ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

15 U.S.C. § 7431Federal cybersecurity research and development

submitted 12 years ago by Pub. L. 113-274 to r/title-15-COMMERCE-AND-TRADE · 1,545 words · no verdicts yet

in plain englishAI-generated · not legal advice

Federal agencies must create and update a national plan for cybersecurity research every four years. The National Science Foundation must fund cybersecurity education research and review whether more test facilities are needed. Agencies must coordinate this research with each other, industry, and outside experts.

(a) Fundamental cybersecurity research (1) Strategic plan: The heads of certain federal agencies and departments, working through the National Science and Technology Council and the Networking and Information Technology Research and Development Program, must write and update — every 4 years — a Federal cybersecurity research and development strategic plan, based on an assessment of cybersecurity risk. The plan must build on existing programs to meet goals like: (A) building secure, reliable software-heavy systems from the start; (B) testing whether software and hardware (in-house or third-party) has known security flaws; (C) testing whether third-party software and hardware does only what it claims to do; (D) protecting individual privacy — identity, information, and transactions — in distributed systems and over networks; (E) building internet protocols with strong security built in; (F) tracing the origin of a message sent over the internet; (G) supporting privacy alongside better security; (H) addressing insider threats; (I) improving consumer education and digital literacy about cybersecurity; (J) protecting information processed in cloud computing or sent over wireless services; (K) carrying out the research goals identified under section 7432 of this title; and (L) any other goals the agency heads decide fit, after consulting the head of any relevant federal agency and getting input from stakeholders, including national laboratories, industry, and academia. (2) Requirements: (A) The plan must: (i) specify and rank near-term, mid-term, and long-term research goals, including goals tied to the research identified in section 7403(a)(1); (ii) explain how the near-term goals complement private-sector research; (iii) describe how the agencies will focus on innovative, transformational technologies that improve the security, reliability, resilience, and trustworthiness of digital infrastructure, and protect consumer privacy; (iv) describe how the agencies will quickly move research results into new cybersecurity technologies and applications, including by sharing best practices; (v) describe how the agencies will build and maintain a national research infrastructure for creating, testing, and evaluating next-generation secure networking and information technology systems; and (vi) describe how the agencies will let academic researchers access that infrastructure and relevant data, including event data. (B) While developing, carrying out, and updating the plan, the agencies must work closely with industry, academia, and other stakeholders, so that federal cybersecurity research isn't duplicating private-sector efforts, as far as possible. (C) In developing and updating the plan, the agencies must get recommendations and advice from the advisory committee established under section 5511(b)(1), and from a wide range of stakeholders — industry, academia (including minority-serving institutions and community colleges), National Laboratories, and other relevant organizations. (D) The agencies must also develop and update every year an "implementation roadmap" for the plan. It must: (i) specify each federal agency's role in carrying out or sponsoring research toward the plan's goals, including how progress will be evaluated; (ii) specify the funding allocated to each major research goal and its source, for the current fiscal year; (iii) estimate the funding needed for each major goal over the following 3 fiscal years; and (iv) track ongoing and completed federal cybersecurity research and development projects. (3) Reports to Congress: The agencies must submit to the Senate Commerce Committee and the House Science Committee: (A) the strategic plan, no later than 1 year after December 18, 2014; (B) each 4-year update to the plan; and (C) the implementation roadmap and its yearly updates, appended to the annual report required under section 5511(a)(2)(D). (4) Definition: "Applicable agencies and departments" means the agencies and departments identified in clauses (i) through (xi) of section 5511(a)(3)(B), or designated under clause (xii) of that section. (b) Cybersecurity practices research: The Director of the National Science Foundation must support research that (1) develops, evaluates, shares, and builds new cybersecurity practices and concepts — including secure coding education — into the core curriculum of computer science programs and other programs whose graduates have a substantial chance of writing software after graduating, and (2) develops new models for training faculty in cybersecurity education, including secure coding development. (c) Cybersecurity modeling and test beds: (1) No later than 1 year after December 18, 2014, the Director of the National Science Foundation, with the Director of the Office of Science and Technology Policy, must review the cybersecurity test beds that existed as of that date, to inform the grants in paragraph (2). The review must assess whether there are enough cybersecurity test beds to meet the research needs of the strategic plan. Once finished, the Director must submit the review to the Senate Commerce Committee and the House Science Committee. (2)(A) If the Director of the National Science Foundation decides, after the review, that the strategic plan's research needs require more cybersecurity test beds, the Director — with the Secretary of Commerce and the Secretary of Homeland Security — may award grants to institutions of higher education or nonprofit research and development institutions to build them. (B) These test beds must be strong enough to realistically model the scale and complexity of real-time cyberattacks and defenses on real-world networks and environments. (C) The Director of the National Science Foundation, with the Secretary of Commerce and the Secretary of Homeland Security, must evaluate how effective any grants under this subsection were at meeting the strategic plan's goals, no later than 2 years after the review under paragraph (1), and periodically after that. (d) Coordination with other research initiatives: Consistent with the responsibilities under section 5511, the Director of the Office of Science and Technology Policy must coordinate, as far as practical, this section's federal research and development activities with other ongoing security-related research, including research by: (1) the National Science Foundation; (2) the National Institute of Standards and Technology; (3) the Department of Homeland Security; (4) other federal agencies; (5) other federal and private research laboratories, research entities, and universities; (6) institutions of higher education; (7) relevant nonprofit organizations; and (8) international partners of the United States. (e) Omitted: This subsection has no content. (f) Research on the science of cybersecurity: Each agency and department head identified under section 5511(a)(3)(B), using existing programs and activities, must support research that builds a scientific foundation for the field of cybersecurity — including research that deepens understanding of how to secure complex networked systems, enables repeatable experiments, and creates measurable security standards.
the actual law source: uscode.house.gov ↗public domain
(a) Fundamental cybersecurity research
(1) Federal cybersecurity research and development strategic plan

The heads of the applicable agencies and departments, working through the National Science and Technology Council and the Networking and Information Technology Research and Development Program, shall develop and update every 4 years a Federal cybersecurity research and development strategic plan (referred to in this subsection as the “strategic plan”) based on an assessment of cybersecurity risk to guide the overall direction of Federal cybersecurity and information assurance research and development for information technology and networking systems. The heads of the applicable agencies and departments shall build upon existing programs and plans to develop the strategic plan to meet objectives in cybersecurity, such as—

(A)

how to design and build complex software-intensive systems that are secure and reliable when first deployed;

(B)

how to test and verify that software and hardware, whether developed locally or obtained from a third party, is free of significant known security flaws;

(C)

how to test and verify that software and hardware obtained from a third party correctly implements stated functionality, and only that functionality;

(D)

how to guarantee the privacy of an individual, including that individual’s identity, information, and lawful transactions when stored in distributed systems or transmitted over networks;

(E)

how to build new protocols to enable the Internet to have robust security as one of the key capabilities of the Internet;

(F)

how to determine the origin of a message transmitted over the Internet;

(G)

how to support privacy in conjunction with improved security;

(H)

how to address the problem of insider threats;

(I)

how improved consumer education and digital literacy initiatives can address human factors that contribute to cybersecurity;

(J)

how to protect information processed, transmitted, or stored using cloud computing or transmitted through wireless services;

(K)

implementation of section 7432 of this title through research and development on the topics identified under subsection (a) of such section; and

(L)

any additional objectives the heads of the applicable agencies and departments, in coordination with the head of any relevant Federal agency and with input from stakeholders, including appropriate national laboratories, industry, and academia, determine appropriate.

(2) Requirements
(A) Contents of plan

The strategic plan shall—

(i)

specify and prioritize near-term, mid-term, and long-term research objectives, including objectives associated with the research identified in section 7403(a)(1) of this title;

(ii)

specify how the near-term objectives described in clause (i) complement research and development areas in which the private sector is actively engaged;

(iii)

describe how the heads of the applicable agencies and departments will focus on innovative, transformational technologies with the potential to enhance the security, reliability, resilience, and trustworthiness of the digital infrastructure, and to protect consumer privacy;

(iv)

describe how the heads of the applicable agencies and departments will foster the rapid transfer of research and development results into new cybersecurity technologies and applications for the timely benefit of society and the national interest, including through the dissemination of best practices and other outreach activities;

(v)

describe how the heads of the applicable agencies and departments will establish and maintain a national research infrastructure for creating, testing, and evaluating the next generation of secure networking and information technology systems; and

(vi)

describe how the heads of the applicable agencies and departments will facilitate access by academic researchers to the infrastructure described in clause (v), as well as to relevant data, including event data.

(B) Private sector efforts

In developing, implementing, and updating the strategic plan, the heads of the applicable agencies and departments, working through the National Science and Technology Council and Networking and Information Technology Research and Development Program, shall work in close cooperation with industry, academia, and other interested stakeholders to ensure, to the extent possible, that Federal cybersecurity research and development is not duplicative of private sector efforts.

(C) Recommendations

In developing and updating the strategic plan the heads of the applicable agencies and departments shall solicit recommendations and advice from—

(i)

the advisory committee established under section 5511(b)(1) of this title; and

(ii)

a wide range of stakeholders, including industry, academia, including representatives of minority serving institutions and community colleges, National Laboratories, and other relevant organizations and institutions.

(D) Implementation roadmap

The heads of the applicable agencies and departments, working through the National Science and Technology Council and Networking and Information Technology Research and Development Program, shall develop and annually update an implementation roadmap for the strategic plan. The implementation roadmap shall—

(i)

specify the role of each Federal agency in carrying out or sponsoring research and development to meet the research objectives of the strategic plan, including a description of how progress toward the research objectives will be evaluated;

(ii)

specify the funding allocated to each major research objective of the strategic plan and the source of funding by agency for the current fiscal year;

(iii)

estimate the funding required for each major research objective of the strategic plan for the following 3 fiscal years; and

(iv)

track ongoing and completed Federal cybersecurity research and development projects.

(3) Reports to Congress

The heads of the applicable agencies and departments, working through the National Science and Technology Council and Networking and Information Technology Research and Development Program, shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives—

(A)

the strategic plan not later than 1 year after December 18, 2014;

(B)

each quadrennial update to the strategic plan; and

(C)

the implementation roadmap under subparagraph (D), and its annual updates, which shall be appended to the annual report required under section 5511(a)(2)(D) of this title.

(4) Definition of applicable agencies and departments

In this subsection, the term “applicable agencies and departments” means the agencies and departments identified in clauses (i) through (xi) of section 5511(a)(3)(B) 1 of this title or designated under clause (xii) of that section.

(b) Cybersecurity practices research

The Director of the National Science Foundation shall support research that—

(1)

develops, evaluates, disseminates, and integrates new cybersecurity practices and concepts into the core curriculum of computer science programs and of other programs where graduates of such programs have a substantial probability of developing software after graduation, including new practices and concepts relating to secure coding education and improvement programs; and

(2)

develops new models for professional development of faculty in cybersecurity education, including secure coding development.

(c) Cybersecurity modeling and test beds
(1) Review

Not later than 1 year after December 18, 2014, the Director of the National Science Foundation, in coordination with the Director of the Office of Science and Technology Policy, shall conduct a review of cybersecurity test beds in existence on December 18, 2014, to inform the grants under paragraph (2). The review shall include an assessment of whether a sufficient number of cybersecurity test beds are available to meet the research needs under the Federal cybersecurity research and development strategic plan. Upon completion, the Director shall submit the review to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives.

(2) Additional cybersecurity modeling and test beds
(A) In general

If the Director of the National Science Foundation, after the review under paragraph (1), determines that the research needs under the Federal cybersecurity research and development strategic plan require the establishment of additional cybersecurity test beds, the Director of the National Science Foundation, in coordination with the Secretary of Commerce and the Secretary of Homeland Security, may award grants to institutions of higher education or research and development non-profit institutions to establish cybersecurity test beds.

(B) Requirement

The cybersecurity test beds under subparagraph (A) shall be sufficiently robust in order to model the scale and complexity of real-time cyber attacks and defenses on real world networks and environments.

(C) Assessment required

The Director of the National Science Foundation, in coordination with the Secretary of Commerce and the Secretary of Homeland Security, shall evaluate the effectiveness of any grants awarded under this subsection in meeting the objectives of the Federal cybersecurity research and development strategic plan not later than 2 years after the review under paragraph (1) of this subsection, and periodically thereafter.

(d) Coordination with other research initiatives

In accordance with the responsibilities under section 5511 of this title, the Director of the Office of Science and Technology Policy shall coordinate, to the extent practicable, Federal research and development activities under this section with other ongoing research and development security-related initiatives, including research being conducted by—

(1)

the National Science Foundation;

(2)

the National Institute of Standards and Technology;

(3)

the Department of Homeland Security;

(4)

other Federal agencies;

(5)

other Federal and private research laboratories, research entities, and universities;

(6)

institutions of higher education;

(7)

relevant nonprofit organizations; and

(8)

international partners of the United States.

(e) Omitted

(f) Research on the science of cybersecurity

The head of each agency and department identified under section 5511(a)(3)(B)1 of this title, through existing programs and activities, shall support research that will lead to the development of a scientific foundation for the field of cybersecurity, including research that increases understanding of the underlying principles of securing complex networked systems, enables repeatable experimentation, and creates quantifiable security metrics.

Source credit: (Pub. L. 113–274, title II, § 201, Dec. 18, 2014, 128 Stat. 2974; Pub. L. 114–329, title I, § 105(t), Jan. 6, 2017, 130 Stat. 2985; Pub. L. 116–283, div. H, title XCIV, § 9407(b), Jan. 1, 2021, 134 Stat. 4814.)

history & why it existsrecord from the source credit
  • 2014Enacted · Pub. L. 113-274 · 128 Stat. 2974
  • 2017Amended · Pub. L. 114-329 · 130 Stat. 2985
  • 2021Amended · Pub. L. 116-283 · 134 Stat. 4814

A history note hasn’t been published yet. The record shows enactment by Pub. L. 113-274 on 2014-12-18.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case