Title 38 › Part PART IV— - GENERAL ADMINISTRATIVE PROVISIONS › Chapter CHAPTER 57— - RECORDS AND INVESTIGATIONS › Subchapter SUBCHAPTER III— - INFORMATION SECURITY › § 5723
Require the Secretary to run a single, Department-wide information security program that follows Federal standards. The Secretary must make sure security matches the risks, is part of planning, and that top leaders protect the information they control. The Secretary must enforce rules, train staff, give the Assistant Secretary for Information and Technology (the Department’s Chief Information Officer) the authority to set and run policies across the Department, report on program effectiveness and fixes to Congress, OMB, and others, and send a compliance report to the Committees on Veterans’ Affairs of the Senate and House of Representatives, the Committee on Government Reform of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs of the Senate by March 1 each year. The Secretary must also make sure the President’s budget shows separate amounts for information security compliance and must notify OMB, the Department Inspector General, and other agencies when a presumptive breach affects the information of 20 or more people. Give the Assistant Secretary (the CIO) the job of writing, approving, and enforcing security policies, setting technical and access rules consistent with NIST, running incident reporting, and ordering Department-wide compliance. The CIO must require quick reporting and fixes for policy failures, send quarterly reports to the Secretary about any compliance gaps, and notify the Secretary immediately of any presumptive data breach. The Senior Information Security Officer may carry out the CIO’s duties. Department information owners must help set security needs, decide who gets system access, and enforce annual signing of the VA National Rules of Behavior. Under Secretaries and other key officials must put policies into action, test controls, give quarterly plans for fixes, and make sure staff follow CIO orders during incidents. All system users must follow the rules, take yearly security training, report incidents right away, and sign the VA National Rules of Behavior each year. The Inspector General must audit the security program every year, send an independent annual report to OMB, and investigate complaints or possible violations.
Full Legal Text
Veterans' Benefits — Source: USLM XML via OLRC
Legislative History
Reference
Citation
38 U.S.C. § 5723
Title 38 — Veterans' Benefits
Last Updated
Apr 6, 2026
Release point: 119-73