Sec. 504. Cybersecurity research
319 words·~1 min read·
/bill/117/hr/2153/ih/section-504·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
The Secretary, acting through the Director, shall expand the fundamental and applied research carried out by the Institute to address key questions relating the measurement of privacy, security, and vulnerability of software tools and communications networks, including through— the development of research and engineering capabilities to provide practical solutions, including measurement techniques and engineering toolkits, to solve cybersecurity challenges such as human factors, identity management, network security, privacy, and software; investment in tools to help private and public sector organizations, including institutions of higher education and research organizations, measure and manage cybersecurity risks and ensure workforce preparedness for new cybersecurity challenges; and investment in programs to prepare the United States with strong cybersecurity and encryption technologies to apply to emerging technologies such as artificial intelligence, the internet of things, and quantum computing.
The Director shall enhance and expand the Institute’s guidance and assistance to Federal agencies to help agencies effectively implement the Framework for Improving Critical Infrastructure Cybersecurity, including— technical guidance on the requirements in the Executive order; technical guidance and education and training of agency staff responsible for cyber security, consultative services, and other assistance at individual Federal agencies; and technical guidance and education and training of individual Federal agency Inspectors General and staff who are responsible for the annual independent evaluation they are required to perform of the information security program and practices of Federal agencies under section 3555 of title 44, United States Code.
The Director shall provide the House Science, Space, and Technology Committee and the Senate Committee on Commerce, Science, and Transportation a report, not later than 12 months after the date of the enactment of this Act, describing how the National Institute of Standards and Technology carried out the activities described in subsection
(b)in as much detail as possible, including identification of agencies assisted and the types of consultative services, education, guidance, assistance, and training provided to individual agencies and Inspectors General.