Public Law 115-236. NIST Small Business Cybersecurity Act
718 words·~3 min read·
/plaw/115/public/236A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
An Act To require the Director of the National Institute of Standards and Technology to disseminate guidance to help reduce small business cybersecurity risks, and for other purposes.Aug. 14, 2018[[S. 770](/us/bill/115/s/770)] * Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,* NIST Small Business Cybersecurity Act.[15 USC 271 note](/us/usc/t15/s271). ## SECTION 1 SHORT TITLE This Act may be cited as the “NIST Small Business Cybersecurity Act”. ## SEC. 2 IMPROVING CYBERSECURITY OF SMALL BUSINESSES [15 USC 272 note](/us/usc/t15/s272). ###
(a)Definitions In this section: ####
(1)Director The term “**Director**” means the Director of the National Institute of Standards and Technology. ####
(2)Resources The term “**resources**” means guidelines, tools, best practices, standards, methodologies, and other ways of providing information. ####
(3)Small business concern The term “**small business concern**” has the meaning given such term in section 3 of the Small Business Act ([15 U.S.C. 632](/us/usc/t15/s632)). ###
(b)Small Business Cybersecurity Section 2(e)(1)(A) of the National Institute of Standards and Technology Act ([15 U.S.C. 272(e)(1)(A)](/us/usc/t15/s272/e/1/A)) is amended— ####
(1)in clause (vii), by striking “and” at the end; ####
(2)by redesignating clause
(viii)as clause (ix); and ####
(3)by inserting after clause
(vii)the following: > > ###### “(viii) > > consider small business concerns (as defined in section 3 of the Small Business Act ([15 U.S.C. 632](/us/usc/t15/s632))); and” > . ###
(c)Dissemination of Resources for Small Businesses ####
(1)In general Deadline.Consultation. Not later than one year after the date of the enactment of this Act, the Director, in carrying out section 2(e)(1)(A)(viii) of the National Institute of Standards and Technology Act, as added by subsection
(b)of this Act, in consultation with the heads of other appropriate Federal agencies, shall disseminate clear and concise resources to help small business concerns identify, assess, manage, and reduce their cybersecurity risks. ####
(2)Requirements The Director shall ensure that the resources disseminated pursuant to paragraph (1)— #####
(A)are generally applicable and usable by a wide range of small business concerns; #####
(B)vary with the nature and size of the implementing small business concern, and the nature and sensitivity 132 STAT. 2445 of the data collected or stored on the information systems or devices of the implementing small business concern; #####
(C)include elements, that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist small business concerns in mitigating common cybersecurity risks; #####
(D)include case studies of practical application; #####
(E)are technology-neutral and can be implemented using technologies that are commercial and off-the-shelf; and #####
(F)are based on international standards to the extent possible, and are consistent with the Stevenson-Wydler Technology Innovation Act of 1980 ([15 U.S.C. 3701 et seq.](/us/usc/t15/s3701/etseq)). ####
(3)National cybersecurity awareness and education program The Director shall ensure that the resources disseminated under paragraph
(1)are consistent with the efforts of the Director under section 401 of the Cybersecurity Enhancement Act of 2014 ([15 U.S.C. 7451](/us/usc/t15/s7451)). ####
(4)Small business development center cyber strategy In carrying out paragraph (1), the Director, to the extent practicable, shall consider any methods included in the Small Business Development Center Cyber Strategy developed under section 1841(a)(3)(B) of the National Defense Authorization Act for Fiscal Year 2017 ([Public Law 114–328](/us/pl/114/328)). ####
(5)Voluntary resources The use of the resources disseminated under paragraph
(1)shall be considered voluntary. ####
(6)Updates Review. The Director shall review and, if necessary, update the resources disseminated under paragraph
(1)in accordance with the requirements under paragraph (2). ####
(7)Public availability Web posting. The Director and the head of each Federal agency that so elects shall make prominently available on the respective agency’s public Internet website information about the resources and updates to the resources disseminated under paragraph (1). The Director and the heads shall each ensure that the information they respectively make prominently available is consistent, clear, and concise. ###
(d)Other Federal Cybersecurity Requirements Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal agencies.132 STAT. 2446 ###
(e)Funding This Act shall be carried out using funds otherwise authorized to be appropriated or made available to the National Institute of Standards and Technology. Approved August 14, 2018.
Connections23 cite this · traces to 6
Cited by 23 sections · top 18
public-private-law
statute-compilations
statutes-at-large
- Public Law 115–236To require the Director of the National Institute of Standards and Technology to disseminate guidance to help reduce small business cybersecurity risks, and for other purposes
- Public Law 115–235To amend title 23, United States Code, to extend the deadline for promulgation of regulations under the tribal transportation self-governance program
- Public Law 116–283To authorize appropriations for fiscal year 2021 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes
bill
- Sec. 2Improving National Initiative for Cybersecurity Education
- Sec. 5231Improving National Initiative for Cybersecurity Education
- Sec. 9401Improving national initiative for cybersecurity education
- Sec. 2Improving cybersecurity of small organizations
- Sec. 2Improving National Initiative for Cybersecurity Education
- Sec. 5231Improving National Initiative for Cybersecurity Education
- Sec. 2Improving cybersecurity of small organizations
- Sec. 50107Improving cybersecurity of small entities
- Sec. 50107Improving cybersecurity of small entities
- Sec. 2Improving cybersecurity of small entities
- Sec. 2Improving cybersecurity of small organizations
Traces to 6 documents
Citation graph
cites case law
Public Law 115-236
NIST Small Business Cybersecurity Act
Bills×11
U.S.C.×6
Stat.×4
Pub. L.×1
Stat. Comp.×1
Cites 6Cited by 23 across 5 sources