ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

42 U.S.C. § 18935Dissemination of resources for research institutions

submitted 4 years ago by Pub. L. 117-167 to r/title-42-THE-PUBLIC-HEALTH-AND-WELFARE · 332 words · no verdicts yet

in plain englishAI-generated · not legal advice

Within one year, the NIST Director must publish cybersecurity resources for research institutions with large federal funding. These resources must fit institutions of different sizes and be voluntary to use. This section doesn't change any other federal cybersecurity rules.

(a) Dissemination of resources for research institutions. (1) Within one year of August 9, 2022, using existing authority under subsections (c)(15) and (e)(1)(A)(ix) of section 272 of title 15, the Director must publish and make public tailored resources helping "qualifying institutions" identify, assess, manage, and reduce cybersecurity risk related to conducting research. (2) The Director must make sure these resources: (A) generally apply and work for a wide range of qualifying institutions; (B) vary with the nature and size of the institution, and the nature and sensitivity of the data on its systems or devices; (C) promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to help mitigate common risks; (D) include case studies, examples, and practical scenarios; (E) are outcomes-based and usable with a variety of commercial, off-the-shelf technologies; and (F) are based on international technical standards to the extent practical. (3) The Director must make sure these resources line up with the national cybersecurity awareness and education efforts under section 7443 of title 15. (4) The Director must periodically review and update these resources as the Director thinks appropriate. (5) Using these resources is voluntary. (b) Other Federal cybersecurity requirements. Nothing in this section may be read to replace, change, or otherwise affect any cybersecurity requirements that apply to federal agencies. (c) Definitions. (1) "Qualifying institutions" means colleges and universities awarded more than $50,000,000 per year in total federal research funding. (2) "Resources" means guidelines, tools, best practices, technical standards, methods, and other ways of providing information.
the actual law source: uscode.house.gov ↗public domain
(a) Dissemination of resources for research institutions
(1) In general

Not later than one year after August 9, 2022, the Director shall, using the authorities of the Director under subsections (c)(15) and (e)(1)(A)(ix) of section 272 of title 15, disseminate and make publicly available tailored resources to help qualifying institutions identify, assess, manage, and reduce their cybersecurity risk related to conducting research.

(2) Requirements

The Director shall ensure that the resources disseminated pursuant to paragraph (1)—

(A)

are generally applicable and usable by a wide range of qualifying institutions;

(B)

vary with the nature and size of the qualifying institutions, and the nature and sensitivity of the data collected or stored on the information systems or devices of the qualifying institutions;

(C)

include elements that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist qualifying institutions in mitigating common cybersecurity risks;

(D)

include case studies, examples, and scenarios of practical application;

(E)

are outcomes-based and can be implemented using a variety of technologies that are commercial and off-the-shelf; and

(F)

to the extent practicable, are based on international technical standards.

(3) National cybersecurity awareness and education program

The Director shall ensure that the resources disseminated under paragraph (1) are consistent with the efforts of the Director under section 7443 of title 15.

(4) Updates

The Director shall review periodically and update the resources under paragraph (1) as the Director determines appropriate.

(5) Voluntary resources

The use of the resources disseminated under paragraph (1) shall be considered voluntary.

(b) Other Federal cybersecurity requirements

Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal agencies.

(c) Definitions

In this section:

(1) Qualifying institutions

The term “qualifying institutions” means institutions of higher education that are awarded in excess of $50,000,000 per year in total Federal research funding.

(2) Resources

The term “resources” means guidelines, tools, best practices, technical standards, methodologies, and other ways of providing information.

Source credit: (Pub. L. 117–167, div. B, title II, § 10229, Aug. 9, 2022, 136 Stat. 1481.)

history & why it existsrecord from the source credit
  • 2022Enacted · Pub. L. 117-167 · 136 Stat. 1481

A history note hasn’t been published yet. The record shows enactment by Pub. L. 117-167 on 2022-08-09.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case