---
kind: "section"
citation: "6 U.S.C. § 1522"
title: "6"
title_heading: "Domestic Security"
number: "1522"
heading: "Advanced internal defenses"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/6/1522"
units:
  - "Chapter 6 — Cybersecurity"
  - "Subchapter II — Federal Cybersecurity Enhancement"
---

# §1522. Advanced internal defenses

- (a) **Advanced network security tools—**
  - (1) **In general—** The [Secretary](/usc/6/1521.md?p=8) shall include, in the efforts of the [Department](/usc/6/101.md?p=5) to continuously diagnose and mitigate [cybersecurity risks](/usc/6/1521.md?p=4), advanced network security tools to improve visibility of network activity, including through the use of commercial and free or open source tools, and to detect and mitigate intrusions and anomalous activity.
  - (2) **Development of plan—** The [Director](/usc/6/1521.md?p=5) shall develop and the [Secretary](/usc/6/1521.md?p=8) shall implement a plan to ensure that each [agency](/usc/6/1501.md?p=1) utilizes advanced network security tools, including those described in [paragraph (1)](#a-1), to detect and mitigate intrusions and anomalous activity.
- (b) **Prioritizing advanced security tools—** The [Director](/usc/6/1521.md?p=5) and the [Secretary](/usc/6/1521.md?p=8), in consultation with appropriate [agencies](/usc/6/1501.md?p=1), shall—
  - (1) review and update Government-wide policies and programs to ensure appropriate prioritization and use of network security monitoring tools within [agency](/usc/6/1501.md?p=1) networks; and
  - (2) brief [appropriate congressional committees](/usc/6/1521.md?p=3) on such prioritization and use.
- (c) **Improved metrics—** The [Secretary](/usc/6/1521.md?p=8), in collaboration with the [Director](/usc/6/1521.md?p=5), shall review and update the metrics used to measure security under [section 3554 of title 44](/usc/44/3554.md) to include measures of intrusion and [incident](/usc/6/677a.md?p=6) detection and response times.
- (d) **Transparency and accountability—** The [Director](/usc/6/1521.md?p=5), in consultation with the [Secretary](/usc/6/1521.md?p=8), shall increase transparency to the public on [agency](/usc/6/1501.md?p=1) cybersecurity posture, including by increasing the number of metrics available on Federal Government performance websites and, to the greatest extent practicable, displaying metrics for [department](/usc/6/101.md?p=5) components, small [agencies](/usc/6/1501.md?p=1), and micro-[agencies](/usc/6/1501.md?p=1).
- (e) **Omitted—**
- (f) **Exception—** The requirements under this section shall not apply to the [Department](/usc/6/101.md?p=5) of Defense, a [national security system](/usc/6/1521.md?p=7), or an element of the [intelligence community](/usc/6/1521.md?p=6).

## Source credit

(Pub. L. 114–113, div. N, title II, § 224, Dec. 18, 2015, 129 Stat. 2967.)

## Notes

### Editorial Notes

### Codification

Section is comprised of section 224 of title II of div. N of Pub. L. 114–113. Subsec. (e) of section 224 of title II of div. N of Pub. L. 114–113 amended section 3553 of Title 44, Public Printing and Documents.
