Cybersecurity plans
Definitions
In this section—
the term “agency information system” means an information system used or operated by an agency or by another entity on behalf of an agency;
the terms “cybersecurity risk” and “information system” have the meanings given those terms in section 659 of this title;
the term “intelligence community” has the meaning given the term in section 3003(4) of title 50; and
the term “national security system” has the meaning given the term in section 11103 of title 40.
Intrusion assessment plan
Requirement
The Secretary, in coordination with the Director of the Office of Management and Budget, shall—
develop and implement an intrusion assessment plan to proactively detect, identify, and remove intruders in agency information systems on a routine basis; and
update such plan as necessary.