The report required under paragraph (1) shall include—
(1) In general The President shall submit to the appropriate congressional committees a report that describes significant activities undermining cybersecurity aimed against the United States Government or any United States person and conducted by the Government of North Korea, or a person owned or controlled, directly or indirectly, by the Government of North Korea or any person acting for or on behalf of that Government.
The report required under paragraph (1) shall include—
(A) the identity and nationality of persons that have knowingly engaged in, directed, or provided material support to conduct significant activities undermining cybersecurity described in paragraph (1);
(B) a description of the conduct engaged in by each person identified;
(C) an assessment of the extent to which a foreign government has provided material support to the Government of North Korea or any person acting for or on behalf of that Government to conduct significant activities undermining cybersecurity; and
(D) a United States strategy to counter North Korea’s efforts to conduct significant activities undermining cybersecurity against the United States, that includes efforts to engage foreign governments to halt the capability of the Government of North Korea and persons acting for or on behalf of that Government to conduct significant activities undermining cybersecurity.
The report required under paragraph (1) shall be submitted not later than 90 days after October 25, 2018, and every 180 days thereafter for 5 years.
(A) Submission The report required under paragraph (1) shall be submitted not later than 90 days after October 25, 2018, and every 180 days thereafter for 5 years.
(B) Form The report required under paragraph (1) shall be submitted in an unclassified form, but may include a classified annex.
The President shall designate under section 9214(a) of this title any person identified in the report required under subsection (a)(1) that knowingly engages in significant activities undermining cybersecurity through the use of computer networks or systems against foreign persons, governments, or other entities on behalf of the Government of North Korea.
(Pub. L. 114–122, title II, § 209, Feb. 18, 2016, 130 Stat. 110; Pub. L. 115–272, title III, § 303(c)(1), Oct. 25, 2018, 132 Stat. 4157.)