From: Wiley Rein, LLP
The John S. McCain National Defense Authorization Act for Fiscal Year 2019 (NDAA or the Act) (H.R. 5515) was signed into law on August 13, 2018. The appropriations law authorizes a $717 billion national defense budget and includes wide-ranging provisions on cybersecurity, touching everything from enhancing the military’s ability to respond to cyber attacks to protecting the IT supply chain and encouraging greater public-private collaboration. Below, we outline key elements of the law, which will impact how private industry engages with the U.S. Department of Defense (DOD) on cybersecurity issues.
***
Mitigating Cybersecurity and IT Supply Chain Risks
Supply chain IT risk is addressed in Section 1655. Subject to forthcoming regulations, DOD “may not use a product, service, or system procured or acquired … relating to information or operational technology, cybersecurity, an industrial control system, or weapons system,” unless the certain information is disclosed to the Secretary of Defense, including:
Leave a Reply