Sec. 104. Cybersecurity research
450 words·~2 min read·
/bill/114/s/3084/es/section-104A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Section 4(a)(1) of the Cyber Security Research and Development Act, as amended ( 15 U.S.C. 7403(a)(1) ) is amended— in subparagraph (O), by striking and at the end; in subparagraph (P), by striking the period at the end and inserting a semicolon; and by adding at the end the following: security of election-dedicated voting system software and hardware; and role of the human factor in cybersecurity and the interplay of computers and humans and the physical world. . The Director of NIST shall continue to raise public awareness of the voluntary, industry-led cybersecurity standards and best practices for critical infrastructure developed under section 2(c)(15) of the National Institute of Standards and Technology Act ( 15 U.S.C. 272(c)(15) ).
Under section 2(b) of the National Institute of Standards and Technology Act ( 15 U.S.C. 272(b) ) and section 20 of that Act ( 15 U.S.C. 278g–3 ), the Director of NIST shall— research information systems for future cybersecurity needs; and coordinate with relevant stakeholders to develop a process— to research and identify or, if necessary, develop cryptography standards and guidelines for future cybersecurity needs, including quantum-resistant cryptography standards; and to provide recommendations to Congress, Federal agencies, and industry consistent with the National Technology Transfer and Advancement Act of 1995 ( Public Law 104–113 ; 110 Stat. 775), for a secure and smooth transition to the standards under clause (i).
Section 20(d)(3) of the National Institute of Standards and Technology Act ( 15 U.S.C. 278g–3(d)(3) ) is amended to read as follows: conduct research and analysis— to determine the nature and extent of information security vulnerabilities and techniques for providing cost-effective information security; to review and determine prevalent information security challenges and deficiencies identified by agencies or the Institute, including any challenges or deficiencies described in any of the annual reports under section 3553 or 3554 of title 44, United States Code, and in any of the reports and the independent evaluations under section 3555 of that title, that may undermine the effectiveness of agency information security programs and practices; and to evaluate the effectiveness and sufficiency of, and challenges to, Federal agencies' implementation of standards and guidelines developed under this section and policies and standards promulgated under section 11331 of title 40, United States Code; .
Section 2(c) of the National Institute of Standards and Technology Act ( 15 U.S.C. 272(c) ) is amended— by redesignating paragraphs
(16)through
(23)as paragraphs
(17)through (24), respectively; and by inserting after paragraph
(15)the following: perform research to support the development of voluntary, consensus-based, industry-led standards and recommendations on the security of computers, computer networks, and computer data storage used in election systems to ensure voters can vote securely and privately. .
Connectionstraces to 3
Traces to 3 documents
3 references not yet in our index
- 15 USC 278g–3
- Pub. L. 104-113
- 15 USC 278g–3(d)(3)
Citation graph
cites case law
Sec. 104
Cybersecurity research
Cite15 USC 278g–3
Pub. L.Pub. L. 104-113
Cite15 USC 278g–3(d)(3)
Cites 6Cited by 0 across 0 sources