home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Hackers Underworld 2: Forbidden Knowledge
/
Hackers Underworld 2: Forbidden Knowledge.iso
/
LEGAL
/
CSA87.TXT
< prev
next >
Wrap
Text File
|
1994-07-17
|
28KB
|
462 lines
101 STAT. 1724 PUBLIC LAW 100-235--JAN. 8, 1988
Public Law 100-235
100th Congress
AN ACT
To provide for a computer standards program within the National
Bureau of Standards, to provide for Government-wide computer
security, and to provide for the training in security mat-
ters of persons who are involved in the management, opera-
tion, and use of Federal computer systems, and for other
purposes.
Be it enacted by the Senate and House of Representatives of
the United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the "Computer Security Act of
1987".
SEC. 2. PURPOSE.
(a) In General.--The Congress declares that improving the
security and privacy of sensitive information in Federal computer
systems is in the public interest, and hereby creates a means for
establishing minimum acceptable security practices for such sys-
tems, without limiting the scope of security measures already
planned or in use.
(b) Specific Purposes.--The purposes of this Act are--
(1) by amending the Act of March 3, 1901, to
assign to the National Bureau of Standards responsibil-
ity for developing standards and guidelines for Federal
computer systems, including responsibility for develop-
ing standards and guidelines needed to assure the cost-
effective security and privacy of sensitive information
in Federal computer systems, drawing on the technical
advice and assistance (including work products) of the
National Security Agency, where appropriate;
(2) to provide for promulgation of such standards
and guidelines by amending section 111(d) of the Feder-
al Property and Administrative Services Act of 1949;
(3) to require establishment of security plans by
all operators of Federal computer systems that contain
sensitive information; and
(4) to require mandatory periodic training for all
persons involved in management, use, or operation of
Federal computer systems that contain sensitive infor-
mation.
SEC. 3. ESTABLISHMENT OF COMPUTER STANDARDS PROGRAM.
The Act of March 3, 1901 (15 U.S.C. 271-278h), is amended--
(1) in section 2(f), by striking out "and" at the
end of paragraph (18), by striking out the period at
the end of paragraph (19) and inserting in lieu thereof:
"; and", and by inserting after such paragraph the
following:
"(20) the study of computer systems (as that term
is defined in section 20(d) of this Act) and their use
to control machinery and processes.";
(2) by redesignating section 20 as section 22, and
by inserting after section 19 the following new sec-
tions:
"Sec. 20. (a) The National Bureau of Standards shall--
"(1) have the mission of developing standards,
guidelines, and associated methods and techniques for
computer systems;
"(2) except as described in paragraph (3) of this
subsection (relating to security standards), develop
uniform standards and guidelines for Federal computer
systems, except those systems excluded by section 2315
of title 10, United States Code, or section 3502(2) of
title 44, United States Code;
"(3) have responsibility within the Federal Gov-
ernment for developing technical, management, physical,
and administrative standards and guidelines for the
cost-effective security and privacy of sensitive infor-
mation in Federal computer systems except--
"(A) those systems excluded by section
2315 of title 10, United States Code, or section
3502(2) of title 44, United States Code; and
"(B) those systems which are protected
at all times by procedures established for infor-
mation which has been specifically authorized
under criteria established by an Executive order
or an Act of Congress to be kept secret in the
interest of national defense or foreign policy,
the primary purpose of which standards and guidelines
shall be to control loss and unauthorized modification
or disclosure of sensitive information in such systems
and to prevent computer-related fraud and misuse;
"(4) submit standards and guidelines developed
pursuant to paragraphs (2) and (3) of this subsection,
along with recommendations as to the extent to which
these should be made compulsory and binding, to the
Secretary of Commerce for promulgation under section
111(d) of the Federal Property and Administrative
Services Act of 1949;
"(5) develop guidelines for use by operators of
Federal computer systems that contain sensitive infor-
mation in training their employees in security aware-
ness and accepted security practice, as required by
section 5 of the Computer Security Act of 1987; and
"(6) develop validation procedures for, and evalu-
ate the effectiveness of, standards and guidelines
developed pursuant to paragraphs (1), (2), and (3) of
this subsection through research and liaison with other
government and private agencies.
"(b) In fulfilling subsection (a) of this section, the Na-
tional Bureau of Standards is authorized--
"(1) to assist the private sector, upon request,
in using and applying the results of the programs and
activities under this section;
"(2) to make recommendations, as appropriate, to
the Administrator of General Services on policies and
regulations proposed pursuant to section 111(d) of the
Federal Property and Administrative Services Act of
1949;
"(3) as requested, to provide to operators of
Federal computer systems technical assistance in imple-
menting the standards and guidelines promulgated pursu-
ant to section 111(d) of the Federal Property and
Administrative Services Act of 1949;
"(4) to assist, as appropriate, the Office of
Personnel Management in developing regulations pertain-