128 STAT. 2974 PUBLIC LAW 113–274—DEC. 18, 2014 development of such standards and procedures be voluntary and led by industry representatives; (C) the extent to which other Federal agencies have promoted and sectors of critical infrastructure (as defined in section 1016(e) of the USA PATRIOT Act of 2001 (42 U.S.C. 5195c(e))) have adopted a voluntary, industry-led set of standards, guidelines, best practices, methodologies, procedures, and processes to reduce cyber risks to critical infrastructure in accordance with such section 2(c)(15); (D) the reasons behind the decisions of sectors of critical infrastructure (as defined in subparagraph (C)) to adopt or to not adopt the voluntary standards described in subparagraph (C); and (E) the extent to which such voluntary standards have proved successful in protecting critical infrastructure from cyber threats. (2) REPORTS.—Not later than 1 year after the date of the enactment of this Act, and every 2 years thereafter for the following 6 years, the Comptroller General shall submit a report, which summarizes the findings of the study conducted under paragraph (1), to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives. 15 USC prec. 7431. 15 USC 7431. TITLE II—CYBERSECURITY RESEARCH AND DEVELOPMENT SEC. 201. FEDERAL CYBERSECURITY RESEARCH AND DEVELOPMENT. (a) FUNDAMENTAL CYBERSECURITY RESEARCH.— (1) FEDERAL CYBERSECURITY RESEARCH AND DEVELOPMENT STRATEGIC PLAN.—The heads of the applicable agencies and departments, working through the National Science and Technology Council and the Networking and Information Technology Research and Development Program, shall develop and update every 4 years a Federal cybersecurity research and development strategic plan (referred to in this subsection as the ‘‘strategic plan’’) based on an assessment of cybersecurity risk to guide the overall direction of Federal cybersecurity and information assurance research and development for information technology and networking systems. The heads of the applicable agencies and departments shall build upon existing programs and plans to develop the strategic plan to meet objectives in cybersecurity, such as— (A) how to design and build complex software-intensive systems that are secure and reliable when first deployed; (B) how to test and verify that software and hardware, whether developed locally or obtained from a third party, is free of significant known security flaws; (C) how to test and verify that software and hardware obtained from a third party correctly implements stated functionality, and only that functionality; (D) how to guarantee the privacy of an individual, including that individual’s identity, information, and lawful transactions when stored in distributed systems or transmitted over networks; dkrause on DSKHT7XVN1PROD with PUBLAWS Deadline. VerDate Mar 15 2010 07:01 Mar 03, 2015 Jkt 049139 PO 00274 Frm 00004 Fmt 6580 Sfmt 6581 E:\PUBLAW\PUBL274.113 PUBL274

Select target paragraph3