out the responsibilities of the Assistant [Secretary](/usc/38/101.md?p=1) for Information and Technology under the provisions of subchapter III of [chapter 35](/usc/44/chch35.md) of title 44, as set forth in [subsection (b)](#b).
- (d) **Department Information Owners.—** In accordance with the criteria of the Centralized IT Management System, [Department](/usc/38/101.md?p=1) [information owners](/usc/38/5727.md?p=9) are responsible for the following:
  - (1) Providing assistance to the Assistant [Secretary](/usc/38/101.md?p=1) for Information and Technology regarding the security requirements and appropriate level of security controls for the [information system](/usc/38/5727.md?p=13) or systems where [sensitive personal information](/usc/38/5727.md?p=19) is currently created, collected, processed, disseminated, or subject to disposal.
  - (2) Determining who has access to the system or systems containing [sensitive personal information](/usc/38/5727.md?p=19), including types of privileges and access rights.
  - (3) Ensuring the [VA National Rules of Behavior](/usc/38/5727.md?p=22) is signed on an annual basis and enforced by all system users to ensure appropriate use and protection of the information which is used to support [Department](/usc/38/101.md?p=1) missions and functions.
  - (4) Assisting the Assistant [Secretary](/usc/38/101.md?p=1) for Information and Technology in the identification and assessment of the common security controls for systems where their information resides.
  - (5) Providing assistance to Administration and staff office personnel involved in the development of new systems regarding the appropriate level of security controls for their information.
- (e) **Other Key Officials.—** In accordance with the provisions of subchapter III of [chapter 35](/usc/44/chch35.md) of title 44, the Under [Secretaries](/usc/38/101.md?p=1), Assistant [Secretaries](/usc/38/101.md?p=1), and other key officials of the [Department](/usc/38/101.md?p=1) are responsible for the following:
  - (1) Implementing the policies, procedures, practices, and other countermeasures identified in the [Department](/usc/38/101.md?p=1) [information security](/usc/38/5727.md?p=11) program that comprise activities that are under their day-to-day operational control or supervision.
  - (2) Periodically testing and evaluating [information security](/usc/38/5727.md?p=11) controls that comprise activities that are under their day-to-day operational control or supervision to ensure effective implementation.
  - (3) Providing a [plan of action and milestones](/usc/38/5727.md?p=16) to the Assistant [Secretary](/usc/38/101.md?p=1) for Information and Technology on at least a quarterly basis detailing the status of actions being taken to correct any security compliance failure or policy violation.
  - (4) Complying with the provisions of subchapter III of [chapter 35](/usc/44/chch35.md) of title 44 and other related [information security](/usc/38/5727.md?p=11) laws and requirements in accordance with orders of the Assistant [Secretary](/usc/38/101.md?p=1) for Information and Technology to execute the appropriate security controls commensurate to responding to a security bulletin of the Security Operations Center of the [Department](/usc/38/101.md?p=1), with such orders to supersede and take priority over all operational tasks and assignments and be complied with immediately.
  - (5) Ensuring that—
    - (A) all employees within their organizations take immediate action to comply with orders from the Assistant [Secretary](/usc/38/101.md?p=1) for Information and Technology to—
      - (i) mitigate the impact of any potential security vulnerability;
      - (ii) respond to a [security incident](/usc/38/5727.md?p=18); or
      - (iii) implement the provisions of a bulletin or alert of the Security Operations Center; and
    - (B) organizational managers have all necessary authority and means to direct full compliance with such orders from the Assistant [Secretary](/usc/38/101.md?p=1).
  - (6) Ensuring the [VA National Rules of Behavior](/usc/38/5727.md?p=22) is signed and enforced by all system users to ensure appropriate use and protection of the information which is used to support [Department](/usc/38/101.md?p=1) missions and functions on an annual basis.
- (f) **Users of Department Information and Information Systems.—** Users of [Department](/usc/38/101.md?p=1) information and [information systems](/usc/38/5727.md?p=13) are responsible for the following:
  - (1) Complying with all [Department](/usc/38/101.md?p=1) [information security](/usc/38/5727.md?p=11) program policies, procedures, and practices.
  - (2) Attending security awareness [training](/usc/38/5727.md?p=21) on at least an annual basis.
  - (3) Reporting all [security incidents](/usc/38/5727.md?p=18) immediately to the [Information Security](/usc/38/5727.md?p=11) Officer of the system or facility and to their immediate supervisor.
  - (4) Complying with orders from the Assistant [Secretary](/usc/38/101.md?p=1) for Information and Technology directing specific activities when a [security incident](/usc/38/5727.md?p=18) occurs.
  - (5) Signing an acknowledgment that they have read, understand, and agree to abide by the [VA National Rules of Behavior](/usc/38/5727.md?p=22) on an annual basis.
- (g) **Inspector General of Department of Veterans Affairs.—** In accordance with the provisions of subchapter III of [chapter 35](/usc/44/chch35.md) of title 44, the Inspector General of the [Department](/usc/38/101.md?p=1) is responsible for the following:
  - (1) Conducting an annual audit of the [Department](/usc/38/101.md?p=1) [information security](/usc/38/5727.md?p=11) program.
  - (2) Submitting an independent annual report to the Office of Management and Budget on the status of the [Department](/usc/38/101.md?p=1) [information security](/usc/38/5727.md?p=11) program, based on the results of the annual audit.
  - (3) Conducting investigations of complaints and referrals of violations as considered appropriate by the Inspector General.

## Source credit

(Added Pub. L. 109–461, title IX, § 902(a), Dec. 22, 2006, 120 Stat. 3451; amended Pub. L. 111–275, title X, § 1001(m)(1), Oct. 13, 2010, 124 Stat. 2897.)

## Notes

### Editorial Notes

### Amendments

2010—Subsec. (g)(2). Pub. L. 111–275 inserted “the” before “Department”.

### Statutory Notes and Related Subsidiaries

### Change of Name

Committee on Government Reform of House of Representatives changed to Committee on Oversight and Government Reform of House of Representatives by House Resolution No. 6, One Hundred Tenth Congress, Jan. 5, 2007. Committee on Oversight and Government Reform of House of Representatives changed to Committee on Oversight and Reform of House of Representatives by House Resolution No. 6, One Hundred Sixteenth Congress, Jan. 9, 2019. Committee on Oversight and Reform of House of Representatives changed to Committee on Oversight and Accountability of House of Representatives by House Resolution No. 5, One Hundred Eighteenth Congress, Jan. 9, 2023.
