Us Code § 11331 - Responsibilities for Federal information systems standards

Full text of Us Code United States Code § 11331 — Responsibilities for Federal information systems standards, with citation guidance and answers to common questions.

§ 11331. Responsibilities for Federal information systems standards

(a) Standards and Guidelines.—

(1) Authority to prescribe.—Except as provided under paragraph (2), the Secretary of Commerce shall, on the basis of standards and guidelines developed by the National Institute of Standards and Technology pursuant to paragraphs (2) and (3) of section 20(a) of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3(a)), prescribe standards and guidelines pertaining to Federal information systems.

(2) National security systems.—Standards and guidelines for national security systems shall be developed, prescribed, enforced, and overseen as otherwise authorized by law and as directed by the President.


(b) Mandatory Requirements.—

(1) Authority to make mandatory.—Except as provided under paragraph (2), the Secretary of Commerce shall make standards prescribed under subsection (a)(1) compulsory and binding to the extent determined necessary by the Secretary to improve the efficiency of operation or security of Federal information systems.

(2) Required mandatory standards.—

(A) In general.—Standards prescribed under subsection (a)(1) shall include information security standards that—

(i) provide minimum information security requirements as determined under section 20(b) of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3(b)); and

(ii) are otherwise necessary to improve the security of Federal information and information systems.


(B) Requirement.—Information security standards described in subparagraph (A) shall be compulsory and binding.


(c) Authority to Disapprove or Modify.—The President may disapprove or modify the standards and guidelines referred to in subsection (a)(1) if the President determines such action to be in the public interest. The President's authority to disapprove or modify such standards and guidelines may not be delegated. Notice of such disapproval or modification shall be published promptly in the Federal Register. Upon receiving notice of such disapproval or modification, the Secretary of Commerce shall immediately rescind or modify such standards or guidelines as directed by the President.

(d) Exercise of Authority.—To ensure fiscal and policy consistency, the Secretary of Commerce shall exercise the authority conferred by this section subject to direction by the President and in coordination with the Director of the Office of Management and Budget.

(e) Application of More Stringent Standards.—The head of an executive agency may employ standards for the cost-effective information security for Federal information systems within or under the supervision of that agency that are more stringent than the standards the Secretary prescribes under this section if the more stringent standards—

(1) contain at least the applicable standards made compulsory and binding by the Secretary of Commerce; and

(2) are otherwise consistent with policies and guidelines issued under section 3553 of title 44.


(f) Decisions on Promulgation of Standards.—The decision by the Secretary of Commerce regarding the promulgation of any standard under this section shall occur not later than 6 months after the submission of the proposed standard to the Secretary by the National Institute of Standards and Technology, as provided under section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3).

(g) Definitions.—In this section:

(1) Federal information system.—The term "Federal information system" means an information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency.

(2) Information security.—The term "information security" has the meaning given that term in section 3552(b)(3) of title 44.

(3) National security system.—The term "national security system" has the meaning given that term in section 3552(b)(6) of title 44.

(Pub. L. 107–217, Aug. 21, 2002, 116 Stat. 1243; Pub. L. 107–296, title X, §1002(a), Nov. 25, 2002, 116 Stat. 2268; Pub. L. 107–347, title III, §302(a), Dec. 17, 2002, 116 Stat. 2956; Pub. L. 117–167, div. B, title II, §10246(f), Aug. 9, 2022, 136 Stat. 1492.)

Historical and Revision Notes
Revised

Section

Source (U.S. Code)Source (Statutes at Large)
11331 40:1441. Pub. L. 104–106, div. E, title LI, §5131(a)–(d), Feb. 10, 1996, 110 Stat. 687.

Editorial Notes

Amendments

2022—Pub. L. 117–167 amended text generally. Prior to amendment, text related to the definition of "information security", in subsec. (a); the requirement that the Director of the Office of Management and Budget promulgate information security standards, in subsec. (b); the application of more stringent standards by heads of agencies, in subsec. (c); and requirements regarding decisions by the Director, in subsec. (d).

2002—Pub. L. 107–296 amended text generally. Prior to amendment, text, as amended generally by Pub. L. 107–347, read as follows:

"(a) Standards and Guidelines.—

"(1) Authority to prescribe.—Except as provided under paragraph (2), the Secretary of Commerce shall, on the basis of standards and guidelines developed by the National Institute of Standards and Technology pursuant to paragraphs (2) and (3) of section 20(a) of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3(a)), prescribe standards and guidelines pertaining to Federal information systems.

"(2) National security systems.—Standards and guidelines for national security systems (as defined under this section) shall be developed, prescribed, enforced, and overseen as otherwise authorized by law and as directed by the President.

"(b) Mandatory Requirements.—

"(1) Authority to make mandatory.—Except as provided under paragraph (2), the Secretary shall make standards prescribed under subsection (a)(1) compulsory and binding to the extent determined necessary by the Secretary to improve the efficiency of operation or security of Federal information systems.

"(2) Required mandatory standards.—(A) Standards prescribed under subsection (a)(1) shall include information security standards that—

"(i) provide minimum information security requirements as determined under section 20(b) of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3(b)); and

"(ii) are otherwise necessary to improve the security of Federal information and information systems.

"(B) Information security standards described in subparagraph (A) shall be compulsory and binding.

"(c) Authority to Disapprove or Modify.—The President may disapprove or modify the standards and guidelines referred to in subsection (a)(1) if the President determines such action to be in the public interest. The President's authority to disapprove or modify such standards and guidelines may not be delegated. Notice of such disapproval or modification shall be published promptly in the Federal Register. Upon receiving notice of such disapproval or modification, the Secretary of Commerce shall immediately rescind or modify such standards or guidelines as directed by the President.

"(d) Exercise of Authority.—To ensure fiscal and policy consistency, the Secretary shall exercise the authority conferred by this section subject to direction by the President and in coordination with the Director of the Office of Management and Budget.

"(e) Application of More Stringent Standards.—The head of an executive agency may employ standards for the cost-effective information security for information systems within or under the supervision of that agency that are more stringent than the standards the Secretary prescribes under this section if the more stringent standards—

"(1) contain at least the applicable standards made compulsory and binding by the Secretary; and

"(2) are otherwise consistent with policies and guidelines issued under section 3543 of title 44.

"(f) Decisions on Promulgation of Standards.—The decision by the Secretary regarding the promulgation of any standard under this section shall occur not later than 6 months after the submission of the proposed standard to the Secretary by the National Institute of Standards and Technology, as provided under section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3).

"(g) Definitions.—In this section:

"(1) Federal information system.—The term 'Federal information system' means an information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency.

"(2) Information security.—The term 'information security' has the meaning given that term in section 3542(b)(1) of title 44.

"(3) National security system.—The term 'national security system' has the meaning given that term in section 3542(b)(2) of title 44."

Pub. L. 107–347 substituted "Responsibilities for Federal information systems standards" for "Responsibilities regarding efficiency, security, and privacy of federal computer systems" in section catchline and amended text generally. Prior to amendment, text read as follows:

"(a) Definitions.—In this section, the terms 'federal computer system' and 'operator of a federal computer system' have the meanings given those terms in section 20(d) of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3(d)).

"(b) Standards and Guidelines.—

"(1) Authority to prescribe and disapprove or modify.—

"(A) Authority to prescribe.—On the basis of standards and guidelines developed by the National Institute of Standards and Technology pursuant to paragraphs (2) and (3) of section 20(a) of the Act (15 U.S.C. 278g–3(a)(2), (3)), the Secretary of Commerce shall prescribe standards and guidelines pertaining to federal computer systems. The Secretary shall make those standards compulsory and binding to the extent the Secretary determines necessary to improve the efficiency of operation or security and privacy of federal computer systems.

"(B) Authority to disapprove or modify.—The President may disapprove or modify those standards and guidelines if the President determines that action to be in the public interest. The President's authority to disapprove or modify those standards and guidelines may not be delegated. Notice of disapproval or modification shall be published promptly in the Federal Register. On receiving notice of disapproval or modification, the Secretary shall immediately rescind or modify those standards or guidelines as directed by the President.

"(2) Exercise of authority.—To ensure fiscal and policy consistency, the Secretary shall exercise the authority conferred by this section subject to direction by the President and in coordination with the Director of the Office of Management and Budget.

"(c) Application of More Stringent Standards.—The head of a federal agency may employ standards for the cost-effective security and privacy of sensitive information in a federal computer system in or under the supervision of that agency that are more stringent than the standards the Secretary prescribes under this section if the more stringent standards contain at least the applicable standards the Secretary makes compulsory and binding.

"(d) Waiver of Standards.—

"(1) Authority of the secretary.—The Secretary may waive in writing compulsory and binding standards under subsection (b) if the Secretary determines that compliance would—

"(A) adversely affect the accomplishment of the mission of an operator of a federal computer system; or

"(B) cause a major adverse financial impact on the operator that is not offset by Federal Government-wide savings.

"(2) Delegation of waiver authority.—The Secretary may delegate to the head of one or more federal agencies authority to waive those standards to the extent the Secretary determines that action to be necessary and desirable to allow for timely and effective implementation of federal computer system standards. The head of the agency may redelegate that authority only to a chief information officer designated pursuant to section 3506 of title 44.

"(3) Notice.—Notice of each waiver and delegation shall be transmitted promptly to Congress and published promptly in the Federal Register."


Statutory Notes and Related Subsidiaries

Effective Date of 2002 Amendments

Amendment by Pub. L. 107–347 effective Dec. 17, 2002, see section 402(b) of Pub. L. 107–347, set out as a note under section 3504 of Title 44, Public Printing and Documents.

Amendment by Pub. L. 107–296 effective 60 days after Nov. 25, 2002, see section 4 of Pub. L. 107–296, set out as an Effective Date note under section 101 of Title 6, Domestic Security.

About This Section

40 U.S.C. § 11331 is part of Title 40 of the United States Code. The United States Code is the official codification of federal statutes maintained by the Office of the Law Revision Counsel of the U.S. House of Representatives. Congress amends the Code through new public laws, which are eventually incorporated into the relevant title.

This section may be cited in legal writing as 40 U.S.C. § 11331. For the most current official text, including any recent amendments, use the official source links below. Do not rely on this page as the sole authority for legal citation or litigation.

How to Read This Statute

Statutes are organized by title, chapter, section, and subsection. Pay attention to words like "shall," "may," "and," and "or," because they determine whether a requirement is mandatory or permissive and whether multiple conditions must all be met. Historical notes and amendments often appear at the end of a section.

Using This Page

This page is intended for research and educational use. Lawyers, students, journalists, and compliance professionals can use it as a starting point, but should always verify the current text through an official government source before relying on it for legal advice, filings, or compliance decisions.

Sources

Frequently Asked Questions About Us Code § 11331

What does United States Code § 11331 cover?

Section 11331 ("Responsibilities for Federal information systems standards") is part of the United States Code, the codified statutory law of Us Code. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.

How do I cite Us Code § 11331?

A common citation format is "United States Code § 11331" (Us Code). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.

Is this the official text of Us Code law?

No. This page is for research and education and may not include the most recent amendments. For official current law, check the Us Code official source linked on this page or consult a licensed Us Code attorney.

How does Us Code § 11331 apply to my situation?

Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Us Code can advise on how this section applies to you. Contact your state or local bar association for a referral.

Sources & Verification

Not legal advice. Verify against the official source and consult a licensed attorney in Us Code.