PUBLIC LAW 115–236—AUG. 14, 2018 132 STAT. 2445 dkrause on DSKBC28HB2PROD with PUBLAWS of the data collected or stored on the information systems or devices of the implementing small business concern; (C) include elements, that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist small business concerns in mitigating common cybersecurity risks; (D) include case studies of practical application; (E) are technology-neutral and can be implemented using technologies that are commercial and off-the-shelf; and (F) are based on international standards to the extent possible, and are consistent with the Stevenson-Wydler Technology Innovation Act of 1980 (15 U.S.C. 3701 et seq.). (3) NATIONAL CYBERSECURITY AWARENESS AND EDUCATION PROGRAM.—The Director shall ensure that the resources disseminated under paragraph (1) are consistent with the efforts of the Director under section 401 of the Cybersecurity Enhancement Act of 2014 (15 U.S.C. 7451). (4) SMALL BUSINESS DEVELOPMENT CENTER CYBER STRATEGY.—In carrying out paragraph (1), the Director, to the extent practicable, shall consider any methods included in the Small Business Development Center Cyber Strategy developed under section 1841(a)(3)(B) of the National Defense Authorization Act for Fiscal Year 2017 (Public Law 114–328). (5) VOLUNTARY RESOURCES.—The use of the resources disseminated under paragraph (1) shall be considered voluntary. (6) UPDATES.—The Director shall review and, if necessary, update the resources disseminated under paragraph (1) in accordance with the requirements under paragraph (2). (7) PUBLIC AVAILABILITY.—The Director and the head of each Federal agency that so elects shall make prominently available on the respective agency’s public Internet website information about the resources and updates to the resources disseminated under paragraph (1). The Director and the heads shall each ensure that the information they respectively make prominently available is consistent, clear, and concise. (d) OTHER FEDERAL CYBERSECURITY REQUIREMENTS.—Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal agencies. VerDate Sep 11 2014 06:22 Jun 26, 2019 Jkt 089139 PO 00236 Frm 00003 Fmt 6580 Sfmt 6581 E:\PUBLAW\PUBL236.115 Review. Web posting. PUBL236

Select target paragraph3