Title 6 › Chapter CHAPTER 6— - CYBERSECURITY › Subchapter SUBCHAPTER II— - FEDERAL CYBERSECURITY ENHANCEMENT › § 1523
The Secretary, working with the Director, must issue binding orders to help make sure federal agencies quickly adopt and follow federal cybersecurity policies and standards for protecting agency computer systems. Within 1 year after December 18, 2015, each agency head must find and list sensitive and mission‑critical data, check who needs access and how it is controlled, make that data unreadable to anyone not allowed to see it (both when stored and when sent), use a single sign‑on trusted identity system for public websites that require login, and use identity management with multi‑factor authentication for remote access and for accounts with special privileges. An agency can be exempt only if the agency head personally certifies to the Director that it would be overly burdensome, is not needed to secure the system, and the agency has taken all needed security steps, and that certification is sent to the right congressional and authorizing committees. These rules do not apply to the Department of Defense, national security systems, or the intelligence community, and they do not change the roles or standards process of the Secretary, the Director, or NIST.
Full Legal Text
Domestic Security — Source: USLM XML via OLRC
Legislative History
Reference
Citation
6 U.S.C. § 1523
Title 6 — Domestic Security
Last Updated
Apr 6, 2026
Release point: 119-73