<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-06-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0790-AJ14</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>201410</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0790</CODE>
            <NAME>Office of the Secretary</NAME>
            <ACRONYM>OS</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0700</CODE>
            <NAME>Department of Defense</NAME>
            <ACRONYM>DOD</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Defense Industrial Base (DIB) Cyber Security/Information Assurance (CS/IA) Activities: Amendment</RULE_TITLE>
        <ABSTRACT><![CDATA[This rule amends the DoD-DIB CS/IA Voluntary Activities regulation in response to section 941 National Defense Authorization Act (NDAA) for Fiscal Year (FY) 2013 which requires the Secretary of Defense to establish procedures that require each cleared defense contractor (CDC) to report when a network or information system that meets the criteria reports cyber intrusions.]]></ABSTRACT>
        <PRIORITY_CATEGORY>Other Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Proposed Rule Stage</RULE_STAGE>
        <MAJOR>No</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>32 CFR 236</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>EO 12829</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Department of Defense (DoD) will amend the DoD-DIB CS/IA Voluntary Activities (32 CFR part 236) regulation to incorporate changes as required by section 941 NDAA for FY 2013 to include mandated cyber intrusion incident reporting by all cleared defense contractors (CDCs).</p>
</body>
</html>]]></STMT_OF_NEED>
            <LEGAL_BASIS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This regulation is proposed under the authorities of section 941 NDAA for FY 2013.</p>
</body>
</html>]]></LEGAL_BASIS>
            <ALTERNATIVES><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>DoD analyzed the requirements in section 941 NDAA for FY 2013 and determined that implementation must be accomplished through the rulemaking process. This will allow the public to comment on the implementation strategy.</p>
</body>
</html>]]></ALTERNATIVES>
            <COSTS_AND_BENEFITS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>Implementing the amended rule to meet the requirements of section 941 NDAA for FY 2013 affects approximately 8,700 CDCs. Each company will require DoD approved, medium assured certificates to submit the mandatory cyber incident reporting to the DoD-access controlled website. The cost per certificate is $175. In addition, it is estimated that the average burden per reported incident is 7 hours, which includes identifying the cyber incident details, gathering and maintaining the data needed, reviewing the collection of information to be reported, and completing the report. Note, these costs are the same as those associated with 32 CFR part 236 (DoD-DIB CS/IA Voluntary Activities), but are now applicable across a larger population of defense contractors. The benefit of this amended rule is satisfying the legal mandate from section 941 NDAA for FY 2013 as well as informing the Department of incidents that impact DoD programs and information. DoD needs to have the ability to assess the strategic and operational impacts of cyber incidents and determine appropriate mitigation activities.</p>
</body>
</html>]]></COSTS_AND_BENEFITS>
            <RISKS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>There will likely be significant public interest in DoD's implementation of section 941 NDAA for FY 2013. DoD will need to assure the public that DoD will provide for the reasonable protection of trade secrets, commercial or financial information, and information that can be used to identify a specific person that may be evident through the cyber incident reporting and media analysis.</p>
</body>
</html>]]></RISKS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>03/00/2015</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>No</RFA_REQUIRED>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>None</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Vicki</FIRST_NAME>
                <LAST_NAME>Michetti</LAST_NAME>
                <MIDDLE_NAME>D.</MIDDLE_NAME>
                <TITLE>Director Policy and Partnerships, DoD CIO</TITLE>
                <AGENCY>
                    <CODE>0790</CODE>
                    <NAME>Office of the Secretary</NAME>
                    <ACRONYM>OS</ACRONYM>
                </AGENCY>
                <PHONE>703 695-0906</PHONE>
                <EMAIL>vicki.d.michetti.civ@mail.mil</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>6000 Defense Pentagon, Room 3D1048,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20301-6000</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
