Files
republic-os/legal/us/code/title-10/chapter-131/section-2225.md
T
Fabio 00a184bb3c Legal corpus: U.S. Code titles 1–11 from pinned OLRC XML (11,050 sections)
Raw OLRC USLM XML zips @ release 119-100 (retrieved 2026-07-04 via
Atlas depot), ingested with the standard pipeline: raw snapshot ->
per-section OKF markdown -> manifest + checksums. Title 52 untouched.
LegalText: 171 -> 11,221. Titles 12-54 await a clean OLRC retry.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 09:52:37 -04:00

4.5 KiB
Raw Blame History

type, title, description, jurisdiction, corpus, kind, title_number, title_name, chapter_number, chapter_name, section, citation, status, release_point, release_date, source, source_url, source_identifier, source_file, source_hash, raw_snapshot_hash, text_hash, retrieved_at, confidence, tags
type title description jurisdiction corpus kind title_number title_name chapter_number chapter_name section citation status release_point release_date source source_url source_identifier source_file source_hash raw_snapshot_hash text_hash retrieved_at confidence tags
LegalText 10 U.S.C. § 2225 Insider threat detection us united_states_code code_section 10 ARMED FORCES 131 PLANNING AND COORDINATION 2225 10 U.S.C. § 2225 current 119-100 2026-06-26 official https://uscode.house.gov/download/releasepoints/us/pl/119/100/xml_usc10@119-100.zip /us/usc/t10/s2225 data/legal/raw/us/code/title-10/usc10.xml 04bded6f7285eb00a2d46561da18702a4aace91e14e024d910ad888575df3b40 06a2679d38355c44f4219c983fdad34009233205d6ba271593a4c1b17a739ec1 86e7987416a34b6d43743e14029b0700ef7df3c43dbeeda753945ba74279f6ad 2026-07-04 official
legal
us-code

10 U.S.C. § 2225 - Insider threat detection

Text

(a) Program Required.— The Secretary of Defense shall establish a program for information sharing protection and insider threat mitigation for the information systems of the Department of Defense to detect unauthorized access to, use of, or transmission of classified or controlled unclassified information.

(b) Elements.— The program established under subsection (a) shall include the following:

(1) Technology solutions for deployment within the Department of Defense that allow for centralized monitoring and detection of unauthorized activities, including—

(A) monitoring the use of external ports and read and write capability controls;

(B) disabling the removable media ports of computers physically or electronically;

(C) electronic auditing and reporting of unusual and unauthorized user activities;

(D) using data-loss prevention and data-rights management technology to prevent the unauthorized export of information from a network or to render such information unusable in the event of the unauthorized export of such information;

(E) a roles-based access certification system;

(F) cross-domain guards for transfers of information between different networks; and

(G) patch management for software and security updates.

(2) Policies and procedures to support such program, including special consideration for policies and procedures related to international and interagency partners and activities in support of ongoing operations in areas of hostilities.

(3) A governance structure and process that integrates information security and sharing technologies with the policies and procedures referred to in paragraph (2). Such structure and process shall include—

(A) coordination with the existing security clearance and suitability review process;

(B) coordination of existing anomaly detection techniques, including those used in counterintelligence investigation or personnel screening activities; and

(C) updating and expediting of the classification review and marking process.

(4) A continuing analysis of—

(A) gaps in security measures under the program; and

(B) technology, policies, and processes needed to increase the capability of the program beyond the initially established full operating capability to address such gaps.

(5) A baseline analysis framework that includes measures of performance and effectiveness.

(6) A plan for how to ensure related security measures are put in place for other departments or agencies with access to Department of Defense networks.

(7) A plan for enforcement to ensure that the program is being applied and implemented on a uniform and consistent basis.

(Added Pub. L. 11960, div. A, title XVI, § 1623(a), Dec. 18, 2025, 139 Stat. 1183.)

Notes

Editorial Notes

Codification Text of section, as added by Pub. L. 11960, is based on text of subsecs. (a) and (b) of section 922 of Pub. L. 11281, div. A, title IX, Dec. 31, 2011, 125 Stat. 1537, which was formerly set out in a note under section 2224 of this title, prior to repeal by Pub. L. 11960, div. A, title XVI, § 1623(b), Dec. 18, 2025, 139 Stat. 1183.

Prior ProvisionsA prior section 2225, added Pub. L. 106398, § 1 [[div. A], title VIII, § 812(a)(1)], Oct. 30, 2000, 114 Stat. 1654, 1654A212; amended Pub. L. 108178, § 4(b)(2), Dec. 15, 2003, 117 Stat. 2640; Pub. L. 109364, div. A, title X, § 1071(a)(2), Oct. 17, 2006, 120 Stat. 2398; Pub. L. 111350, § 5(b)(6), Jan. 4, 2011, 124 Stat. 3842, related to tracking and management of information technology purchases, prior to repeal by Pub. L. 114328, div. A, title VIII, § 833(b)(2)(A), Dec. 23, 2016, 130 Stat. 2284.