Files
republic-os/legal/us/code/title-42/chapter-159/section-18445.md
Fabio 76b8ec33a7 Legal corpus: the complete U.S. Code (59,740 sections, all 53 titles)
Ingested titles 12–51 and 54 from OLRC USLM XML @119-100 (the whole Code
now, uniform edition; Title 53 is reserved/empty). LegalText 11,221 ->
59,740; repo total 105,704 records. Deterministic (byte-identical rerun,
verified on Title 42's 8,356 sections); make check green. make
legal-us-code default now covers every title.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 10:51:44 -04:00

3.9 KiB
Raw Permalink Blame History

type, title, description, jurisdiction, corpus, kind, title_number, title_name, chapter_number, chapter_name, section, citation, status, release_point, release_date, source, source_url, source_identifier, source_file, source_hash, raw_snapshot_hash, text_hash, retrieved_at, confidence, tags
type title description jurisdiction corpus kind title_number title_name chapter_number chapter_name section citation status release_point release_date source source_url source_identifier source_file source_hash raw_snapshot_hash text_hash retrieved_at confidence tags
LegalText 42 U.S.C. § 18445 Information security us united_states_code code_section 42 THE PUBLIC HEALTH AND WELFARE 159 SPACE EXPLORATION, TECHNOLOGY, AND SCIENCE 18445 42 U.S.C. § 18445 current 119-100 2026-06-26 official https://uscode.house.gov/download/releasepoints/us/pl/119/100/xml_usc42@119-100.zip /us/usc/t42/s18445 data/legal/raw/us/code/title-42/usc42.xml 18308bd53b9b88913ecb8475576274ded93bab1e160a5104d1826e767a127f35 644321055a08eb1f260a6a3e31ac157fa024756abf612a9fd6857e7e400cf24e 3575e4c020f08b335aa42b5ce8720a30a7cc85588e4985ce9dd5d40c75049e65 2026-07-04 official
legal
us-code

42 U.S.C. § 18445 - Information security

Text

(a) Monitoring risk (1) Update on system implementation Not later than 120 days after October 11, 2010, and on a biennial basis thereafter, the chief information officer of NASA, in coordination with other national security agencies, shall provide to the appropriate committees of Congress—

(A) an update on efforts to implement a system to provide dynamic, comprehensive, real-time information regarding risk of unauthorized remote, proximity, and insider use or access, for all information infrastructure under the responsibility of the chief information officer, and mission-related networks, including contractor networks;

(B) an assessment of whether the system has demonstrably and quantifiably reduced network risk compared to alternative methods of measuring security; and

(C) an assessment of the progress that each center and facility has made toward implementing the system.

(2) Existing assessments The assessments required of the Inspector General under section 3545 11 See References in Text note below. of title 44 shall evaluate the effectiveness of the system described in this subsection.

(b) Information security awareness and education (1) In general In consultation with the Department of Education, other national security agencies, and other agency directorates, the chief information officer shall institute an information security awareness and education program for all operators and users of NASA information infrastructure, with the goal of reducing unauthorized remote, proximity, and insider use or access.

(2) Program requirements (A) The program shall include, at a minimum, ongoing classified and unclassified threat-based briefings, and automated exercises and examinations that simulate common attack techniques.

(B) All agency employees and contractors engaged in the operation or use of agency information infrastructure shall participate in the program.

(C) Access to NASA information infrastructure shall only be granted to operators and users who regularly satisfy the requirements of the program.

(D) The chief human capital officer of NASA, in consultation with the chief information officer, shall create a system to reward operators and users of agency information infrastructure for continuous high achievement in the program.

(c) Information infrastructure defined In this section, the term “information infrastructure” means the underlying framework that information systems and assets rely on to process, transmit, receive, or store information electronically, including programmable electronic devices and communications networks and any associated hardware, software, or data.

(Pub. L. 111267, title XII, § 1207, Oct. 11, 2010, 124 Stat. 2844.)

Notes

Editorial Notes

References in TextSection 3545 of title 44, referred to in subsec. (a)(2), was repealed by Pub. L. 113283, § 2(a), Dec. 18, 2014, 128 Stat. 3073. Provisions similar to section 3545 of title 44 are now contained in section 3555 of title 44, as enacted by Pub. L. 113283.