Title I — Research and Development
I Research and Development
Sec. 102 Findings
“(1) Advancements in information and communications technology have resulted in a globally interconnected network of government, commercial, scientific, and education infrastructures, including critical infrastructures for electric power, natural gas and petroleum production and distribution, telecommunications, transportation, water supply, banking and finance, and emergency and government services.”
“(3) The Cyberspace Policy Review published by the President in May, 2009, concluded that our information technology and communications infrastructure is vulnerable and has “suffered intrusions that have allowed criminals to steal hundreds of millions of dollars and nation-states and other entities to steal intellectual property and sensitive military information”.”
“(6) While African-Americans, Hispanics, and Native Americans constitute 33 percent of the college-age population, members of these minorities comprise less than 20 percent of bachelor degree recipients in the field of computer sciences.”
Sec. 103 Cybersecurity strategic research and development plan
Sec. 104 Social and behavioral research in cybersecurity
“(J) social and behavioral factors, including human-computer interactions, usability, and user motivations.”
Sec. 105 National Science Foundation cybersecurity research and development programs
“(A) $119,000,000 for fiscal year 2014;
“(B) $119,000,000 for fiscal year 2015; and
“(C) $119,000,000 for fiscal year 2016.”
“(E) how the center will partner with government laboratories, for-profit entities, other institutions of higher education, or nonprofit research institutions.”
“(A) $5,000,000 for fiscal year 2014;
“(B) $5,000,000 for fiscal year 2015; and
“(C) $5,000,000 for fiscal year 2016.”
“(A) $25,000,000 for fiscal year 2014;
“(B) $25,000,000 for fiscal year 2015; and
“(C) $25,000,000 for fiscal year 2016.”
“(A) $4,000,000 for fiscal year 2014;
“(B) $4,000,000 for fiscal year 2015; and
“(C) $4,000,000 for fiscal year 2016.”
“(A) $32,000,000 for fiscal year 2014;
“(B) $32,000,000 for fiscal year 2015; and
“(C) $32,000,000 for fiscal year 2016.”
Sec. 106 Federal cyber scholarship for service program
Sec. 107 Cybersecurity workforce assessment
Sec. 108 Cybersecurity university-industry task force
Sec. 109 Cybersecurity automation and checklists for government systems
“(c) Security automation and checklists for government systems
“(1) In general—The Director of the National Institute of Standards and Technology shall develop, and revise as necessary, security automation standards, associated reference materials (including protocols), and checklists providing settings and option selections that minimize the security risks associated with each information technology hardware or software system and security tool that is, or is likely to become, widely used within the Federal Government in order to enable standardized and interoperable technologies, architectures, and frameworks for continuous monitoring of information security within the Federal Government.
“(2) Priorities for development—The Director of the National Institute of Standards and Technology shall establish priorities for the development of standards, reference materials, and checklists under this subsection on the basis of—
“(A) the security risks associated with the use of the system;
“(B) the number of agencies that use a particular system or security tool;
“(C) the usefulness of the standards, reference materials, or checklists to Federal agencies that are users or potential users of the system;
“(D) the effectiveness of the associated standard, reference material, or checklist in creating or enabling continuous monitoring of information security; or
“(E) such other factors as the Director of the National Institute of Standards and Technology determines to be appropriate.
“(3) Excluded systems—The Director of the National Institute of Standards and Technology may exclude from the application of paragraph (1) any information technology hardware or software system or security tool for which such Director determines that the development of a standard, reference material, or checklist is inappropriate because of the infrequency of use of the system, the obsolescence of the system, or the inutility or impracticability of developing a standard, reference material, or checklist for the system.
“(4) Dissemination of standards and related materials—The Director of the National Institute of Standards and Technology shall ensure that Federal agencies are informed of the availability of any standard, reference material, checklist, or other item developed under this subsection.
“(5) Agency use requirements—The development of standards, reference materials, and checklists under paragraph (1) for an information technology hardware or software system or tool does not—
“(A) require any Federal agency to select the specific settings or options recommended by the standard, reference material, or checklist for the system;
“(B) establish conditions or prerequisites for Federal agency procurement or deployment of any such system;
“(C) imply an endorsement of any such system by the Director of the National Institute of Standards and Technology; or
“(D) preclude any Federal agency from procuring or deploying other information technology hardware or software systems for which no such standard, reference material, or checklist has been developed or identified under paragraph (1).”
Sec. 110 National Institute of Standards and Technology cybersecurity research and development
“(e) Intramural security research—As part of the research activities conducted in accordance with subsection (d)(3), the Institute shall—
“(1) conduct a research program to develop a unifying and standardized identity, privilege, and access control management framework for the execution of a wide variety of resource protection policies and that is amenable to implementation within a wide variety of existing and emerging computing environments;
“(2) carry out research associated with improving the security of information systems and networks;
“(3) carry out research associated with improving the testing, measurement, usability, and assurance of information systems and networks;
“(4) carry out research associated with improving security of industrial control systems; and
“(5) carry out research associated with improving the security and integrity of the information technology supply chain.”