US Codex
Bill
Notes

H.R. 2105 — what changed

NIST Small Business Cybersecurity Act

From Introduced in House to Engrossed in House. 2 sections amended and 1 removed between Introduced in House and Engrossed in House.

Section 1 Short title

changed This Act may be cited as the “NIST Small Business Cybersecurity Act of 2017”.Act”.

Sec. 2 Improving cybersecurity of small businesses

(a)
added Definitions— In this section:
(1)
added Director— The term “Director” means the Director of the National Institute of Standards and Technology.
(2)
added Resources— The term “resources” means guidelines, tools, best practices, standards, methodologies, and other ways of providing information.
(3)
added Small business concern— The term “small business concern” has the meaning given such term in section 3 of the Small Business Act (15 U.S.C. 632).

removed Congress makes the following findings:

(b)
changed Small business cybersecurity— Small businesses play a vital role in the economy Section 2(e)(1)(A) of the United States, accounting for 54 percent National Institute of all United States sales Standards and 55 percent of jobs in the United States.Technology Act (15 U.S.C. 272(e)(1)(A)) is amended—
(1)
added in clause (vii), by striking “and” at the end;
(2)
added by redesignating clause (viii) as clause (ix); and
(3)
added by inserting after clause (vii) the following:

added “(viii) consider small business concerns (as defined in section 3 of the Small Business Act (15 U.S.C. 632)); and”

(c)
added Dissemination of resources for small businesses—
(1)
added In general— Not later than one year after the date of the enactment of this Act, the Director, in carrying out section 2(e)(1)(A)(viii) of the National Institute of Standards and Technology Act, as added by subsection (b) of this Act, in consultation with the heads of other appropriate Federal agencies, shall disseminate clear and concise resources to help small business concerns identify, assess, manage, and reduce their cybersecurity risks.
(2)
added Requirements— The Director shall ensure that the resources disseminated pursuant to paragraph (1)—
(A)
added are generally applicable and usable by a wide range of small business concerns;
(B)
added vary with the nature and size of the implementing small business concern, and the nature and sensitivity of the data collected or stored on the information systems or devices of the implementing small business concern;
(C)
added include elements, that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist small business concerns in mitigating common cybersecurity risks;
(D)
added include case studies of practical application;
(E)
added are technology-neutral and can be implemented using technologies that are commercial and off-the-shelf; and
(F)
added are based on international standards to the extent possible, and are consistent with the Stevenson-Wydler Technology Innovation Act of 1980 (15 U.S.C. 3701 et seq.).
(3)
added National cybersecurity awareness and education program— The Director shall ensure that the resources disseminated under paragraph (1) are consistent with the efforts of the Director under section 401 of the Cybersecurity Enhancement Act of 2014 (15 U.S.C. 7451).
(4)
added Small Business Development Center Cyber Strategy— In carrying out paragraph (1), the Director, to the extent practicable, shall consider any methods included in the Small Business Development Center Cyber Strategy developed under section 1841(a)(3)(B) of the National Defense Authorization Act for Fiscal Year 2017 (Public Law 114–328).
(5)
added Voluntary resources— The use of the resources disseminated under paragraph (1) shall be considered voluntary.
(6)
added Updates— The Director shall review and, if necessary, update the resources disseminated under paragraph (1) in accordance with the requirements under paragraph (2).
(7)
added Public availability— The Director and the head of each Federal agency that so elects shall make prominently available on the respective agency’s public Internet website information about the resources and updates to the resources disseminated under paragraph (1). The Director and the heads shall each ensure that the information they respectively make prominently available is consistent, clear, and concise.
(2)
removed Attacks targeting small and medium businesses account for a high percentage of cyberattacks in the United States. Sixty percent of small businesses that suffer a cyberattack are out of business within 6 months, according to the National Cyber Security Alliance.
(d)
changed Other Federal cybersecurity requirements— The Cybersecurity Enhancement Act of 2014 (15 U.S.C. 7421 et seq.) calls on the National Institute of Standards and Technology to facilitate and support a voluntary public-private partnership Nothing in this section may be construed to reduce supersede, alter, or otherwise affect any cybersecurity risks to critical infrastructure. Such a partnership continues requirements applicable to play a key role in improving the cyber resilience of the United States and making cyberspace safer.Federal agencies.
(e)
changed Funding— There is a need This Act shall be carried out using funds otherwise authorized to develop simplified resources that are consistent with be appropriated or made available to the partnership described in paragraph (3) that improves its use by small businesses.National Institute of Standards and Technology.

Sec. 3 Improving cybersecurity of small businesses

removed
(a)
removed Definitions— In this section:
(1)
removed Director— The term “Director” means the Director of the National Institute of Standards and Technology.
(2)
removed Resources— The term “resources” means guidelines, tools, best practices, standards, methodologies, and other ways of providing information.
(3)
removed Small business concern— The term “small business concern” has the meaning given such term in section 3 of the Small Business Act (15 U.S.C. 632).
(b)
removed Small business cybersecurity— Section 2(e)(1)(A) of the National Institute of Standards and Technology Act (15 U.S.C. 272(e)(1)(A)) is amended—
(1)
removed in clause (vii), by striking “and” at the end;
(2)
removed by redesignating clause (viii) as clause (ix); and
(3)
removed by inserting after clause (vii) the following:

removed “(viii) consider small business concerns (as defined in section 3 of the Small Business Act (15 U.S.C. 632)); and”

(c)
removed Dissemination of resources for small businesses—
(1)
removed In general— Not later than one year after the date of the enactment of this Act, the Director, in carrying out section 2(e)(1)(A)(viii) of the National Institute of Standards and Technology Act, as added by subsection (b) of this Act, in consultation with the heads of other appropriate Federal agencies, shall disseminate clear and concise resources to help small business concerns identify, assess, manage, and reduce their cybersecurity risks.
(2)
removed Requirements— The Director shall ensure that the resources disseminated pursuant to paragraph (1)—
(A)
removed are generally applicable and usable by a wide range of small business concerns;
(B)
removed vary with the nature and size of the implementing small business concern, and the nature and sensitivity of the data collected or stored on the information systems or devices of the implementing small business concern;
(C)
removed include elements, that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist small business concerns in mitigating common cybersecurity risks;
(D)
removed are technology-neutral and can be implemented using technologies that are commercial and off-the-shelf; and
(E)
removed are based on international standards to the extent possible, and are consistent with the Stevenson-Wydler Technology Innovation Act of 1980 (15 U.S.C. 3701 et seq.).
(3)
removed National cybersecurity awareness and education program— The Director shall ensure that the resources disseminated under paragraph (1) are consistent with the efforts of the Director under section 401 of the Cybersecurity Enhancement Act of 2014 (15 U.S.C. 7451).
(4)
removed Small Business Development Center Cyber Strategy— In carrying out paragraph (1), the Director, to the extent practicable, shall consider any methods included in the Small Business Development Center Cyber Strategy developed under section 1841(a)(3)(B) of the National Defense Authorization Act for Fiscal Year 2017 (Public Law 114–328).
(5)
removed Voluntary resources— The use of the resources disseminated under paragraph (1) shall be considered voluntary.
(6)
removed Updates— The Director shall review and, if necessary, update the resources disseminated under paragraph (1) in accordance with the requirements under paragraph (2).
(7)
removed Public availability— The Director and the head of each Federal agency that so elects shall make prominently available on the respective agency’s public Internet website information about the resources and updates to the resources disseminated under paragraph (1). The Director and the heads shall each ensure that the information they respectively make prominently available is consistent, clear, and concise.
(d)
removed Other Federal cybersecurity requirements— Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal agencies.
(e)
removed Funding— This Act shall be carried out using funds otherwise authorized to be appropriated or made available to the National Institute of Standards and Technology.