---
kind: "section"
citation: "44 U.S.C. § 3555"
title: "44"
title_heading: "Public Printing and Documents"
number: "3555"
heading: "Annual independent evaluation"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/44/3555"
units:
  - "Chapter 35 — Coordination of Federal Information Policy"
  - "Subchapter II — Information Security"
---

# §3555. Annual independent evaluation

- (a) **In General.—**
  - (1) Each year each [agency](/usc/44/3502.md?p=1) shall have performed an independent evaluation of the [information security](/usc/44/3552.md?p=b-3) program and practices of that [agency](/usc/44/3502.md?p=1) to determine the effectiveness of such program and practices.
  - (2) Each evaluation under this section shall include—
    - (A) testing of the effectiveness of [information security](/usc/44/3552.md?p=b-3) policies, procedures, and practices of a representative subset of the [agency](/usc/44/3502.md?p=1)’s [information systems](/usc/44/3502.md?p=8);
    - (B) an assessment of the effectiveness of the [information security](/usc/44/3552.md?p=b-3) policies, procedures, and practices of the [agency](/usc/44/3502.md?p=1); and
    - (C) separate presentations, as appropriate, regarding [information security](/usc/44/3552.md?p=b-3) relating to [national security systems](/usc/44/3552.md?p=b-6-A).
- (b) **Independent Auditor.—** Subject to [subsection (c)](#c)—
  - (1) for each [agency](/usc/44/3502.md?p=1) with an Inspector General appointed under [chapter 4](/usc/5/chptI/ch4.md) of title 5, the annual evaluation required by this section shall be performed by the Inspector General or by an independent external auditor, as determined by the Inspector General of the [agency](/usc/44/3502.md?p=1); and
  - (2) for each [agency](/usc/44/3502.md?p=1) to which [paragraph (1)](#b-1) does not apply, the head of the [agency](/usc/44/3502.md?p=1) shall engage an independent external auditor to perform the evaluation.
- (c) **National Security Systems.—** For each [agency](/usc/44/3502.md?p=1) operating or exercising control of a [national security system](/usc/44/3552.md?p=b-6-A), that portion of the evaluation required by this section directly relating to a [national security system](/usc/44/3552.md?p=b-6-A) shall be performed—
  - (1) only by an entity designated by the [agency](/usc/44/3502.md?p=1) head; and
  - (2) in such a manner as to ensure appropriate protection for information associated with any [information security](/usc/44/3552.md?p=b-3) vulnerability in such system commensurate with the risk and in accordance with all applicable laws.
- (d) **Existing Evaluations.—** The evaluation required by this section may be based in whole or in part on an audit, evaluation, or report relating to programs or practices of the applicable [agency](/usc/44/3502.md?p=1).
- (e) **Agency Reporting.—**
  - (1) Each year, not later than such date established by the [Director](/usc/44/3502.md?p=4), the head of each [agency](/usc/44/3502.md?p=1) shall submit to the [Director](/usc/44/3502.md?p=4) the results of the evaluation required under this section.
  - (2) To the extent an evaluation required under this section directly relates to a [national security system](/usc/44/3552.md?p=b-6-A), the evaluation results submitted to the [Director](/usc/44/3502.md?p=4) shall contain only a summary and assessment of that portion of the evaluation directly relating to a [national security system](/usc/44/3552.md?p=b-6-A).
- (f) **Protection of Information.—** [Agencies](/usc/44/3502.md?p=1) and evaluators shall take appropriate steps to ensure the protection of information which, if disclosed, may adversely affect [information security](/usc/44/3552.md?p=b-3). Such protections shall be commensurate with the risk and comply with all applicable laws and regulations.
- (g) **OMB Reports to Congress.—**
  - (1) The [Director](/usc/44/3502.md?p=4) shall summarize the results of the evaluations conducted under this section in the report to Congress required under [section 3553(c)](/usc/44/3553.md?p=c).
  - (2) The [Director](/usc/44/3502.md?p=4)’s report to Congress under this subsection shall summarize information regarding [information security](/usc/44/3552.md?p=b-3) relating to [national security systems](/usc/44/3552.md?p=b-6-A) in such a manner as to ensure appropriate protection for information associated with any [information security](/usc/44/3552.md?p=b-3) vulnerability in such system commensurate with the risk and in accordance with all applicable laws.
  - (3) Evaluations and any other descriptions of [information systems](/usc/44/3502.md?p=8) under the authority and control of the [Director](/usc/44/3502.md?p=4) of National Intelligence or of National Foreign Intelligence Programs systems under the authority and control of the [Secretary](/usc/44/3552.md?p=b-7) of Defense shall be made available to Congress only through the appropriate oversight committees of Congress, in accordance with applicable laws.
- (h) **Comptroller General.—** The Comptroller General shall periodically evaluate and report to Congress on—
  - (1) the adequacy and effectiveness of [agency](/usc/44/3502.md?p=1) [information security](/usc/44/3552.md?p=b-3) policies and practices; and
  - (2) implementation of the requirements of this subchapter.
- (i) **Assessment Technical Assistance.—** The Comptroller General may provide technical assistance to an Inspector General or the head of an [agency](/usc/44/3502.md?p=1), as applicable, to assist the Inspector General or head of an [agency](/usc/44/3502.md?p=1) in carrying out the duties under this section, including by testing [information security](/usc/44/3552.md?p=b-3) controls and procedures.
- (j) **Guidance.—** The [Director](/usc/44/3502.md?p=4), in consultation with the [Secretary](/usc/44/3552.md?p=b-7), the Chief Information Officers Council established under [section 3603](/usc/44/3603.md), the Council of the Inspectors General on Integrity and Efficiency, and other interested parties as appropriate, shall ensure the development of guidance for evaluating the effectiveness of an [information security](/usc/44/3552.md?p=b-3) program and practices.

## Source credit

(Added Pub. L. 113–283, § 2(a), Dec. 18, 2014, 128 Stat. 3082; amended Pub. L. 117–286, § 4(b)(89), Dec. 27, 2022, 136 Stat. 4352.)

## Notes

### Editorial Notes

### Prior Provisions

Provisions similar to this section were contained in sections 3535 and 3545 of this title prior to repeal by Pub. L. 113–283.

### Amendments

2022—Subsec. (b)(1). Pub. L. 117–286 substituted “chapter 4 of title 5,” for “the Inspector General Act of 1978,”.
