Requires the Department of Defense to submit to Congress a plan for ensuring that the Department's cyber red teams possess the capabilities necessary to execute their duties, including with respect to threats stemming from artificial intelligence systems abroad.
Requires officials from the Department of Defense -- namely the Principal Cyber Advisor to the Secretary of Defense, the Chief Information Officer of the Department of Defense, the Director of Operational Test and Evaluation, and the Commander of the United States Cyber Command -- to assess the status of the implementation of recommendations made by the Secretary of Defense to enhance the capabilities of the Department of Defense's cyber red teams.
Requires the same officials listed above to submit to Congress a plan for ensuring that the Department's cyber red teams possess the capabilities necessary to execute their duties, including with respect to threats stemming from artificial intelligence systems abroad.
Requires the Director of Operational Test and Evaluation to evaluate annually, from 2025 through 2031, the status of the implementation of the plan described in the paragraph above.
Key facts
🏛️ This document has been enacted by the United States Congress.
For authoritative text and metadata, visit the official source.
🎯 This document primarily applies to the government, rather than the private sector.
📜 This document's name is National Defense Authorization Act for Fiscal Year 2024, Section 1507 ("Review and plan relating to cyber red teams of Department of Defense").
AGORA also tracks this document under the name FY2024 NDAA, Section 1507 ("Review and plan relating to cyber red teams of Department of Defense"). It is part of FY2024 NDAA.
↳ This document is part of a longer one: FY2024 NDAA.
Some AGORA documents are "split off" from longer documents that mix AI
and non-AI content, such as omnibus authorization or appropriations laws
in the United States Congress. Read more >>
Themes AI risks, applications, governance strategies, and other themes addressed in AGORA documents.
This is an unofficial copy. The document has been
archived and reformatted in plaintext for AGORA. Footnotes, tables, and
similar material may be omitted. For the official text, visit the original source.
SEC. 1507. REVIEW AND PLAN RELATING TO CYBER RED TEAMS OF DEPARTMENT OF DEFENSE.
(a) Review Relating to Prior Joint Assessment.--
(1) Review required.--Not later than 90 days after the date of the enactment of this Act, the officials described in subsection (c) shall review, and assess the status of the implementation of, the recommendations set forth by the Secretary of Defense in response to the joint assessment requirement under section 1660 of the National Defense Authorization Act for Fiscal Year 2020 (Public Law 116-92; 133 Stat. 1771).
(2) Elements.--The review under paragraph (1) shall include, with respect to the recommendations specified in such paragraph--
(A) the timelines associated with each such recommendation, regardless of whether the recommendation is fully implemented or yet to be fully implemented; and
(B) a description of any impediments to the implementation of such recommendations encountered.
Requires officials to review and assess Defense recommendations' implementation status within 90 days.
Requires officials to review and assess Defense recommendations' implementation status within 90 days.
(b) Plan Required.--
(1) Plan.--Not later than 180 days after the date of the enactment of this Act, the officials described in subsection (c) shall submit to the congressional defense committees a plan, developed taking into account the findings of the review under subsection (a), to ensure cyber red teams of the Department of Defense achieve sufficient capacity and capability to provide services and meet current and projected future demands on a Defense-wide basis. Such plan shall include--
(A) a description of the funding necessary for such cyber red teams to achieve such capacity and capability;
(B) a description of any other resources, personnel, infrastructure, or authorities for access to information necessary for such cyber red teams to achieve such capacity
and capability (including with respect to the emulation of threats from foreign countries with advanced cyber capabilities, automation, artificial intelligence or machine learning, and data collection and correlation); and(C) updated joint service standards and metrics to ensure the training, staffing, and equipping of such cyber red teams at levels necessary to achieve such capacity and capability.
(2) Implementation.--Not later than one year after the date of enactment of this Act, the Secretary of Defense shall prescribe such regulations and issue such guidance as the Secretary determines necessary to implement the plan developed under subsection (a).
Requires officials to submit a plan ensuring cyber red teams' capacity and capability within 180 days.
Requires officials to submit a plan ensuring cyber red teams' capacity and capability within 180 days.
(c) Officials Described.--The officials described in this subsection are the Principal Cyber Advisor to the Secretary of Defense, the Chief Information Officer of the Department of Defense, the Director of Operational Test and Evaluation, and the Commander of the United States Cyber Command.
(d) Annual Reports.--Not later than January 31, 2025, and not less frequently than annually thereafter until January 31, 2031, the Director of Operational Test and Evaluation shall include in each annual report required under section 139(h) of title 10, United States Code, an update on progress made with respect to the implementation of this section, including the following:
(1) The results of test and evaluation events, including any resource or capability shortfalls limiting the capacity or capability of cyber red teams of the Department of Defense to meet operational requirements.
(2) The extent to which operations of such cyber red teams have expanded across the competition continuum, including during cooperation and competition phases, to match adversary positioning and cyber activities.
(3) A summary of identified categories of common gaps and shortfalls across cyber red teams of the military departments and Defense Agencies (as such terms are defined in section 101 of title 10, United States Code).
(4) Any identified lessons learned that would affect training or operational employment decisions relating to the cyber red teams of the Department of Defense.
Describes the officials involved and mandates annual reports on cyber red teams' progress until 2031.
Describes the officials involved and mandates annual reports on cyber red teams' progress until 2031.