Title 50War and National DefenseRelease 119-73

§2412 Cybersecurity Risk Inventory, Assessment, and Mitigation Working Group

Title 50 › Chapter CHAPTER 41— - NATIONAL NUCLEAR SECURITY ADMINISTRATION › Subchapter SUBCHAPTER I— - ESTABLISHMENT AND ORGANIZATION › § 2412

Last updated Apr 6, 2026|Official source

Summary

Creates a working group inside the Administration called the Cybersecurity Risk Inventory, Assessment, and Mitigation Working Group. The group must include the Deputy Administrator for Defense Programs, the Associate Administrator for Information Management and Chief Information Officer, and other staff the chair picks. The Deputy Administrator for Defense Programs leads the group unless the Administrator names a different chair. The group must make a detailed plan to list systems in operational technology and nuclear weapons IT that might be at risk, rank those risks by mission impact, and carry out fixes. The plan must show goals, tasks, how people and offices will work together, the resources needed through 2034, and schedules with milestones. The group must brief the congressional defense committees within 120 days after December 22, 2023, and give the finished plan by April 1, 2025. The group ends on a date the Administrator sets, but not before five years after December 22, 2023.

Full Legal Text

Title 50, §2412

War and National Defense — Source: USLM XML via OLRC

(a)There is in the Administration a working group, to be known as the “Cybersecurity Risk Inventory, Assessment, and Mitigation Working Group” (referred to in this section as the “working group”).
(b)Members of the working group shall include—
(1)the Deputy Administrator for Defense Programs;
(2)the Associate Administrator for Information Management and Chief Information Officer; and
(3)such other personnel of the Administration as are determined appropriate for inclusion in the working group by the Chairperson.
(c)The Deputy Administrator for Defense Programs shall serve as the Chairperson of the working group, except that the Administrator may designate another member of the working group to serve as Chairperson in lieu of the Deputy Administrator if the Administrator determines it is appropriate to do so.
(d)The working group shall prepare a comprehensive strategy for inventorying the range of systems of the Administration that are potentially at risk in the operational technology and nuclear weapons information technology environments, assessing the systems at risk based on mission impact, and implementing risk mitigation actions. Such strategy shall incorporate key elements of effective cybersecurity risk management strategies, as identified by the Government Accountability Office, including the specification of—
(1)goals, objectives, activities, and performance measures;
(2)organizational roles, responsibilities, and coordination;
(3)resources needed to implement the strategy through 2034; and
(4)detailed milestones and schedules for completion of tasks.
(e)(1)Not later than 120 days after December 22, 2023, the working group shall provide to the congressional defense committees a briefing on the plan of the working group to develop the strategy required under subsection (d).
(2)Not later than April 1, 2025, the working group shall submit the congressional defense committees a copy of the completed strategy.
(f)The working group shall terminate on a date determined by the Administrator that is not earlier than the date that is five years after December 22, 2023.

Reference

Citations & Metadata

Citation

50 U.S.C. § 2412

Title 50War and National Defense

Last Updated

Apr 6, 2026

Release point: 119-73