Sec. 103
Cybersecurity strategic research and development plan
(a)
In general— Not later than 12 months after the date of enactment of this Act, the agencies identified in subsection 101(a)(3)(B)(i) through (x) of the High-Performance Computing Act of 1991 (15 U.S.C. 5511(a)(3)(B)(i) through (x)) or designated under section 101(a)(3)(B)(xi) of such Act, working through the National Science and Technology Council and with the assistance of the National Coordination Office, shall transmit to Congress a strategic plan based on an assessment of cybersecurity risk to guide the overall direction of Federal cybersecurity and information assurance research and development for information technology and networking systems. Once every 3 years after the initial strategic plan is transmitted to Congress under this section, such agencies shall prepare and transmit to Congress an update of such plan.
(b)
Contents of plan— The strategic plan required under subsection (a) shall—
(1)
specify and prioritize near-term, mid-term and long-term research objectives, including objectives associated with the research areas identified in section 4(a)(1) of the Cyber Security Research and Development Act (15 U.S.C. 7403(a)(1)) and how the near-term objectives complement research and development areas in which the private sector is actively engaged;
(2)
describe how the Program will focus on innovative, transformational technologies with the potential to enhance the security, reliability, resilience, and trustworthiness of the digital infrastructure, and to protect consumer privacy;
(3)
describe how the Program will foster the rapid transfer of research and development results into new cybersecurity technologies and applications for the timely benefit of society and the national interest, including through the dissemination of best practices and other outreach activities;
(4)
describe how the Program will establish and maintain a national research infrastructure for creating, testing, and evaluating the next generation of secure networking and information technology systems;
(5)
changed
describe how the Program will facilitate access by academic researchers to the infrastructure described in paragraph (4), as well as to relevant data, including event data; anddata;
(6)
changed
describe how the Program will engage females and individuals identified in section 33 or 34 of the Science and Engineering Equal Opportunities Act (42 U.S.C. 1885a or 1885b) to foster a more diverse workforce in this area.area; and
(7)
added
describe how the Program will help to recruit and prepare veterans for the Federal cybersecurity workforce.
(c)
Development of roadmap— The agencies described in subsection (a) shall develop and annually update an implementation roadmap for the strategic plan required in this section. Such roadmap shall—
(1)
specify the role of each Federal agency in carrying out or sponsoring research and development to meet the research objectives of the strategic plan, including a description of how progress toward the research objectives will be evaluated;
(2)
specify the funding allocated to each major research objective of the strategic plan and the source of funding by agency for the current fiscal year; and
(3)
estimate the funding required for each major research objective of the strategic plan for the following 3 fiscal years.
(d)
Recommendations— In developing and updating the strategic plan under subsection (a), the agencies involved shall solicit recommendations and advice from—
(1)
the advisory committee established under section 101(b)(1) of the High-Performance Computing Act of 1991 (15 U.S.C. 5511(b)(1)); and
(2)
a wide range of stakeholders, including industry, academia, including representatives of minority serving institutions and community colleges, National Laboratories, and other relevant organizations and institutions.
(e)
Appending to report— The implementation roadmap required under subsection (c), and its annual updates, shall be appended to the report required under section 101(a)(2)(D) of the High-Performance Computing Act of 1991 (15 U.S.C. 5511(a)(2)(D)).
(f)
added
Cybersecurity research database— The agencies involved in developing and updating the strategic plan under subsection (a) shall establish, in coordination with the Office of Management and Budget, a mechanism to track ongoing and completed Federal cybersecurity research and development projects and associated funding, and shall make such information publically available.
Sec. 105
National Science Foundation cybersecurity research and development programs
(a)
Computer and network security research areas— Section 4(a)(1) of the Cyber Security Research and Development Act (15 U.S.C. 7403(a)(1)) is amended—
(1)
in subparagraph (A) by inserting “identity management,” after “cryptography,”; and
(2)
in subparagraph (I), by inserting “, crimes against children, and organized crime” after “intellectual property”.
(b)
Computer and network security research grants— Section 4(a)(3) of such Act (15 U.S.C. 7403(a)(3)) is amended by striking subparagraphs (A) through (E) and inserting the following new subparagraphs:
changed
“(A) $90,000,000 $119,000,000 for fiscal year 2014;
changed
“(B) $90,000,000 $119,000,000 for fiscal year 2015; and
changed
“(C) $90,000,000 $119,000,000 for fiscal year 2016.”
(c)
Computer and network security research centers— Section 4(b) of such Act (15 U.S.C. 7403(b)) is amended—
(A)
in subparagraph (C), by striking “and” after the semicolon;
(B)
in subparagraph (D), by striking the period and inserting “; and”; and
(C)
by adding at the end the following new subparagraph:
“(E) how the center will partner with government laboratories, for-profit entities, other institutions of higher education, or nonprofit research institutions.”
(2)
in paragraph (7) by striking subparagraphs (A) through (E) and inserting the following new subparagraphs:
changed
“(A) $4,500,000 $5,000,000 for fiscal year 2014;
changed
“(B) $4,500,000 $5,000,000 for fiscal year 2015; and
changed
“(C) $4,500,000 $5,000,000 for fiscal year 2016.”
(d)
Computer and network security capacity building grants— Section 5(a)(6) of such Act (15 U.S.C. 7404(a)(6)) is amended by striking subparagraphs (A) through (E) and inserting the following new subparagraphs:
changed
“(A) $19,000,000 $25,000,000 for fiscal year 2014;
changed
“(B) $19,000,000 $25,000,000 for fiscal year 2015; and
changed
“(C) $19,000,000 $25,000,000 for fiscal year 2016.”
(e)
Scientific and advanced technology act grants— Section 5(b)(2) of such Act (15 U.S.C. 7404(b)(2)) is amended by striking subparagraphs (A) through (E) and inserting the following new subparagraphs:
changed
“(A) $2,500,000 $4,000,000 for fiscal year 2014;
changed
“(B) $2,500,000 $4,000,000 for fiscal year 2015; and
changed
“(C) $2,500,000 $4,000,000 for fiscal year 2016.”
(f)
Graduate traineeships in computer and network security— Section 5(c)(7) of such Act (15 U.S.C. 7404(c)(7)) is amended by striking subparagraphs (A) through (E) and inserting the following new subparagraphs:
changed
“(A) $24,000,000 $32,000,000 for fiscal year 2014;
changed
“(B) $24,000,000 $32,000,000 for fiscal year 2015; and
changed
“(C) $24,000,000 $32,000,000 for fiscal year 2016.”
(g)
Cyber security faculty development traineeship program— Section 5(e) of such Act (15 U.S.C. 7404(e)) is repealed.
Sec. 106
Federal cyber scholarship for service program
(a)
In general— The Director of the National Science Foundation shall continue a Scholarship for Service program under section 5(a) of the Cyber Security Research and Development Act (15 U.S.C. 7404(a)) to recruit and train the next generation of Federal cybersecurity professionals and to increase the capacity of the higher education system to produce an information technology workforce with the skills necessary to enhance the security of the Nation’s communications and information infrastructure.
(b)
Characteristics of program— The program under this section shall—
(1)
changed
provide, through qualified institutions of higher education, including community colleges, scholarships that provide tuition, fees, and a competitive stipend for up to 2 years to students pursing a bachelor’s or master’s degree and up to 3 years to students pursuing a doctoral degree in a cybersecurity field;
(2)
provide the scholarship recipients with summer internship opportunities or other meaningful temporary appointments in the Federal information technology workforce; and
(3)
increase the capacity of institutions of higher education throughout all regions of the United States to produce highly qualified cybersecurity professionals, through the award of competitive, merit-reviewed grants that support such activities as—
(A)
faculty professional development, including technical, hands-on experiences in the private sector or government, workshops, seminars, conferences, and other professional development opportunities that will result in improved instructional capabilities;
(B)
changed
institutional partnerships, including minority serving institutions and community colleges; andcolleges;
(C)
changed
development and evaluation of cybersecurity-related courses and curricula.curricula; and
(D)
added
public-private partnerships that will integrate research experiences and hands-on learning into cybersecurity degree programs.
(c)
Scholarship requirements—
(1)
Eligibility— Scholarships under this section shall be available only to students who—
(A)
are citizens or permanent residents of the United States;
(B)
are full-time students in an eligible degree program, as determined by the Director, that is focused on computer security or information assurance at an awardee institution; and
(C)
accept the terms of a scholarship pursuant to this section.
(2)
changed
Selection— Individuals shall be selected to receive scholarships primarily on the basis of academic merit, with consideration given to financial need, to the goal of promoting the participation of females and individuals identified in section 33 or 34 of the Science and Engineering Equal Opportunities Act (42 U.S.C. 1885a or 1885b), and to veterans. For purposes of this paragraph, the term “veteran” means a person who—
(A)
served on active duty (other than active duty for training) in the Armed Forces of the United States for a period of more than 180 consecutive days, and who was discharged or released therefrom under conditions other than dishonorable; or
(B)
served on active duty (other than active duty for training) in the Armed Forces of the United States and was discharged or released from such service for a service-connected disability before serving 180 consecutive days.
(3)
Service obligation— If an individual receives a scholarship under this section, as a condition of receiving such scholarship, the individual upon completion of their degree must serve as a cybersecurity professional within the Federal workforce for a period of time as provided in paragraph (5). If a scholarship recipient is not offered employment by a Federal agency or a federally funded research and development center, the service requirement can be satisfied at the Director’s discretion by—
(A)
serving as a cybersecurity professional in a State, local, or tribal government agency; or
(B)
teaching cybersecurity courses at an institution of higher education.
(4)
Conditions of support— As a condition of acceptance of a scholarship under this section, a recipient shall agree to provide the awardee institution with annual verifiable documentation of employment and up-to-date contact information.
(5)
Length of service— The length of service required in exchange for a scholarship under this subsection shall be 1 year more than the number of years for which the scholarship was received.
(d)
Failure To complete service obligation—
(1)
General rule— If an individual who has received a scholarship under this section—
(A)
fails to maintain an acceptable level of academic standing in the educational institution in which the individual is enrolled, as determined by the Director;
(B)
is dismissed from such educational institution for disciplinary reasons;
(C)
withdraws from the program for which the award was made before the completion of such program;
(D)
declares that the individual does not intend to fulfill the service obligation under this section; or
(E)
fails to fulfill the service obligation of the individual under this section,
(2)
Monitoring compliance— As a condition of participating in the program, a qualified institution of higher education receiving a grant under this section shall—
(A)
enter into an agreement with the Director of the National Science Foundation to monitor the compliance of scholarship recipients with respect to their service obligation; and
(B)
provide to the Director, on an annual basis, post-award employment information required under subsection (c)(4) for scholarship recipients through the completion of their service obligation.
(A)
Less than one year of service— If a circumstance described in paragraph (1) occurs before the completion of 1 year of a service obligation under this section, the total amount of awards received by the individual under this section shall be repaid or such amount shall be treated as a loan to be repaid in accordance with subparagraph (C).
(B)
More than one year of service— If a circumstance described in subparagraph (D) or (E) of paragraph (1) occurs after the completion of 1 year of a service obligation under this section, the total amount of scholarship awards received by the individual under this section, reduced by the ratio of the number of years of service completed divided by the number of years of service required, shall be repaid or such amount shall be treated as a loan to be repaid in accordance with subparagraph (C).
(C)
Repayments— A loan described in subparagraph (A) or (B) shall be treated as a Federal Direct Unsubsidized Stafford Loan under part D of title IV of the Higher Education Act of 1965 (20 U.S.C. 1087a and following), and shall be subject to repayment, together with interest thereon accruing from the date of the scholarship award, in accordance with terms and conditions specified by the Director (in consultation with the Secretary of Education) in regulations promulgated to carry out this paragraph.
(4)
Collection of repayment—
(A)
In general— In the event that a scholarship recipient is required to repay the scholarship under this subsection, the institution providing the scholarship shall—
(i)
be responsible for determining the repayment amounts and for notifying the recipient and the Director of the amount owed; and
(ii)
collect such repayment amount within a period of time as determined under the agreement described in paragraph (2), or the repayment amount shall be treated as a loan in accordance with paragraph (3)(C).
(B)
Returned to treasury— Except as provided in subparagraph (C) of this paragraph, any such repayment shall be returned to the Treasury of the United States.
(C)
Retain percentage— An institution of higher education may retain a percentage of any repayment the institution collects under this paragraph to defray administrative costs associated with the collection. The Director shall establish a single, fixed percentage that will apply to all eligible entities.
(5)
Exceptions— The Director may provide for the partial or total waiver or suspension of any service or payment obligation by an individual under this section whenever compliance by the individual with the obligation is impossible or would involve extreme hardship to the individual, or if enforcement of such obligation with respect to the individual would be unconscionable.
(e)
added
Hiring Authority—
(1)
added
Appointment in excepted service— Notwithstanding any provision of chapter 33 of title 5, United States Code, governing appointments in the competitive service, an agency shall appoint in the excepted service an individual who has completed the academic program for which a scholarship was awarded.
(2)
added
Noncompetitive conversion— Except as provided in paragraph (4), upon fulfillment of the service term, an employee appointed under paragraph (1) may be converted noncompetitively to term, career-conditional or career appointment.
(3)
added
Timing of conversion— An agency may noncompetitively convert a term employee appointed under paragraph (2) to a career-conditional or career appointment before the term appointment expires.
(4)
added
Authority to decline conversion— An agency may decline to make the noncompetitive conversion or appointment under paragraph (2) for cause.
(e)
removed
Hiring authority— For purposes of any law or regulation governing the appointment of individuals in the Federal civil service, upon successful completion of their degree, students receiving a scholarship under this section shall be hired under the authority provided for in section 213.3102(r) of title 5, Code of Federal Regulations, and be exempted from competitive service. Upon fulfillment of the service term, such individuals shall be converted to a competitive service position without competition if the individual meets the requirements for that position.
Sec. 108
Cybersecurity university-industry task force
(a)
Establishment of university-Industry task force— Not later than 180 days after the date of enactment of this Act, the Director of the Office of Science and Technology Policy shall convene a task force to explore mechanisms for carrying out collaborative research, development, education, and training activities for cybersecurity through a consortium or other appropriate entity with participants from institutions of higher education and industry.
(b)
Functions— The task force shall—
(1)
develop options for a collaborative model and an organizational structure for such entity under which the joint research and development activities could be planned, managed, and conducted effectively, including mechanisms for the allocation of resources among the participants in such entity for support of such activities;
(2)
changed
propose a process for developing a research identify and development agenda for such entity, including guidelines to ensure an appropriate scope of work prioritize at least three cybersecurity grand challenges, focused on nationally significant challenges and problems requiring collaboration;collaborative and interdisciplinary solutions;
(3)
added
propose a process for developing a research and development agenda for such entity to address the grand challenges identified under paragraph (2);
(4)
renumbered
was (3)(5)
define the roles and responsibilities for the participants from institutions of higher education and industry in such entity;
(5)
renumbered
was (3)(6)
propose guidelines for assigning intellectual property rights and for the transfer of research and development results to the private sector; and
(6)
renumbered
was (3)(7)
make recommendations for how such entity could be funded from Federal, State, and nongovernmental sources.
(c)
Composition— In establishing the task force under subsection (a), the Director of the Office of Science and Technology Policy shall appoint an equal number of individuals from institutions of higher education, including minority-serving institutions and community colleges, and from industry with knowledge and expertise in cybersecurity.
(d)
Report— Not later than 12 months after the date of enactment of this Act, the Director of the Office of Science and Technology Policy shall transmit to the Congress a report describing the findings and recommendations of the task force.
(e)
Termination— The task force shall terminate upon transmittal of the report required under subsection (d).
(f)
Compensation and expenses— Members of the task force shall serve without compensation.
Sec. 110
National Institute of Standards and Technology cybersecurity research and development
Section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) is amended by redesignating subsection (e) as subsection (f), and by inserting after subsection (d) the following:
“(e) Intramural security research—As part of the research activities conducted in accordance with subsection (d)(3), the Institute shall—
“(1) conduct a research program to develop a unifying and standardized identity, privilege, and access control management framework for the execution of a wide variety of resource protection policies and that is amenable to implementation within a wide variety of existing and emerging computing environments;
“(2) carry out research associated with improving the security of information systems and networks;
changed
“(3) carry out research associated with improving the testing, measurement, usability, and assurance of information systems and networks; andnetworks;
changed
“(4) carry out research associated with improving security of industrial control systems.”systems; and
added
“(5) carry out research associated with improving the security and integrity of the information technology supply chain.”
Sec. 204
Promoting cybersecurity awareness and education
(a)
Program— The Director, in collaboration with relevant Federal agencies, industry, educational institutions, National Laboratories, the National Coordination Office of the Networking and Information Technology Research and Development program, and other organizations, shall continue to coordinate a cybersecurity awareness and education program to increase knowledge, skills, and awareness of cybersecurity risks, consequences, and best practices through—
(1)
the widespread dissemination of cybersecurity technical standards and best practices identified by the Institute;
(2)
changed
efforts to make cybersecurity best practices usable by individuals, small to medium-sized businesses, State, local, and tribal governments, and educational institutions; andinstitutions;
(3)
changed
efforts to attract, recruit, and retain qualified professionals to improving the Federal state of cybersecurity workforce.education at all educational levels;
(4)
added
efforts to attract, recruit, and retain qualified professionals to the Federal cybersecurity workforce; and
(5)
added
improving the skills, training, and professional development of the Federal cybersecurity workforce.
(b)
Strategic plan— The Director shall, in cooperation with relevant Federal agencies and other stakeholders, develop and implement a strategic plan to guide Federal programs and activities in support of a comprehensive cybersecurity awareness and education program as described under subsection (a).
(c)
Report to congress— Not later than 1 year after the date of enactment of this Act and every 5 years thereafter, the Director shall transmit the strategic plan required under subsection (b) to the Committee on Science, Space, and Technology of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate.