The Administrator shall establish procedures that require each contractor and subcontractor to report to the Chief Information Officer when a covered network of the contractor or subcontractor that meets the criteria established pursuant to subsection (b) is successfully penetrated.
The Administrator shall, in consultation with the officials specified in paragraph (2), establish criteria for covered networks to be subject to the procedures for reporting penetrations under subsection (a).
The officials specified in this paragraph are the following officials of the Administration:
The procedures established pursuant to subsection (a) shall require each contractor or subcontractor to submit to the Chief Information Officer a report on each successful penetration of a covered network of the contractor or subcontractor that meets the criteria established pursuant to subsection (b) not later than 60 days after the discovery of the successful penetration.
Subject to subparagraph (C), each report required by subparagraph (A) with respect to a successful penetration of a covered network of a contractor or subcontractor shall include the following:
If a contractor or subcontractor is not able to obtain all of the information required by subparagraph (B) to be included in a report required by subparagraph (A) by the date that is 60 days after the discovery of a successful penetration of a covered network of the contractor or subcontractor, the contractor or subcontractor shall-
Concurrent with the establishment of the procedures pursuant to subsection (a), the Administrator shall establish procedures to be used if information owned by the Administration was in use during or at risk as a result of the successful penetration of a covered network-
The procedures established pursuant to subsection (a) shall allow for limiting the dissemination of information obtained or derived through such procedures so that such information may be disseminated only to entities-
In this section:
The term "Chief Information Officer" means the Associate Administrator for Information Management and Chief Information Officer of the Administration.
The term "contractor" means a private entity that has entered into a contract or contractual action of any kind with the Administration to furnish supplies, equipment, materials, or services of any kind.
The term "covered network" includes any network or information system that accesses, receives, or stores-
The term "subcontractor" means a private entity that has entered into a contract or contractual action with a contractor or another subcontractor to furnish supplies, equipment, materials, or services of any kind in connection with another contract in support of any program of the Administration.
50 U.S.C. § 2662
- Administration
- The term "Administration" means the National Nuclear Security Administration.
- Administrator
- The term "Administrator" means the Administrator for Nuclear Security.
- classified information
- The term "classified information" means any information that has been determined pursuant to Executive Order No. 12333 of December 4, 1981 (50 U.S.C. 3001 note), Executive Order No. 12958 of April 17, 1995 (50 U.S.C. 3161 note), Executive Order No. 13526 of December 29, 2009 (50 U.S.C. 3161 note), or successor orders, to require protection against unauthorized disclosure and that is so designated.