<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Enrolled-Bill" bill-type="olc" dms-id="A1" public-print="no" public-private="public" stage-count="1" star-print="no-star-print"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title> S770 ENR: NIST Small Business Cybersecurity Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date></dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form display="yes">
<congress>One Hundred Fifteenth Congress of the United States of America</congress><session display="yes">2d Session</session><enrolled-dateline display="yes">Begun and held at the City of Washington on Wednesday, the third day of January, two thousand and
			 eighteen</enrolled-dateline><legis-num display="yes">S. 770</legis-num><current-chamber display="no">IN THE SENATE OF THE UNITED
		  STATES</current-chamber><legis-type display="yes">AN ACT</legis-type><official-title display="yes">To require the Director of the National Institute of Standards and Technology to disseminate
			 guidance to help reduce small business cybersecurity risks, and for other
 purposes.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause" style="OLC"><section commented="no" display-inline="no-display-inline" id="H4A4A12D56CD543CFA02D5AD48E9972ED" section-type="section-one"><enum>1.</enum><header display-inline="yes-display-inline">Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>NIST Small Business Cybersecurity Act</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" id="H52BDF720194E4028BBC19DD40DC9AB12" section-type="subsequent-section"><enum>2.</enum><header display-inline="yes-display-inline">Improving cybersecurity of small businesses</header><subsection commented="no" display-inline="no-display-inline" id="H16E200AFAA394C6DA88610A7C62F2E36"><enum>(a)</enum><header display-inline="yes-display-inline">Definitions</header><text display-inline="yes-display-inline">In this section:</text><paragraph commented="no" display-inline="no-display-inline" id="H4DB2CBB328EE4A0494ADBA782B902EFA"><enum>(1)</enum><header display-inline="yes-display-inline">Director</header><text display-inline="yes-display-inline">The term <quote>Director</quote> means the Director of the National Institute of Standards and Technology.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="HC3B6E9C69B744B05BA3744BFCEA38589"><enum>(2)</enum><header display-inline="yes-display-inline">Resources</header><text display-inline="yes-display-inline">The term <quote>resources</quote> means guidelines, tools, best practices, standards, methodologies, and other ways of providing information.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="HA6B64B850BA74D6D9A59A2B2C1F1855F"><enum>(3)</enum><header display-inline="yes-display-inline">Small business concern</header><text display-inline="yes-display-inline">The term <quote>small business concern</quote> has the meaning given such term in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>).</text></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="HBF032309E55841A5B9DC2052DF119CFF"><enum>(b)</enum><header display-inline="yes-display-inline">Small business cybersecurity</header><text display-inline="yes-display-inline">Section 2(e)(1)(A) of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/272">15 U.S.C. 272(e)(1)(A)</external-xref>) is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="H6E1C5F3D0F5540A08D3C59DE49E5E3B1"><enum>(1)</enum><text display-inline="yes-display-inline">in clause (vii), by striking <quote>and</quote> at the end;</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="HCC03F8589B704C97ACB7A59D1527B87E"><enum>(2)</enum><text display-inline="yes-display-inline">by redesignating clause (viii) as clause (ix); and</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="H8C97F26672EB4201819C7F826D2E76A6"><enum>(3)</enum><text display-inline="yes-display-inline">by inserting after clause (vii) the following:</text><quoted-block display-inline="no-display-inline" id="H486D2891873A4CF9B5E6DC8D2FDD1B7F" style="OLC"><clause commented="no" display-inline="no-display-inline" id="HEC83FAEBF53244EBAD37D58C3158FF83"><enum>(viii)</enum><text display-inline="yes-display-inline">consider small business concerns (as defined in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>)); and</text></clause><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="H6CEDA0319D74492484E2F4FCDC133AFE"><enum>(c)</enum><header display-inline="yes-display-inline">Dissemination of resources for small businesses</header><paragraph commented="no" display-inline="no-display-inline" id="HE56828EE87CC43658E075DD2550931C0"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Not later than one year after the date of the enactment of this Act, the Director, in carrying out section 2(e)(1)(A)(viii) of the National Institute of Standards and Technology Act, as added by subsection (b) of this Act, in consultation with the heads of other appropriate Federal agencies, shall disseminate clear and concise resources to help small business concerns identify, assess, manage, and reduce their cybersecurity risks.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="H7E1E0472CFD74D14BEACD31E31D4B169"><enum>(2)</enum><header display-inline="yes-display-inline">Requirements</header><text display-inline="yes-display-inline">The Director shall ensure that the resources disseminated pursuant to paragraph (1)—</text><subparagraph commented="no" display-inline="no-display-inline" id="H6EBF314282AF4D93AAFBE5C6683E2006"><enum>(A)</enum><text display-inline="yes-display-inline">are generally applicable and usable by a wide range of small business concerns;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="HD6309BE729CF45598BCAF23DE52BDA54"><enum>(B)</enum><text display-inline="yes-display-inline">vary with the nature and size of the implementing small business concern, and the nature and sensitivity of the data collected or stored on the information systems or devices of the implementing small business concern;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H3F8EFFF1090541C38D352ED8EEF57707"><enum>(C)</enum><text display-inline="yes-display-inline">include elements, that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist small business concerns in mitigating common cybersecurity risks;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H0CBAF48FE31C40BCA5F7C1DD6C96E4C4"><enum>(D)</enum><text display-inline="yes-display-inline">include case studies of practical application;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H5980054E3CFF4F959BB8C274483D44F3"><enum>(E)</enum><text display-inline="yes-display-inline">are technology-neutral and can be implemented using technologies that are commercial and off-the-shelf; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H3B757A684140443093BFA6B059323129"><enum>(F)</enum><text display-inline="yes-display-inline">are based on international standards to the extent possible, and are consistent with the Stevenson-Wydler Technology Innovation Act of 1980 (<external-xref legal-doc="usc" parsable-cite="usc/15/3701">15 U.S.C. 3701</external-xref> et seq.).</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="H215B4527D5404336B24F55ACC8F9393D"><enum>(3)</enum><header display-inline="yes-display-inline">National cybersecurity awareness and education program</header><text display-inline="yes-display-inline">The Director shall ensure that the resources disseminated under paragraph (1) are consistent with the efforts of the Director under section 401 of the Cybersecurity Enhancement Act of 2014 (<external-xref legal-doc="usc" parsable-cite="usc/15/7451">15 U.S.C. 7451</external-xref>).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="HFEAFA4BCD5AA4CB0AA7BFECA6A454F37"><enum>(4)</enum><header display-inline="yes-display-inline">Small Business Development Center Cyber Strategy</header><text display-inline="yes-display-inline">In carrying out paragraph (1), the Director, to the extent practicable, shall consider any methods included in the Small Business Development Center Cyber Strategy developed under section 1841(a)(3)(B) of the National Defense Authorization Act for Fiscal Year 2017 (<external-xref legal-doc="public-law" parsable-cite="pl/114/328">Public Law 114–328</external-xref>).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="H34DCB1B6774847D288228812205C9286"><enum>(5)</enum><header display-inline="yes-display-inline">Voluntary resources</header><text display-inline="yes-display-inline">The use of the resources disseminated under paragraph (1) shall be considered voluntary.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="H9010C69F56BC45FC91C4D1E0D90B6CE4"><enum>(6)</enum><header display-inline="yes-display-inline">Updates</header><text display-inline="yes-display-inline">The Director shall review and, if necessary, update the resources disseminated under paragraph (1) in accordance with the requirements under paragraph (2).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="HD26DA59365DA434DAD604F6190547867"><enum>(7)</enum><header display-inline="yes-display-inline">Public availability</header><text display-inline="yes-display-inline">The Director and the head of each Federal agency that so elects shall make prominently available on the respective agency’s public Internet website information about the resources and updates to the resources disseminated under paragraph (1). The Director and the heads shall each ensure that the information they respectively make prominently available is consistent, clear, and concise.</text></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="HB089279DF6D640EE8A651A0189F0BF2E"><enum>(d)</enum><header display-inline="yes-display-inline">Other Federal cybersecurity requirements</header><text display-inline="yes-display-inline">Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal agencies.</text></subsection><subsection commented="no" display-inline="no-display-inline" id="HC01B0D61EE7B4B66BC43721969B34DB8"><enum>(e)</enum><header display-inline="yes-display-inline">Funding</header><text display-inline="yes-display-inline">This Act shall be carried out using funds otherwise authorized to be appropriated or made available to the National Institute of Standards and Technology.</text></subsection></section></legis-body><attestation><attestation-group><attestor display="no"></attestor><role>Speaker of the House of Representatives</role></attestation-group><attestation-group><attestor display="no"></attestor><role>Vice President of the United States and President of the Senate</role></attestation-group></attestation></bill>


