Sec. 10229. Dissemination of resources for research institutions
322 words·~1 min read·
/bill/117/hr/4521/pcs/section-10229A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than one year after the date of the enactment of this Act, the Director shall, using the authorities of the Director under subsections (c)(15) and (e)(1)(A)(ix) of section 2 of the National Institute of Standards and Technology Act ( 15 U.S.C. 272 ), as amended by section 10228, disseminate and make publicly available resources to help qualifying institutions identify, assess, manage, and reduce their cybersecurity risk related to conducting research. The Director shall ensure that the resources disseminated pursuant to paragraph (1)— are generally applicable and usable by a wide range of qualifying institutions; vary with the nature and size of the qualifying institutions, and the nature and sensitivity of the data collected or stored on the information systems or devices of the qualifying institutions; include elements that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist qualifying institutions in mitigating common cybersecurity risks; include case studies, examples, and scenarios of practical application; are technology-neutral and can be implemented using technologies that are commercial and off-the-shelf; and to the extent practicable, are based on international technical standards.
The Director shall ensure that the resources disseminated under paragraph
(1)are consistent with the efforts of the Director under section 303 of the Cybersecurity Enhancement Act of 2014 ( 15 U.S.C. 7451 ). The Director shall review periodically and update the resources under paragraph
(1)as the Director determines appropriate. The use of the resources disseminated under paragraph
(1)shall be considered voluntary. Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal agencies. In this section: The term qualifying institutions means institutions of higher education that are classified as either very-high research intensive
(R1)or high research intensive
(R2)status universities by the Carnegie Classification of Academic Institutions. The term resources means guidelines, tools, best practices, technical standards, methodologies, and other ways of providing information.
Connectionstraces to 2
Traces to 2 documents
Citation graph
cites case law
Cites 2Cited by 0 across 0 sources