Title 38 › Part PART IV— - GENERAL ADMINISTRATIVE PROVISIONS › Chapter CHAPTER 57— - RECORDS AND INVESTIGATIONS › Subchapter SUBCHAPTER III— - INFORMATION SECURITY › § 5722
The Secretary must set up and keep a department-wide information security program to protect Department information in any form and the Department’s information systems. The program must include risk assessments, policies that lower risk and cover each system from start to finish, and required technical, operational, and management security controls. It must also have plans for networks and facilities, annual security training for all employees, contractors, and other users of VA sensitive data and systems, and a way to find and fix security problems. The program must test controls regularly, including certification testing of all controls every three years and yearly testing of a subset for each system. It must include procedures to detect, report, and respond to incidents (and to notify the U.S. Computer Emergency Readiness Team at DHS, law enforcement, the Department’s Inspector General, and others) and plans to keep systems running during disruptions. The Secretary must follow subchapter III of chapter 35 of title 44 and related rules from NIST and OMB.
Full Legal Text
Veterans' Benefits — Source: USLM XML via OLRC
Reference
Citation
38 U.S.C. § 5722
Title 38 — Veterans' Benefits
Last Updated
Apr 6, 2026
Release point: 119-73