132 STAT. 2444
PUBLIC LAW 115–236—AUG. 14, 2018
Public Law 115–236
115th Congress
An Act
Aug. 14, 2018
[S. 770]
NIST Small
Business
Cybersecurity
Act.
15 USC 271 note.
15 USC 272 note.
dkrause on DSKBC28HB2PROD with PUBLAWS
Deadline.
Consultation.
VerDate Sep 11 2014
06:22 Jun 26, 2019
To require the Director of the National Institute of Standards and Technology
to disseminate guidance to help reduce small business cybersecurity risks, and
for other purposes.
Be it enacted by the Senate and House of Representatives of
the United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the ‘‘NIST Small Business Cybersecurity Act’’.
SEC. 2. IMPROVING CYBERSECURITY OF SMALL BUSINESSES.
(a) DEFINITIONS.—In this section:
(1) DIRECTOR.—The term ‘‘Director’’ means the Director
of the National Institute of Standards and Technology.
(2) RESOURCES.—The term ‘‘resources’’ means guidelines,
tools, best practices, standards, methodologies, and other ways
of providing information.
(3) SMALL BUSINESS CONCERN.—The term ‘‘small business
concern’’ has the meaning given such term in section 3 of
the Small Business Act (15 U.S.C. 632).
(b) SMALL BUSINESS CYBERSECURITY.—Section 2(e)(1)(A) of the
National Institute of Standards and Technology Act (15 U.S.C.
272(e)(1)(A)) is amended—
(1) in clause (vii), by striking ‘‘and’’ at the end;
(2) by redesignating clause (viii) as clause (ix); and
(3) by inserting after clause (vii) the following:
‘‘(viii) consider small business concerns (as defined
in section 3 of the Small Business Act (15 U.S.C.
632)); and’’.
(c) DISSEMINATION OF RESOURCES FOR SMALL BUSINESSES.—
(1) IN GENERAL.—Not later than one year after the date
of the enactment of this Act, the Director, in carrying out
section 2(e)(1)(A)(viii) of the National Institute of Standards
and Technology Act, as added by subsection (b) of this Act,
in consultation with the heads of other appropriate Federal
agencies, shall disseminate clear and concise resources to help
small business concerns identify, assess, manage, and reduce
their cybersecurity risks.
(2) REQUIREMENTS.—The Director shall ensure that the
resources disseminated pursuant to paragraph (1)—
(A) are generally applicable and usable by a wide range
of small business concerns;
(B) vary with the nature and size of the implementing
small business concern, and the nature and sensitivity
Jkt 089139
PO 00236
Frm 00002
Fmt 6580
Sfmt 6581
E:\PUBLAW\PUBL236.115
PUBL236