<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HA43FA66A5E49411BB1211E9D55153FE2" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>116 HR 7998 IH: NIST COVID–19 Cybersecurity Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2020-08-11</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">116th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 7998</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20200811">August 11, 2020</action-date><action-desc><sponsor name-id="B001282">Mr. Barr</sponsor> (for himself and <cosponsor name-id="L000491">Mr. Lucas</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HSY00">Committee on Science, Space, and Technology</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To require the Director of the National Institute of Standards and Technology to disseminate guidance to institutions of higher education and nonprofit research institutions to help mitigate cybersecurity risks to COVID-19 related research, and for other purposes.</official-title></form><legis-body id="H16F92D0D0A4B4FAF830CA4A7BB1A40F7" style="OLC"><section id="H3E4B348B9E6248A0A7A7170E82E1C62D" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>NIST COVID–19 Cybersecurity Act</short-title></quote>.</text></section><section id="HA0817543CDF1416AB50DD32BD0110002"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="H1FD7659528394A7890B7637726C86342"><enum>(1)</enum><header>Director</header><text>The term <quote>Director</quote> means the Director of the National Institute of Standards and Technology.</text></paragraph><paragraph id="HE84055F5840B403E8FBEE695BA952A56" display-inline="no-display-inline"><enum>(2)</enum><header>Institution of higher education</header><text>The term <quote>institution of higher education</quote> has the meaning given such term in section 101 of the Higher Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/1001">20 U.S.C. 1001</external-xref>).</text></paragraph><paragraph id="HC60B5475CFD842B3BB4A2D7D273F7413"><enum>(3)</enum><header>Resources</header><text>The term <quote>resources</quote> means guidelines, tools, best practices, standards, methodologies, and other ways of providing information.</text></paragraph><paragraph id="HBD78D2DF44BA44AEBAF822B9CAC75B0A"><enum>(4)</enum><header>Research institution</header><text>The term <quote>research institution</quote>—</text><subparagraph id="H21F85D37C2CC401DA26064F76577CDF9"><enum>(A)</enum><text>means a nonprofit institution (as defined in section 4(5) of the Stevenson-Wydler Technology Innovation Act of 1980 (<external-xref legal-doc="usc" parsable-cite="usc/15/3703">15 U.S.C. 3703(5)</external-xref>)); and</text></subparagraph><subparagraph id="HD612F69AD9B844F28A30B0111B4D251A"><enum>(B)</enum><text>includes federally funded research and development centers, as identified by the National Science Foundation in accordance with the Federal Acquisition Regulation issued in accordance with section 1303(a)(1) of title 41 (or any successor regulation).</text></subparagraph></paragraph></section><section id="H01508FC22E114FEEBC2A222BF18639B3"><enum>3.</enum><header>Improving cybersecurity of institutions of higher education</header><text display-inline="no-display-inline">Section 2(e)(1)(A) of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/272">15 U.S.C. 272(e)(1)(A)</external-xref>) is amended—</text><paragraph id="H00181561B33C4E3EB0307A05568DF3B2"><enum>(1)</enum><text display-inline="yes-display-inline">in clause (viii), by striking <quote>and</quote> after the semicolon;</text></paragraph><paragraph id="HBC2D6F2307BA4E4C94F3881B2C513885"><enum>(2)</enum><text>by redesignating clause (ix) as clause (x); and</text></paragraph><paragraph id="H698829F0BED54083B00BCC0FA93D5A88"><enum>(3)</enum><text>by inserting after clause (viii) the following:</text><quoted-block style="OLC" id="HFF62AFC3C7C945C499CFC014C44DC95C" display-inline="no-display-inline"><clause id="HF345F28F292945EB8A6B42BFF5E88B14"><enum>(ix)</enum><text display-inline="yes-display-inline">consider institutions of higher education (as defined in section 101 of the Higher Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/1001">20 U.S.C. 1001</external-xref>)); and</text></clause><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section><section id="H268BCBC53F514FEFB0EB4843121664B2"><enum>4.</enum><header>Dissemination of resources for research institutions</header><subsection id="H2FB85CB9D0164C46A3EE98BDBF898902"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 90 days after the date of the enactment of this Act, the Director shall, using the authorities of the Director under subsections (c)(15) and (e)(1)(A)(ix) of section 2 of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/272">15 U.S.C. 272</external-xref>), as amended by section 3, disseminate and make publicly available resources to help research institutions and institutions of higher education identify, assess, manage, and reduce their cybersecurity risk related to conducting research with respect to COVID–19.</text></subsection><subsection id="HB6537261E7FC49DFA21ABCD1434B750B"><enum>(b)</enum><header>Requirements</header><text display-inline="yes-display-inline">The Director shall ensure that the resources disseminated pursuant to subsection (a)—</text><paragraph id="H2B7B5F373BAD4FDAAA12EC2F0A4E89DC"><enum>(1)</enum><text>are generally applicable and usable by a wide range of research institutions and institutions of higher education;</text></paragraph><paragraph id="HF79937936EA248C0B6D901A2D453967C"><enum>(2)</enum><text>vary with the nature and size of the implementing research institutions or institutions of higher education, and the nature and sensitivity of the data collected or stored on the information systems or devices of the implementing research institutions or institutions of higher education; </text></paragraph><paragraph id="H084FAAE3CA71448FB714C676285614F4"><enum>(3)</enum><text>include elements that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist research institutions or institutions of higher education in mitigating common cybersecurity risks; </text></paragraph><paragraph id="HC5759BEB10634642B9E4CF47EF96F778"><enum>(4)</enum><text>include case studies of practical application; </text></paragraph><paragraph id="HD16AD5AA295F45778420D035309C5905"><enum>(5)</enum><text>are technology-neutral and can be implemented using technologies that are commercial and off-the-shelf; and</text></paragraph><paragraph id="HF39DAD69E7DA49D9AD3C03F4D4BE3CF4"><enum>(6)</enum><text display-inline="yes-display-inline">to the extent practicable, are based on international standards. </text></paragraph></subsection><subsection id="H20A1DDED515E4CCA9A36AA5400753291"><enum>(c)</enum><header>National cybersecurity awareness and education program</header><text display-inline="yes-display-inline">The Director shall ensure that the resources disseminated under subsection (a) are consistent with the efforts of the Director under section 401 of the Cybersecurity Enhancement Act of 2014 (<external-xref legal-doc="usc" parsable-cite="usc/15/7451">15 U.S.C. 7451</external-xref>).</text></subsection><subsection id="H9C47A3F3BB27427CB3C971C08A49A9FE"><enum>(d)</enum><header>Updates</header><text>The Director shall review periodically and update the resources under subsection (a) as the Director determines appropriate.</text></subsection><subsection id="H59335983A4614443BDB8FBB2435C81A8"><enum>(e)</enum><header>Voluntary resources</header><text display-inline="yes-display-inline">The use of the resources disseminated under paragraph (1) shall be considered voluntary.</text></subsection><subsection id="HFD7CA13B77164BC2B771440497911321"><enum>(f)</enum><header>Other Federal Cybersecurity Requirements</header><text display-inline="yes-display-inline">Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal agencies.</text></subsection><subsection id="HF7F9810560A049CCB936054FFB177380"><enum>(g)</enum><header>Funding</header><text display-inline="yes-display-inline">This Act shall be carried out using funds made available to the Director. </text></subsection></section></legis-body></bill> 

