Title II — Advancement of Cybersecurity Technical Standards
II Advancement of Cybersecurity Technical Standards
Sec. 202 International cybersecurity technical standards
In general— The Director, in coordination with appropriate Federal authorities, shall—
as appropriate, ensure coordination of Federal agencies engaged in the development of international technical standards related to information system security; and
not later than 1 year after the date of enactment of this Act, develop and transmit to the Congress a plan for ensuring such Federal agency coordination.
Consultation with the private sector— In carrying out the activities specified in subsection (a)(1), the Director shall ensure consultation with appropriate private sector stakeholders.
Sec. 203 Cloud computing strategy
In general— The Director, in collaboration with the Federal CIO Council, and in consultation with other relevant Federal agencies and stakeholders from the private sector, shall continue to develop and encourage the implementation of a comprehensive strategy for the use and adoption of cloud computing services by the Federal Government.
Activities— In carrying out the strategy developed under subsection (a), the Director shall give consideration to activities that—
accelerate the development, in collaboration with the private sector, of standards that address interoperability and portability of cloud computing services;
advance the development of conformance testing performed by the private sector in support of cloud computing standardization; and
support, in consultation with the private sector, the development of appropriate security frameworks and reference materials, and the identification of best practices, for use by Federal agencies to address security and privacy requirements to enable the use and adoption of cloud computing services, including activities—
to ensure the physical security of cloud computing data centers and the data stored in such centers;
to ensure secure access to the data stored in cloud computing data centers;
to develop security standards as required under section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3); and
to support the development of the automation of continuous monitoring systems.
Sec. 204 Promoting cybersecurity awareness and education
Program— The Director, in collaboration with relevant Federal agencies, industry, educational institutions, National Laboratories, the National Coordination Office of the Networking and Information Technology Research and Development program, and other organizations, shall continue to coordinate a cybersecurity awareness and education program to increase knowledge, skills, and awareness of cybersecurity risks, consequences, and best practices through—
the widespread dissemination of cybersecurity technical standards and best practices identified by the Institute;
efforts to make cybersecurity best practices usable by individuals, small to medium-sized businesses, State, local, and tribal governments, and educational institutions;
improving the state of cybersecurity education at all educational levels;
efforts to attract, recruit, and retain qualified professionals to the Federal cybersecurity workforce; and
improving the skills, training, and professional development of the Federal cybersecurity workforce.
Strategic plan— The Director shall, in cooperation with relevant Federal agencies and other stakeholders, develop and implement a strategic plan to guide Federal programs and activities in support of a comprehensive cybersecurity awareness and education program as described under subsection (a).
Report to congress— Not later than 1 year after the date of enactment of this Act and every 5 years thereafter, the Director shall transmit the strategic plan required under subsection (b) to the Committee on Science, Space, and Technology of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate.
Sec. 205 Identity management research and development
The Director shall continue a program to support the development of technical standards, metrology, testbeds, and conformance criteria, taking into account appropriate user concerns, to—
improve interoperability among identity management technologies;
strengthen authentication methods of identity management systems;
improve privacy protection in identity management systems, including health information technology systems, through authentication and security protocols; and
improve the usability of identity management systems.
Sec. 206 Authorizations
No additional funds are authorized to carry out this Act, and the amendments made by this Act. This Act, and the amendments made by this Act, shall be carried out using amounts otherwise authorized or appropriated.