Implementing cybersecurity standards and best practices developed by the National Institute of Standards and Technology, including frameworks, consistent with section 2(c) of the National Institute of Standards and Technology Act (
15 U.S.C. 272(c)). In implementing such standards and best practices, a State shall, to the extent practicable, utilize CIS Controls from the nonprofit Center for Internet Security (formerly the 20 Critical Security Controls).