Files
republic-os/legal/us/code/title-06/chapter-6/section-1523.md
T
Fabio 00a184bb3c Legal corpus: U.S. Code titles 1–11 from pinned OLRC XML (11,050 sections)
Raw OLRC USLM XML zips @ release 119-100 (retrieved 2026-07-04 via
Atlas depot), ingested with the standard pipeline: raw snapshot ->
per-section OKF markdown -> manifest + checksums. Title 52 untouched.
LegalText: 171 -> 11,221. Titles 12-54 await a clean OLRC retry.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 09:52:37 -04:00

4.9 KiB
Raw Blame History

type, title, description, jurisdiction, corpus, kind, title_number, title_name, chapter_number, chapter_name, section, citation, status, release_point, release_date, source, source_url, source_identifier, source_file, source_hash, raw_snapshot_hash, text_hash, retrieved_at, confidence, tags
type title description jurisdiction corpus kind title_number title_name chapter_number chapter_name section citation status release_point release_date source source_url source_identifier source_file source_hash raw_snapshot_hash text_hash retrieved_at confidence tags
LegalText 6 U.S.C. § 1523 Federal cybersecurity requirements us united_states_code code_section 6 DOMESTIC SECURITY 6 CYBERSECURITY 1523 6 U.S.C. § 1523 current 119-100 2026-06-26 official https://uscode.house.gov/download/releasepoints/us/pl/119/100/xml_usc06@119-100.zip /us/usc/t6/s1523 data/legal/raw/us/code/title-06/usc06.xml 8cd003be5d282430f418905185a37f91eb8fd638858cf467f86de1f527db4dd7 a286ebc069cd8c7d317b4084d217abe94cd2a3642b1a3e409a909d1e92452161 f861a798fc2df1fe642f6aa5ffd6bee5442e4b2e12f3a67f94dbbd9aeb02c6ab 2026-07-04 official
legal
us-code

6 U.S.C. § 1523 - Federal cybersecurity requirements

Text

(a) Implementation of Federal cybersecurity standards Consistent with section 3553 of title 44, the Secretary, in consultation with the Director, shall exercise the authority to issue binding operational directives to assist the Director in ensuring timely agency adoption of and compliance with policies and standards promulgated under section 11331 of title 40 11 See References in Text note below. for securing agency information systems.

(b) Cybersecurity requirements at agencies (1) In general Consistent with policies, standards, guidelines, and directives on information security under subchapter II of chapter 35 of title 44 and the standards and guidelines promulgated under section 11331 of title 40 and except as provided in paragraph (2), not later than 1 year after December 18, 2015, the head of each agency shall—

(A) identify sensitive and mission critical data stored by the agency consistent with the inventory required under the first subsection (c) (relating to the inventory of major information systems) and the second subsection (c) (relating to the inventory of information systems) of section 3505 of title 44;

(B) assess access controls to the data described in subparagraph (A), the need for readily accessible storage of the data, and individuals need to access the data;

(C) encrypt or otherwise render indecipherable to unauthorized users the data described in subparagraph (A) that is stored on or transiting agency information systems;

(D) implement a single sign-on trusted identity platform for individuals accessing each public website of the agency that requires user authentication, as developed by the Administrator of General Services in collaboration with the Secretary; and

(E) implement identity management consistent with section 7464 of title 15, including multi-factor authentication, for—

(i) remote access to an agency information system; and

(ii) each user account with elevated privileges on an agency information system.

(2) Exception The requirements under paragraph (1) shall not apply to an agency information system for which—

(A) the head of the agency has personally certified to the Director with particularity that—

(i) operational requirements articulated in the certification and related to the agency information system would make it excessively burdensome to implement the cybersecurity requirement;

(ii) the cybersecurity requirement is not necessary to secure the agency information system or agency information stored on or transiting it; and

(iii) the agency has taken all necessary steps to secure the agency information system and agency information stored on or transiting it; and

(B) the head of the agency or the designee of the head of the agency has submitted the certification described in subparagraph (A) to the appropriate congressional committees and the agencys authorizing committees.

(3) Construction Nothing in this section shall be construed to alter the authority of the Secretary, the Director, or the Director of the National Institute of Standards and Technology in implementing subchapter II of chapter 35 of title 44. Nothing in this section shall be construed to affect the National Institute of Standards and Technology standards process or the requirement under section 3553(a)(4) of such title or to discourage continued improvements and advancements in the technology, standards, policies, and guidelines used to promote Federal information security.

(c) Exception The requirements under this section shall not apply to the Department of Defense, a national security system, or an element of the intelligence community.

(Pub. L. 114113, div. N, title II, § 225, Dec. 18, 2015, 129 Stat. 2967.)

Notes

Editorial Notes

References in TextThe text of section 11331 of title 40, referred to in subsec. (a), was generally amended by Pub. L. 117167, div. B, title II, § 10246(f), Aug. 9, 2022, 136 Stat. 1492, so as to provide for the prescription by the Secretary of Commerce of standards and guidelines pertaining to Federal information systems.