ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

42 U.S.C. § 19037Research security and integrity information sharing analysis organization

submitted 4 years ago by Pub. L. 117-167 to r/title-42-THE-PUBLIC-HEALTH-AND-WELFARE · 501 words · no verdicts yet

in plain englishAI-generated · not legal advice

The Director must set up an independent group to share research security information, called the RSI-ISAO. It gathers threat reports, trains staff at colleges, and studies patterns of bad actors. Colleges, nonprofits, and small businesses can join, eventually paying fees to fund it.

(a) Establishment. The Director must contract with a qualified independent organization to set up a research security and integrity information sharing analysis organization, called the RSI-ISAO here. It must include the members described in subsection (d) and carry out the duties in subsection (b). (b) Duties. The RSI-ISAO must: act as a clearinghouse of information to help members and others in the research community understand their research's context and spot improper or illegal efforts by foreign entities to steal research results, know-how, materials, or intellectual property; build standard risk-assessment frameworks and best practices for assessing research security risks in different settings; share information about security threats and lessons learned through forums and other communication; give timely reports on research security risks to keep the research and STEM education community aware of the situation; offer training and support, including webinars, for faculty and staff at colleges on research security topics; set up standardized ways to gather, store, and analyze compiled incident reports; help members spot patterns of risk and identify bad actors, and improve their ability to prevent and respond to threats; and take other steps as appropriate to boost research security. (c) Funding. The Foundation may provide starting funds for the RSI-ISAO, but must work toward having membership fees (described in subsection (d)(2)) cover its running costs as soon as practical. (d) Membership. (1) In general: The RSI-ISAO must serve and include members from institutions of higher education, nonprofit research institutions, and small and medium-sized businesses. (2) Fees: As soon as practical, members must be charged an annual fee to help cover the RSI-ISAO's costs. Fees must be set on a sliding scale based on how much each member spends on research and development, so membership stays affordable for a wide range of participants. The RSI-ISAO must also develop a plan to keep running without federal funding, as far as that is practical. (e) Board of directors. The RSI-ISAO may set up a board of directors to guide its policies, legal issues, and strategy. The board should include a mix of stakeholders, including people from academia, industry, and experienced research security administrators. (f) Stakeholder engagement. In setting up the RSI-ISAO, the Director must make sure its services fit what the research community actually needs. The Director can do this by holding workshops or other events with multiple stakeholders, or by publishing a description of the planned services and membership requirements in the Federal Register and taking public comments for at least 60 days.
the actual law source: uscode.house.gov ↗public domain
(a) Establishment

The Director shall enter into an agreement with a qualified independent organization to establish a research security and integrity information sharing analysis organization (referred to in this section as the “RSI-ISAO”), which shall include members described in subsection (d) and carry out the duties described in subsection (b).

(b) Duties

The RSI-ISAO shall—

(1)

serve as a clearinghouse for information to help enable the members and other entities in the research community to understand the context of their research and identify improper or illegal efforts by foreign entities to obtain research results, know how, materials, and intellectual property;

(2)

develop a set of standard risk assessment frameworks and best practices, relevant to the research community, to assess research security risks in different contexts;

(3)

share information concerning security threats and lessons learned from protection and response efforts through forums and other forms of communication;

(4)

provide timely reports on research security risks to provide situational awareness tailored to the research and STEM education community;

(5)

provide training and support, including through webinars, for relevant faculty and staff employed by institutions of higher education on topics relevant to research security risks and response;

(6)

enable standardized information gathering and data compilation, storage, and analysis for compiled incident reports;

(7)

support analysis of patterns of risk and identification of bad actors and enhance the ability of members to prevent and respond to research security risks; and

(8)

take other appropriate steps to enhance research security.

(c) Funding

The Foundation may provide initial funds toward the RSI-ISAO but shall seek to have the fees authorized in subsection (d)(2) cover the costs of operations at the earliest practicable time.

(d) Membership
(1) In general

The RSI-ISAO shall serve and include members representing institutions of higher education, nonprofit research institutions, and small and medium-sized businesses.

(2) Fees

As soon as practicable, members of the RSI-ISAO shall be charged an annual rate to enable the RSI-ISAO to cover its costs. Rates shall be set on a sliding scale based on research and development expenditures to ensure that membership is accessible to a diverse community of stakeholders and ensure broad participation. The RSI-ISAO shall develop a plan to sustain the RSI-ISAO without Federal funding, as practicable.

(e) Board of directors

The RSI-ISAO may establish a board of directors to provide guidance for policies, legal issues, and plans and strategies of the entity’s operations. The board shall include a diverse group of stakeholders representing the research community, including academia, industry, and experienced research security administrators.

(f) Stakeholder engagement

In establishing the RSI-ISAO under this section, the Director shall take necessary steps to ensure the services provided are aligned with the needs of the research community, including by—

(1)

convening a series of workshops or other multi-stakeholder events; or

(2)

publishing a description of the services the RSI-ISAO intends to provide and the requirements for membership in the Federal Register and provide an opportunity for submission of public comments for a period of not less than 60 days.

Source credit: (Pub. L. 117–167, div. B, title III, § 10338, Aug. 9, 2022, 136 Stat. 1553.)

history & why it existsrecord from the source credit
  • 2022Enacted · Pub. L. 117-167 · 136 Stat. 1553

A history note hasn’t been published yet. The record shows enactment by Pub. L. 117-167 on 2022-08-09.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case