(a)
In general— The Secretary of Defense, in coordination with the Director of the National Institute of Standards and Technology, the Director of the National Science Foundation, and the Secretary of Energy, shall establish a pilot program to ensure the security of federally supported research data and to assist regional institutions of higher education and their researchers in compliance with regulations regarding the safeguarding of sensitive information and other relevant regulations and Federal guidelines.
(b)
Structure— In carrying out the pilot program established pursuant to subsection (a), the Secretary shall select three institutions of higher education from among institutions classified under the Indiana University Center for Postsecondary Research Carnegie Classification as a doctorate-granting university with a very high level of research activity, and with a history of working with secure information for the development, installation, maintenance, or sustainment of secure computing enclaves.
(c)
Regionalization—
(1)
In selecting universities pursuant to subsection (b), the Secretary of Defense shall give preference to institutions of higher education with the capability of serving other regional universities.
(2)
The enclaves should be geographically dispersed to better meet the needs of regional interests.
(d)
Program elements— The Department of Defense shall work with Institutions of Higher Education selected pursuant to subsection (b) to—
(1)
develop an approved design blueprint for compliance with Federal data protection protocols;
(2)
develop a comprehensive and confidential list, or a bill of materials, of each binary component of the software, firmware, or product that is required to deploy additional secure computing enclaves;
(3)
develop templates for all policies and procedures required to operate the secure computing enclave in a research setting;
(4)
develop a system security plan template; and
(5)
develop a process for managing a plan of action and milestones for the secure computing enclave.
(e)
Duration— The pilot program established pursuant to subsection (a) shall operate for not less than 3 years.
(f)
Report—
(1)
In General— The Secretary shall report to the Committee on Armed Services of the House, the Committee on Armed Services of the Senate, the Committee on Science, Space, and Technology of the House, and the Committee on Commerce, Science, and Transportation of the Senate not later than 6 months after the completion of the pilot program under subsection (a).
(2)
Contents— The report required under subsection (f)(1) shall include—
(A)
an assessment of the pilot program under subsection (a), including an assessment of the security benefits provided by such secure computing enclaves;
(B)
recommendations related to the valued of expanding the network of secure computing enclaves; and
(C)
recommendations on the efficacy of the use of secure computing enclaves by other Federal agencies in a broader effort to expand security of Federal research.
(g)
Authorization of appropriations— There is authorized to be appropriated to the Secretary, $38,000,000 for fiscal years 2020 through 2022, to carry out the activities outlined in this section.