<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H846A2F89115246DD8BC839F8895497C7" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 2105 IH: NIST Small Business Cybersecurity Act of 2017</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2017-04-20</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">115th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 2105</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20170420">April 20, 2017</action-date><action-desc><sponsor name-id="W000806">Mr. Webster of Florida</sponsor> (for himself, <cosponsor name-id="L000563">Mr. Lipinski</cosponsor>, <cosponsor name-id="S000583">Mr. Smith of Texas</cosponsor>, <cosponsor name-id="C001105">Mrs. Comstock</cosponsor>, <cosponsor name-id="R000608">Ms. Rosen</cosponsor>, <cosponsor name-id="H001059">Mr. Hultgren</cosponsor>, <cosponsor name-id="K000387">Mr. Knight</cosponsor>, <cosponsor name-id="L000585">Mr. LaHood</cosponsor>, <cosponsor name-id="M001198">Mr. Marshall</cosponsor>, and <cosponsor name-id="P000599">Mr. Posey</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HSY00">Committee on Science, Space, and Technology</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To require the Director of the National Institute of Standards and Technology to disseminate
			 guidance to help reduce small business cybersecurity risks, and for other
			 purposes.</official-title></form>
	<legis-body id="H7ED7EA25701E4A148A0CE068630F0A57" style="OLC">
 <section id="HC35E44F04D7D4A24BF380B7C3EBAECCD" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>NIST Small Business Cybersecurity Act of 2017</short-title></quote>.</text> </section><section id="HDD4C84436A4A48A1B267F7CD05C9E9AF"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress makes the following findings:</text>
 <paragraph id="H2754F17D035F494F98F788F589255CA7"><enum>(1)</enum><text>Small businesses play a vital role in the economy of the United States, accounting for 54 percent of all United States sales and 55 percent of jobs in the United States.</text>
 </paragraph><paragraph id="H1847108621654D57A3944ABC8CD5358B"><enum>(2)</enum><text>Attacks targeting small and medium businesses account for a high percentage of cyberattacks in the United States. Sixty percent of small businesses that suffer a cyberattack are out of business within 6 months, according to the National Cyber Security Alliance.</text>
 </paragraph><paragraph id="H2077EF6FF34D433D8C1B4CCB3D2E37BE"><enum>(3)</enum><text>The Cybersecurity Enhancement Act of 2014 (<external-xref legal-doc="usc" parsable-cite="usc/15/7421">15 U.S.C. 7421</external-xref> et seq.) calls on the National Institute of Standards and Technology to facilitate and support a voluntary public-private partnership to reduce cybersecurity risks to critical infrastructure. Such a partnership continues to play a key role in improving the cyber resilience of the United States and making cyberspace safer.</text>
 </paragraph><paragraph id="HF2AF6A88EEA6498F9FA70E7C0B1CC648"><enum>(4)</enum><text>There is a need to develop simplified resources that are consistent with the partnership described in paragraph (3) that improves its use by small businesses.</text>
			</paragraph></section><section id="HE859952CD6B84B2FB55FDE02BB8B036A"><enum>3.</enum><header>Improving cybersecurity of small businesses</header>
 <subsection id="H9129970E0B5842FDA0A8346E95C1E557"><enum>(a)</enum><header>Definitions</header><text>In this section:</text> <paragraph id="H02489C25B796426BAF9D661C993A9F85"><enum>(1)</enum><header>Director</header><text>The term <quote>Director</quote> means the Director of the National Institute of Standards and Technology.</text>
 </paragraph><paragraph id="H13A60B31289F46EEACEADBA306CD747E"><enum>(2)</enum><header>Resources</header><text>The term <quote>resources</quote> means guidelines, tools, best practices, standards, methodologies, and other ways of providing information.</text>
 </paragraph><paragraph id="HBFF43F0ECCD841E4939FAAA10B9C5CFA"><enum>(3)</enum><header>Small business concern</header><text>The term <quote>small business concern</quote> has the meaning given such term in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>).</text> </paragraph></subsection><subsection id="HD686D3D6FEE84BB6810B396DE71BBD9D"><enum>(b)</enum><header>Small business cybersecurity</header><text>Section 2(e)(1)(A) of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/272">15 U.S.C. 272(e)(1)(A)</external-xref>) is amended—</text>
 <paragraph id="HB2022A9E61424E1C9971778710D2802D"><enum>(1)</enum><text>in clause (vii), by striking <quote>and</quote> at the end;</text> </paragraph><paragraph id="HE5FAFDC97E4D4DD9994FADD5F384A917"><enum>(2)</enum><text>by redesignating clause (viii) as clause (ix); and</text>
 </paragraph><paragraph id="H14888AC95E134D66864B1A6CCCEC69BE"><enum>(3)</enum><text>by inserting after clause (vii) the following:</text> <quoted-block id="H8B2EA7A5AE5A45D793431A5AF7CB226E" style="OLC"> <clause id="H7AA519DEC6C04AEB8A17672122FFEF25"><enum>(viii)</enum><text>consider small business concerns (as defined in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>)); and</text></clause><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="H0A37C91AB9EC4663A8E22BE45125EBB5"><enum>(c)</enum><header>Dissemination of resources for small businesses</header>
 <paragraph id="H04D54BA4567C4C04AF8E2720A7068E15"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than one year after the date of the enactment of this Act, the Director, in carrying out section 2(e)(1)(A)(viii) of the National Institute of Standards and Technology Act, as added by subsection (b) of this Act, in consultation with the heads of other appropriate Federal agencies, shall disseminate clear and concise resources to help small business concerns identify, assess, manage, and reduce their cybersecurity risks.</text>
 </paragraph><paragraph id="H15BD7151CCEC48758C38516349D0D82F"><enum>(2)</enum><header>Requirements</header><text>The Director shall ensure that the resources disseminated pursuant to paragraph (1)—</text> <subparagraph id="H1E91135C634144B08728A46138C7F099"><enum>(A)</enum><text>are generally applicable and usable by a wide range of small business concerns;</text>
 </subparagraph><subparagraph id="HCF1194847403444C94B1E49D5B06729D"><enum>(B)</enum><text>vary with the nature and size of the implementing small business concern, and the nature and sensitivity of the data collected or stored on the information systems or devices of the implementing small business concern;</text>
 </subparagraph><subparagraph id="H82C2411D03134BC59B48816270EA6835"><enum>(C)</enum><text>include elements, that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist small business concerns in mitigating common cybersecurity risks;</text>
 </subparagraph><subparagraph id="H0EFE1E5631334C40AA2D61F8D7738D98"><enum>(D)</enum><text>are technology-neutral and can be implemented using technologies that are commercial and off-the-shelf; and</text>
 </subparagraph><subparagraph id="H75A866EB18DE4B36AE1D23B0E95A66C9"><enum>(E)</enum><text>are based on international standards to the extent possible, and are consistent with the Stevenson-Wydler Technology Innovation Act of 1980 (<external-xref legal-doc="usc" parsable-cite="usc/15/3701">15 U.S.C. 3701</external-xref> et seq.).</text>
 </subparagraph></paragraph><paragraph id="HB70A2EF5D48745548AC22C96ADCF105B"><enum>(3)</enum><header>National cybersecurity awareness and education program</header><text>The Director shall ensure that the resources disseminated under paragraph (1) are consistent with the efforts of the Director under section 401 of the Cybersecurity Enhancement Act of 2014 (<external-xref legal-doc="usc" parsable-cite="usc/15/7451">15 U.S.C. 7451</external-xref>).</text>
 </paragraph><paragraph id="H6F8786D076B9470BA006068AC167C9E3"><enum>(4)</enum><header>Small Business Development Center Cyber Strategy</header><text>In carrying out paragraph (1), the Director, to the extent practicable, shall consider any methods included in the Small Business Development Center Cyber Strategy developed under section 1841(a)(3)(B) of the National Defense Authorization Act for Fiscal Year 2017 (<external-xref legal-doc="public-law" parsable-cite="pl/114/328">Public Law 114–328</external-xref>).</text>
 </paragraph><paragraph id="HC2CBB5252C314CDE97C94C99F35F9481"><enum>(5)</enum><header>Voluntary resources</header><text>The use of the resources disseminated under paragraph (1) shall be considered voluntary.</text> </paragraph><paragraph id="HCE0A0CBDD8DB47A29B5645BE72CF541E"><enum>(6)</enum><header>Updates</header><text>The Director shall review and, if necessary, update the resources disseminated under paragraph (1) in accordance with the requirements under paragraph (2).</text>
 </paragraph><paragraph id="HC9ECD1547D4D466F99037BE9E29CE523"><enum>(7)</enum><header>Public availability</header><text>The Director and the head of each Federal agency that so elects shall make prominently available on the respective agency’s public Internet website information about the resources and updates to the resources disseminated under paragraph (1). The Director and the heads shall each ensure that the information they respectively make prominently available is consistent, clear, and concise.</text>
 </paragraph></subsection><subsection id="H98514A45FF3143A09BA77B3373B6D301"><enum>(d)</enum><header>Other Federal cybersecurity requirements</header><text>Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal agencies.</text>
 </subsection><subsection id="H7CF2BB45905B470DABCE07ECD8921E18"><enum>(e)</enum><header>Funding</header><text display-inline="yes-display-inline">This Act shall be carried out using funds otherwise authorized to be appropriated or made available to the National Institute of Standards and Technology.</text>
			</subsection></section></legis-body></bill>


