Improving Cybersecurity of Small Businesses, Nonprofits, and Local Governments Act
A BILL
To require the Director of the Cybersecurity and Infrastructure Security Agency to establish cybersecurity guidance for small organizations, and for other purposes.
Sec. 2 Improving cybersecurity of small entities
“2220D. Annual cybersecurity report for small entities
“(a) Definitions
“(1) Administration—The term Administration means the Small Business Administration.
“(2) Administrator—The term Administrator means the Administrator of the Administration.
“(3) Annual cybersecurity report—The term annual cybersecurity report means the annual cybersecurity report published and promoted under subsections (b) and (c), respectively.
“(4) Commission—The term Commission means the Federal Trade Commission.
“(5) Electronic device—The term electronic device means any electronic equipment that is—
“(A) used by an employee or contractor of a small entity for the purpose of performing work for the small entity;
“(B) capable of connecting to the internet or another communication network; and
“(C) capable of sending, receiving, or processing personal information.
“(6) NIST—The term NIST means the National Institute of Standards and Technology.
“(7) Small business—The term small business has the meaning given the term small business concern under section 3 of the Small Business Act (15 U.S.C. 632).
“(8) Small entity—The term small entity means—
“(A) a small business;
“(B) a small governmental jurisdiction; and
“(C) a small organization.
“(9) Small governmental jurisdiction—The term small governmental jurisdiction means governments of cities, counties, towns, townships, villages, school districts, or special districts with a population of less than 50,000.
“(10) Small organization—The term small organization means any not-for-profit enterprise that is independently owned and operated and is not dominant in its field.
“(b) Annual cybersecurity report
“(1) In general—Not later than 180 days after the date of enactment of this section, and not less frequently than annually thereafter, the Director shall publish a report for small entities that documents and promotes evidence-based cybersecurity policies and controls for use by small entities, which shall—
“(A) include basic controls that have the most impact in protecting small entities against common cybersecurity threats and risks;
“(B) include protocols and policies to address common cybersecurity threats and risks posed by electronic devices, regardless of whether the electronic devices are—
“(i) issued by the small entity to employees and contractors of the small entity; or
“(ii) personal to the employees and contractors of the small entity; and
“(C) recommend, as practicable—
“(i) measures to improve the cybersecurity of small entities; and
“(ii) configurations and settings for some of the most commonly used software that can improve the cybersecurity of small entities.
“(2) Existing recommendations—The Director shall ensure that each annual cybersecurity report published under paragraph (1) incorporates—
“(A) cybersecurity resources developed by NIST, as required by the NIST Small Business Cybersecurity Act (Public Law 115–236); and
“(B) the most recent version of the Cybersecurity Framework, or successor resource, maintained by NIST.
“(3) Consideration for specific types of small entities—The Director may include and prioritize the development of cybersecurity recommendations, as required under paragraph (1), appropriate for specific types of small entities in addition to recommendations applicable for all small entities.
“(4) Consultation—In publishing the annual cybersecurity report under paragraph (1), the Director shall, to the degree practicable and as appropriate, consult with—
“(A) the Administrator, the Secretary of Commerce, the Commission, and the Director of NIST;
“(B) small entities, insurers, State governments, companies that work with small entities, and academic and Federal and non-Federal experts in cybersecurity; and
“(C) any other entity as determined appropriate by the Director.
“(c) Promotion of annual cybersecurity report for small businesses
“(1) Publication—The annual cybersecurity report, and previous versions of the report as appropriate, published under subsection (b)(1) shall be—
“(A) made available, prominently and free of charge, on the public website of the Agency; and
“(B) linked to from relevant portions of the websites of the Administration and the Minority Business Development Agency, as determined by the Administrator and the Director of the Minority Business Development Agency, respectively.
“(2) Promotion generally—The Director, the Administrator, and the Secretary of Commerce shall, to the degree practicable, promote the annual cybersecurity report through relevant resources that are intended for or known to be regularly used by small entities, including agency documents, websites, and events.
“(d) Training and technical assistance—The Director, the Administrator, and the Director of the Minority Business Development Agency shall make available to employees of small entities voluntary training and technical assistance on how to implement the recommendations of the annual cybersecurity report.”