§3554. Federal agency responsibilities — Inbound Citations
44 U.S.C. § 3554
Cited by 11 provisions in release 119-102.
Citations to 44 U.S.C. § 3554 as a whole
-
(c) The Secretary, in collaboration with the Director, shall review and update the metrics used to measure security under section 3554 of title 44 to include measures of intrusion and incident detection and response times.
-
(B) to review and determine prevalent information security challenges and deficiencies identified by agencies or the Institute, including any challenges or deficiencies described in any of the annual reports under section 3553 or 3554 of title 44, and in any of the reports and the independent evaluations under section 3555 of that title, that may undermine the effectiveness of agency information security programs and practices; and
-
(2) Each report required under paragraph (1) may be submitted as part of the report required under section 3554 of title 44.
-
(A) Notwithstanding section 3554, the Secretary may authorize the use under this subsection of the intrusion detection and prevention capabilities established under section 230(b)(1)1 of the Homeland Security Act of 2002 for the purpose of ensuring the security of agency information systems, if—(i) the Secretary determines there is an imminent threat to agency information systems;(ii) the Secretary determines a directive under subsection (b)(2)(C) or paragraph (1)(A) is not reasonably likely to result in a timely response to the threat;(iii) the Secretary determines the risk posed by the imminent threat outweighs any adverse consequences reasonably expected to result from the use of the intrusion detection and prevention capabilities under the control of the Secretary;(iv) the Secretary provides prior notice to the Director, and the head and chief information officer (or equivalent official) of each agency to which specific actions will be taken pursuant to this paragraph, and notifies the appropriate congressional committees and authorizing committees of each such agency within 7 days of taking an action under this paragraph of—(I) any action taken under this paragraph; and(II) the reasons for and duration and nature of the action;(v) the action of the Secretary is consistent with applicable law; and(vi) the Secretary authorizes the use of the intrusion detection and prevention capabilities in accordance with the advance procedures established under subparagraph (C).
-
(d) The Administrator shall establish annual metrics regarding the time and quality of the assessments necessary for completion of a FedRAMP authorization process in a manner that can be consistently tracked over time in conjunction with the periodic testing and evaluation process pursuant to section 3554 in a manner that minimizes the agency reporting burden.
Citations to §3554(b)
-
(1) In developing the agencywide information security program required by section 3554(b) of title 44, an agency that deploys a computer hardware or software system for which the Director of the National Institute of Standards and Technology has developed a checklist under subsection (c) of this section—(A) shall include in that program an explanation of how the agency has considered such checklist in deploying that system; and(B) may treat the explanation as if it were a portion of the agency’s annual performance plan properly classified under criteria established by an Executive Order (within the meaning of section 1115(d) of title 31).
-
(A) providing services, functions, and capabilities, including operation of the agency’s information security program, to assist the agency with meeting the requirements set forth in section 3554(b); and
-
(4) provide, as appropriate, intelligence and other information about cyber threats, vulnerabilities, and incidents to agencies to assist in risk assessments conducted under section 3554(b); and
Citations to §3554(c)(1)
-
(B) requirements for the contents of the annual reports required to be submitted under section 3554(c)(1);
-
(1) a summary of the incidents described in the annual reports required to be submitted under section 3554(c)(1), including a summary of the information required under section 3554(c)(1)(A)(iii);
Citations to §3554(c)(1)(A)(iii)
-
(1) a summary of the incidents described in the annual reports required to be submitted under section 3554(c)(1), including a summary of the information required under section 3554(c)(1)(A)(iii);