Us Code § 5727 - Definitions

Full text of Us Code United States Code § 5727 — Definitions, with citation guidance and answers to common questions.

§ 5727. Definitions

In this subchapter:

(1) Availability.—The term "availability" means ensuring timely and reliable access to and use of information.

(2) Confidentiality.—The term "confidentiality" means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information.

(3) Control techniques.—The term "control techniques" means methods for guiding and controlling the operations of information systems to ensure adherence to the provisions of subchapter III of chapter 35 of title 44 and other related information security requirements.

(4) Data breach.—The term "data breach" means the loss, theft, or other unauthorized access, other than those incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data.

(5) Data breach analysis.—The term "data breach analysis" means the process used to determine if a data breach has resulted in the misuse of sensitive personal information.

(6) Fraud resolution systems.—The term "fraud resolution services" means services to assist an individual in the process of recovering and rehabilitating the credit of the individual after the individual experiences identity theft.

(7) Identity theft.—The term "identity theft" has the meaning given such term under section 603 of the Fair Credit Reporting Act (15 U.S.C. 1681a).

(8) Identity theft insurance.—The term "identity theft insurance" means any insurance policy that pays benefits for costs, including travel costs, notary fees, and postage costs, lost wages, and legal fees and expenses associated with efforts to correct and ameliorate the effects and results of identity theft of the insured individual.

(9) Information owner.—The term "information owner" means an agency official with statutory or operational authority for specified information and responsibility for establishing the criteria for its creation, collection, processing, dissemination, or disposal, which responsibilities may extend to interconnected systems or groups of interconnected systems.

(10) Information resources.—The term "information resources" means information in any medium or form and its related resources, such as personnel, equipment, funds, and information technology.

(11) Information security.—The term "information security" means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide integrity, confidentiality, and availability.

(12) Information security requirements.—The term "information security requirements" means information security requirements promulgated in accordance with law, or directed by the Secretary of Commerce, the National Institute of Standards and Technology, and the Office of Management and Budget, and, as to national security systems, the President.

(13) Information system.—The term "information system" means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information, whether automated or manual.

(14) Integrity.—The term "integrity" means guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.

(15) National security system.—The term "national security system" means an information system that is protected at all times by policies and procedures established for the processing, maintenance, use, sharing, dissemination or disposition of information that has been specifically authorized under criteria established by statute or Executive Order to be kept classified in the interest of national defense or foreign policy.

(16) Plan of action and milestones.—The term "plan of action and milestones", means a plan used as a basis for the quarterly reporting requirements of the Office of Management and Budget that includes the following information:

(A) A description of the security weakness.

(B) The identity of the office or organization responsible for resolving the weakness.

(C) An estimate of resources required to resolve the weakness by fiscal year.

(D) The scheduled completion date.

(E) Key milestones with estimated completion dates.

(F) Any changes to the original key milestone date.

(G) The source that identified the weakness.

(H) The status of efforts to correct the weakness.


(17) Principal credit reporting agency.—The term "principal credit reporting agency" means a consumer reporting agency as described in section 603(p) of the Fair Credit Reporting Act (15 U.S.C. 1681a(p)).

(18) Security incident.—The term "security incident" means an event that has, or could have, resulted in loss or damage to Department assets, or sensitive information, or an action that breaches Department security procedures.

(19) Sensitive personal information.—The term "sensitive personal information", with respect to an individual, means any information about the individual maintained by an agency, including the following:

(A) Education, financial transactions, medical history, and criminal or employment history.

(B) Information that can be used to distinguish or trace the individual's identity, including name, social security number, date and place of birth, mother's maiden name, or biometric records.


(20) Subordinate plan.—The term "subordinate plan", also referred to as a "system security plan", means a plan that defines the security controls that are either planned or implemented for networks, facilities, systems, or groups of systems, as appropriate, within a specific accreditation boundary.

(21) Training.—The term "training" means a learning experience in which an individual is taught to execute a specific information security procedure or understand the information security common body of knowledge.

(22) Va national rules of behavior.—The term "VA National Rules of Behavior" means a set of Department rules that describes the responsibilities and expected behavior of personnel with regard to information system usage.

(23) Va sensitive data.—The term "VA sensitive data" means all Department data, on any storage media or in any form or format, which requires protection due to the risk of harm that could result from inadvertent or deliberate disclosure, alteration, or destruction of the information and includes information whose improper use or disclosure could adversely affect the ability of an agency to accomplish its mission, proprietary information, and records about individuals requiring protection under applicable confidentiality provisions.

(Added Pub. L. 109–461, title IX, §902(a), Dec. 22, 2006, 120 Stat. 3457; amended Pub. L. 111–275, title X, §1001(m)(2), Oct. 13, 2010, 124 Stat. 2897.)


Editorial Notes

Amendments

2010—Par. (20). Pub. L. 111–275 substituted "plan that defines" for "subordinate plan defines".

About This Section

38 U.S.C. § 5727 is part of Title 38 of the United States Code. The United States Code is the official codification of federal statutes maintained by the Office of the Law Revision Counsel of the U.S. House of Representatives. Congress amends the Code through new public laws, which are eventually incorporated into the relevant title.

This section may be cited in legal writing as 38 U.S.C. § 5727. For the most current official text, including any recent amendments, use the official source links below. Do not rely on this page as the sole authority for legal citation or litigation.

How to Read This Statute

Statutes are organized by title, chapter, section, and subsection. Pay attention to words like "shall," "may," "and," and "or," because they determine whether a requirement is mandatory or permissive and whether multiple conditions must all be met. Historical notes and amendments often appear at the end of a section.

Using This Page

This page is intended for research and educational use. Lawyers, students, journalists, and compliance professionals can use it as a starting point, but should always verify the current text through an official government source before relying on it for legal advice, filings, or compliance decisions.

Sources

Frequently Asked Questions About Us Code § 5727

What does United States Code § 5727 cover?

Section 5727 ("Definitions") is part of the United States Code, the codified statutory law of Us Code. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.

How do I cite Us Code § 5727?

A common citation format is "United States Code § 5727" (Us Code). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.

Is this the official text of Us Code law?

No. This page is for research and education and may not include the most recent amendments. For official current law, check the Us Code official source linked on this page or consult a licensed Us Code attorney.

How does Us Code § 5727 apply to my situation?

Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Us Code can advise on how this section applies to you. Contact your state or local bar association for a referral.

Sources & Verification

Not legal advice. Verify against the official source and consult a licensed attorney in Us Code.