US Codex
Pub. L.
Notes

Title II — Cybersecurity Research and Development

113th Congress · Approved Dec 18, 2014 · 128 Stat. 2971

TITLE II Cybersecurity Research and Development

SEC. 201. Federal Cybersecurity Research and Development.

(a)
Fundamental Cybersecurity Research.—
(1)
Federal cybersecurity research and development strategic plan.— The heads of the applicable agencies and departments, working through the National Science and Technology Council and the Networking and Information Technology Research and Development Program, shall develop and update every 4 years a Federal cybersecurity research and development strategic plan (referred to in this subsection as the “strategic plan”) based on an assessment of cybersecurity risk to guide the overall direction of Federal cybersecurity and information assurance research and development for information technology and networking systems. The heads of the applicable agencies and departments shall build upon existing programs and plans to develop the strategic plan to meet objectives in cybersecurity, such as—
(A)
how to design and build complex software-intensive systems that are secure and reliable when first deployed;
(B)
how to test and verify that software and hardware, whether developed locally or obtained from a third party, is free of significant known security flaws;
(C)
how to test and verify that software and hardware obtained from a third party correctly implements stated functionality, and only that functionality;
(D)
how to guarantee the privacy of an individual, including that individual’s identity, information, and lawful transactions when stored in distributed systems or transmitted over networks;
(E)
how to build new protocols to enable the Internet to have robust security as one of the key capabilities of the Internet;
(F)
how to determine the origin of a message transmitted over the Internet;
(G)
how to support privacy in conjunction with improved security;
(H)
how to address the problem of insider threats;
(I)
how improved consumer education and digital literacy initiatives can address human factors that contribute to cybersecurity;
(J)
how to protect information processed, transmitted, or stored using cloud computing or transmitted through wireless services; and
(K)
any additional objectives the heads of the applicable agencies and departments, in coordination with the head of any relevant Federal agency and with input from stakeholders, including appropriate national laboratories, industry, and academia, determine appropriate.
(2)
Requirements.—
(A)
Contents of plan.— The strategic plan shall—
(i)
specify and prioritize near-term, mid-term, and long-term research objectives, including objectives associated with the research identified in section 4(a)(1) of the Cyber Security Research and Development Act (15 U.S.C. 7403(a)(1));
(ii)
specify how the near-term objectives described in clause (i) complement research and development areas in which the private sector is actively engaged;
(iii)
describe how the heads of the applicable agencies and departments will focus on innovative, transformational technologies with the potential to enhance the security, reliability, resilience, and trustworthiness of the digital infrastructure, and to protect consumer privacy;
(iv)
describe how the heads of the applicable agencies and departments will foster the rapid transfer of research and development results into new cybersecurity technologies and applications for the timely benefit of society and the national interest, including through the dissemination of best practices and other outreach activities;
(v)
describe how the heads of the applicable agencies and departments will establish and maintain a national research infrastructure for creating, testing, and evaluating the next generation of secure networking and information technology systems; and
(vi)
describe how the heads of the applicable agencies and departments will facilitate access by academic researchers to the infrastructure described in clause (v), as well as to relevant data, including event data.
(B)
Private sector efforts.— In developing, implementing, and updating the strategic plan, the heads of the applicable agencies and departments, working through the National Science and Technology Council and Networking and Information Technology Research and Development Program, shall work in close cooperation with industry, academia, and other interested stakeholders to ensure, to the extent possible, that Federal cybersecurity research and development is not duplicative of private sector efforts.
(C)
Recommendations.— In developing and updating the strategic plan the heads of the applicable agencies and departments shall solicit recommendations and advice from—
(i)
the advisory committee established under section 101(b)(1) of the High-Performance Computing Act of 1991 (15 U.S.C. 5511(b)(1)); and
(ii)
a wide range of stakeholders, including industry, academia, including representatives of minority serving institutions and community colleges, National Laboratories, and other relevant organizations and institutions.
(D)
Implementation roadmap.— The heads of the applicable agencies and departments, working through the National Science and Technology Council and Networking and Information Technology Research and Development Program, shall develop and annually update an implementation roadmap for the strategic plan. The implementation roadmap shall—
(i)
specify the role of each Federal agency in carrying out or sponsoring research and development to meet the research objectives of the strategic plan, including a description of how progress toward the research objectives will be evaluated;
(ii)
specify the funding allocated to each major research objective of the strategic plan and the source of funding by agency for the current fiscal year;
(iii)
estimate the funding required for each major research objective of the strategic plan for the following 3 fiscal years; and
(iv)
track ongoing and completed Federal cybersecurity research and development projects.
(3)
Reports to congress.— The heads of the applicable agencies and departments, working through the National Science and Technology Council and Networking and Information Technology Research and Development Program, shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives—
(A)
the strategic plan not later than 1 year after the date of enactment of this Act;
(B)
each quadrennial update to the strategic plan; and
(C)
the implementation roadmap under subparagraph (D), and its annual updates, which shall be appended to the annual report required under section 101(a)(2)(D) of the High-Performance Computing Act of 1991 (15 U.S.C. 5511(a)(2)(D)).
(4)
Definition of applicable agencies and departments.— In this subsection, the term “applicable agencies and departments” means the agencies and departments identified in clauses (i) through (x) of section 101(a)(3)(B) of the High-Performance Computing Act of 1991 (15 U.S.C. 5511(a)(3)(B)) or designated under clause (xi) of that section.
(b)
Cybersecurity Practices Research.— The Director of the National Science Foundation shall support research that—
(1)
develops, evaluates, disseminates, and integrates new cybersecurity practices and concepts into the core curriculum of computer science programs and of other programs where graduates of such programs have a substantial probability of developing software after graduation, including new practices and concepts relating to secure coding education and improvement programs; and
(2)
develops new models for professional development of faculty in cybersecurity education, including secure coding development.
(c)
Cybersecurity Modeling and Test Beds.—
(1)
Review.— Not later than 1 year after the date of enactment of this Act, the Director of the National Science Foundation, in coordination with the Director of the Office of Science and Technology Policy, shall conduct a review of cybersecurity test beds in existence on the date of enactment of this Act to inform the grants under paragraph (2). The review shall include an assessment of whether a sufficient number of cybersecurity test beds are available to meet the research needs under the Federal cybersecurity research and development strategic plan. Upon completion, the Director shall submit the review to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives.
(2)
Additional cybersecurity modeling and test beds.—
(A)
In general.— If the Director of the National Science Foundation, after the review under paragraph (1), determines that the research needs under the Federal cybersecurity research and development strategic plan require the establishment of additional cybersecurity test beds, the Director of the National Science Foundation, in coordination with the Secretary of Commerce and the Secretary of Homeland Security, may award grants to institutions of higher education or research and development non-profit institutions to establish cybersecurity test beds.
(B)
Requirement.— The cybersecurity test beds under subparagraph (A) shall be sufficiently robust in order to model the scale and complexity of real-time cyber attacks and defenses on real world networks and environments.
(C)
Assessment required.— The Director of the National Science Foundation, in coordination with the Secretary of Commerce and the Secretary of Homeland Security, shall evaluate the effectiveness of any grants awarded under this subsection in meeting the objectives of the Federal cybersecurity research and development strategic plan not later than 2 years after the review under paragraph (1) of this subsection, and periodically thereafter.
(d)
Coordination With Other Research Initiatives.— In accordance with the responsibilities under section 101 of the High-Performance Computing Act of 1991 (15 U.S.C. 5511), the Director of the Office of Science and Technology Policy shall coordinate, to the extent practicable, Federal research and development activities under this section with other ongoing research and development security-related initiatives, including research being conducted by—
(1)
the National Science Foundation;
(2)
the National Institute of Standards and Technology;
(3)
the Department of Homeland Security;
(4)
other Federal agencies;
(5)
other Federal and private research laboratories, research entities, and universities;
(6)
institutions of higher education;
(7)
relevant nonprofit organizations; and
(8)
international partners of the United States.
(e)
National Science Foundation Computer and Network Security Research Grant Areas.— Section 4(a)(1) of the Cyber Security Research and Development Act (15 U.S.C. 7403(a)(1)) is amended—
(1)
in subparagraph (H), by striking “ and” at the end;
(2)
in subparagraph (I), by striking the period at the end and inserting a semicolon; and
(3)
by adding at the end the following:

“(J) secure fundamental protocols that are integral to inter-network communications and data exchange;

“(K) secure software engineering and software assurance, including—

“(i) programming languages and systems that include fundamental security features;

“(ii) portable or reusable code that remains secure when deployed in various environments;

“(iii) verification and validation technologies to ensure that requirements and specifications have been implemented; and

“(iv) models for comparison and metrics to assure that required standards have been met;

“(L) holistic system security that—

“(i) addresses the building of secure systems from trusted and untrusted components;

“(ii) proactively reduces vulnerabilities;

“(iii) addresses insider threats; and

“(iv) supports privacy in conjunction with improved security;

“(M) monitoring and detection;

“(N) mitigation and rapid recovery methods;

“(O) security of wireless networks and mobile devices; and

“(P) security of cloud infrastructure and services.”

(f)
Research on the Science of Cybersecurity.— The head of each agency and department identified under section 101(a)(3)(B) of the High-Performance Computing Act of 1991 (15 U.S.C. 5511(a)(3)(B)), through existing programs and activities, shall support research that will lead to the development of a scientific foundation for the field of cybersecurity, including research that increases understanding of the underlying principles of securing complex networked systems, enables repeatable experimentation, and creates quantifiable security metrics.

SEC. 202. Computer and Network Security Research Centers.

Section 4(b) of the Cyber Security Research and Development Act (15 U.S.C. 7403(b)) is amended—
(1)
in paragraph (3), by striking “ the research areas” and inserting the following: “ improving the security and resiliency of information technology, reducing cyber vulnerabilities, and anticipating and mitigating consequences of cyber attacks on critical infrastructure, by conducting research in the areas”;
(2)
by striking “ the center” in paragraph (4)(D) and inserting “ the Center”; and
(3)
in paragraph (5)—
(A)
by striking “ and” at the end of subparagraph (C);
(B)
by striking the period at the end of subparagraph (D) and inserting a semicolon; and
(C)
by adding at the end the following:

“(E) the demonstrated capability of the applicant to conduct high performance computation integral to complex computer and network security research, through on-site or off-site computing;

“(F) the applicant’s affiliation with private sector entities involved with industrial research described in subsection (a)(1);

“(G) the capability of the applicant to conduct research in a secure environment;

“(H) the applicant’s affiliation with existing research programs of the Federal Government;

“(I) the applicant’s experience managing public-private partnerships to transition new technologies into a commercial setting or the government user community;

“(J) the capability of the applicant to conduct interdisciplinary cybersecurity research, basic and applied, such as in law, economics, or behavioral sciences; and

“(K) the capability of the applicant to conduct research in areas such as systems security, wireless security, networking and protocols, formal methods and high-performance computing, nanotechnology, or industrial control systems.”

SEC. 203. Cybersecurity Automation and Checklists for Government Systems.

Section 8(c) of the Cyber Security Research and Development Act (15 U.S.C. 7406(c)) is amended to read as follows:

“(c) Security Automation and Checklists for Government Systems.—

“(1) In general.—The Director of the National Institute of Standards and Technology shall, as necessary, develop and revise security automation standards, associated reference materials (including protocols), and checklists providing settings and option selections that minimize the security risks associated with each information technology hardware or software system and security tool that is, or is likely to become, widely used within the Federal Government, thereby enabling standardized and interoperable technologies, architectures, and frameworks for continuous monitoring of information security within the Federal Government.

“(2) Priorities for development.—The Director of the National Institute of Standards and Technology shall establish priorities for the development of standards, reference materials, and checklists under this subsection on the basis of—

“(A) the security risks associated with the use of the system;

“(B) the number of agencies that use a particular system or security tool;

“(C) the usefulness of the standards, reference materials, or checklists to Federal agencies that are users or potential users of the system;

“(D) the effectiveness of the associated standard, reference material, or checklist in creating or enabling continuous monitoring of information security; or

“(E) such other factors as the Director of the National Institute of Standards and Technology determines to be appropriate.

“(3) Excluded systems.—The Director of the National Institute of Standards and Technology may exclude from the application of paragraph (1) any information technology hardware or software system or security tool for which such Director determines that the development of a standard, reference material, or checklist is inappropriate because of the infrequency of use of the system, the obsolescence of the system, or the lack of utility or impracticability of developing a standard, reference material, or checklist for the system.

“(4) Dissemination of standards and related materials.—The Director of the National Institute of Standards and Technology shall ensure that Federal agencies are informed of the availability of any standard, reference material, checklist, or other item developed under this subsection.

“(5) Agency use requirements.—The development of standards, reference materials, and checklists under paragraph (1) for an information technology hardware or software system or tool does not—

“(A) require any Federal agency to select the specific settings or options recommended by the standard, reference material, or checklist for the system;

“(B) establish conditions or prerequisites for Federal agency procurement or deployment of any such system;

“(C) imply an endorsement of any such system by the Director of the National Institute of Standards and Technology; or

“(D) preclude any Federal agency from procuring or deploying other information technology hardware or software systems for which no such standard, reference material, or checklist has been developed or identified under paragraph (1).”

SEC. 204. National Institute of Standards and Technology Cybersecurity Research and Development.

Section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) is amended—
(1)
by redesignating subsection (e) as subsection (f); and
(2)
by inserting after subsection (d) the following:

“(e) Intramural Security Research.—As part of the research activities conducted in accordance with subsection (d)(3), the Institute shall, to the extent practicable and appropriate—

“(1) conduct a research program to develop a unifying and standardized identity, privilege, and access control management framework for the execution of a wide variety of resource protection policies and that is amenable to implementation within a wide variety of existing and emerging computing environments;

“(2) carry out research associated with improving the security of information systems and networks;

“(3) carry out research associated with improving the testing, measurement, usability, and assurance of information systems and networks;

“(4) carry out research associated with improving security of industrial control systems;

“(5) carry out research associated with improving the security and integrity of the information technology supply chain; and

“(6) carry out any additional research the Institute determines appropriate.”