Title 38 › Part IV— GENERAL ADMINISTRATIVE PROVISIONS › Chapter 57— RECORDS AND INVESTIGATIONS › Subchapter III— INFORMATION SECURITY › § 5727
Defines key words used for protecting and handling Department information and computer systems. Availability means people can get and use information when they need it. Confidentiality means keeping access limited so private or business information stays secret. Control techniques are methods to run and check systems so they follow federal security rules. Data breach means loss, theft, or other unauthorized access to sensitive personal info (paper or electronic) that could hurt its secrecy or correctness. Data breach analysis is checking whether a breach led to misuse of that info. Fraud resolution services help someone fix their credit after identity theft. Identity theft is defined in section 603 of the Fair Credit Reporting Act (15 U.S.C. 1681a). Identity theft insurance pays costs like travel, notary, postage, lost wages, and legal fees to repair identity theft harm. Information owner is the agency official who has authority and responsibility for specific information and how it’s handled, possibly across linked systems. Information resources means information in any form plus related people, equipment, money, and IT. Information security means protecting information and systems from unauthorized access, use, change, damage, or destruction so they stay correct, private, and available. Information security requirements are rules set under law or by the Secretary of Commerce, NIST, OMB, and, for national security systems, the President. Information system is a set of resources organized to collect, process, store, use, share, or dispose of information, automated or manual. Integrity means preventing improper changes or destruction and making sure data is authentic. National security system handles classified defense or foreign policy information under special protections. Plan of action and milestones is the OMB quarterly report plan that lists the weakness, who will fix it, required resources by fiscal year, dates and milestones, any changes, the source that found it, and current status. Principal credit reporting agency is defined in section 603(p) of the Fair Credit Reporting Act (15 U.S.C. 1681a(p)). Security incident is an event that has or could harm Department assets or sensitive information or breaks security rules. Sensitive personal information covers agency-held records about a person (like education, finances, medical, criminal or job history) and identity data (like name, Social Security number, birth details, mother’s maiden name, or biometrics). Subordinate plan or system security plan lists security controls planned or in place for networks, systems, or facilities inside an accreditation boundary. Training teaches people specific security tasks or the common security knowledge. VA National Rules of Behavior are Department rules that explain staff responsibilities when using information systems. VA sensitive data is any Department data that needs protection because wrong disclosure, change, or deletion could harm the agency’s mission, reveal secrets, or expose personal records.
Full Legal Text
Veterans' Benefits — Source: USLM XML via OLRC
Legislative History
Reference
Citation
38 U.S.C. § 5727
Title 38 — Veterans' Benefits
Last Updated
Apr 5, 2026
Release point: 119-73not60