Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · U.S. Code · Title 42 - THE PUBLIC HEALTH AND WELFARE · CHAPTER 163— RESEARCH AND DEVELOPMENT, COMPETITION, AND INNOVATION · SUBCHAPTER II— NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY FOR THE FUTURE · § 18935

§ 18935. Dissemination of resources for research institutions

344 words·~2 min read·/usc/title-42/section-18935

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

(a)Dissemination of resources for research institutions
(1)In general Not later than one year after August 9, 2022, the Director shall, using the authorities of the Director under subsections (c)(15) and (e)(1)(A)(ix) of section 272 of title 15, disseminate and make publicly available tailored resources to help qualifying institutions identify, assess, manage, and reduce their cybersecurity risk related to conducting research.
(2)Requirements The Director shall ensure that the resources disseminated pursuant to paragraph (1)—
(A)are generally applicable and usable by a wide range of qualifying institutions;
(B)vary with the nature and size of the qualifying institutions, and the nature and sensitivity of the data collected or stored on the information systems or devices of the qualifying institutions;
(C)include elements that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist qualifying institutions in mitigating common cybersecurity risks;
(D)include case studies, examples, and scenarios of practical application;
(E)are outcomes-based and can be implemented using a variety of technologies that are commercial and off-the-shelf; and
(F)to the extent practicable, are based on international technical standards.
(3)National cybersecurity awareness and education program The Director shall ensure that the resources disseminated under paragraph
(1)are consistent with the efforts of the Director under section 7443 of title 15.
(4)Updates The Director shall review periodically and update the resources under paragraph
(1)as the Director determines appropriate.
(5)Voluntary resources The use of the resources disseminated under paragraph
(1)shall be considered voluntary.
(b)Other Federal cybersecurity requirements Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal agencies.
(c)Definitions In this section:
(1)Qualifying institutions The term “qualifying institutions” means institutions of higher education that are awarded in excess of $50,000,000 per year in total Federal research funding.
(2)Resources The term “resources” means guidelines, tools, best practices, technical standards, methodologies, and other ways of providing information.
(Pub. L. 117–167, div. B, title II, § 10229, Aug. 9, 2022, 136 Stat. 1481.)
Connections3 cite this · traces to 3
1 reference not yet in our index
  • 136 Stat. 1481
Citation graph
cites case law
§ 18935
Dissemination of resources for research institutions
Pub. L.×1
Stat. Comp.×1
Stat.×1
Stat.136 Stat. 1481
Cites 4Cited by 3 across 3 sources
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.