Title 38 › Part IV— GENERAL ADMINISTRATIVE PROVISIONS › Chapter 57— RECORDS AND INVESTIGATIONS › Subchapter III— INFORMATION SECURITY › § 5722
The Secretary must create and keep a department-wide information security program. The program must protect Department information in any format and the systems that store or use it. It must use cost-effective security controls. The program must do regular risk checks and have risk-based policies and procedures that lower risks and cover systems through their life cycle. It must pick and use minimum required technical, operational, and management controls (or other countermeasures). It must include plans for networks, facilities, and groups of systems; annual security training for all employees, contractors, and other users of VA sensitive data and Department systems; testing and evaluation of controls (including triennial certification testing of all management, operational, and technical controls and annual testing of a subset for each system); a process to fix security gaps; immediate incident detection, reporting, and response with notifications to US‑CERT (DHS), law enforcement, and the Department Inspector General as needed; and continuity plans. The Secretary must follow subchapter III of chapter 35 of title 44 and related NIST and OMB security rules.
Full Legal Text
Veterans' Benefits — Source: USLM XML via OLRC
Reference
Citation
38 U.S.C. § 5722
Title 38 — Veterans' Benefits
Last Updated
Apr 5, 2026
Release point: 119-73not60