The purposes of this subchapter are to—

(1) provide a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support Federal operations and assets;

(2) recognize the highly networked nature of the current Federal computing environment and provide effective governmentwide management and oversight of the related information security risks, including coordination of information security efforts throughout the civilian, national security, and law enforcement communities;

(3) provide for development and maintenance of minimum controls required to protect Federal information and information systems;

(4) provide a mechanism for improved oversight of Federal agency information security programs, including through automated security tools to continuously diagnose and improve security;

(5) acknowledge that commercially developed information security products offer advanced, dynamic, robust, and effective information security solutions, reflecting market solutions for the protection of critical information infrastructures important to the national defense and economic security of the nation that are designed, built, and operated by the private sector; and

(6) recognize that the selection of specific technical hardware and software information security solutions should be left to individual agencies from among commercially developed products.

Terms Used In 44 USC 3551

  • Assets: (1) The property comprising the estate of a deceased person, or (2) the property in a trust account.
  • individual: shall include every infant member of the species homo sapiens who is born alive at any stage of development. See 1 USC 8
  • information security: means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide&mdash. See 44 USC 3552
  • Oversight: Committee review of the activities of a Federal agency or program.