128 STAT. 2974
PUBLIC LAW 113–274—DEC. 18, 2014
development of such standards and procedures be voluntary
and led by industry representatives;
(C) the extent to which other Federal agencies have
promoted and sectors of critical infrastructure (as defined
in section 1016(e) of the USA PATRIOT Act of 2001 (42
U.S.C. 5195c(e))) have adopted a voluntary, industry-led
set of standards, guidelines, best practices, methodologies,
procedures, and processes to reduce cyber risks to critical
infrastructure in accordance with such section 2(c)(15);
(D) the reasons behind the decisions of sectors of critical infrastructure (as defined in subparagraph (C)) to adopt
or to not adopt the voluntary standards described in
subparagraph (C); and
(E) the extent to which such voluntary standards have
proved successful in protecting critical infrastructure from
cyber threats.
(2) REPORTS.—Not later than 1 year after the date of the
enactment of this Act, and every 2 years thereafter for the
following 6 years, the Comptroller General shall submit a
report, which summarizes the findings of the study conducted
under paragraph (1), to the Committee on Commerce, Science,
and Transportation of the Senate and the Committee on
Science, Space, and Technology of the House of Representatives.
15 USC
prec. 7431.
15 USC 7431.
TITLE II—CYBERSECURITY RESEARCH
AND DEVELOPMENT
SEC. 201. FEDERAL CYBERSECURITY RESEARCH AND DEVELOPMENT.
(a) FUNDAMENTAL CYBERSECURITY RESEARCH.—
(1) FEDERAL CYBERSECURITY RESEARCH AND DEVELOPMENT
STRATEGIC PLAN.—The heads of the applicable agencies and
departments, working through the National Science and Technology Council and the Networking and Information Technology
Research and Development Program, shall develop and update
every 4 years a Federal cybersecurity research and development
strategic plan (referred to in this subsection as the ‘‘strategic
plan’’) based on an assessment of cybersecurity risk to guide
the overall direction of Federal cybersecurity and information
assurance research and development for information technology
and networking systems. The heads of the applicable agencies
and departments shall build upon existing programs and plans
to develop the strategic plan to meet objectives in cybersecurity,
such as—
(A) how to design and build complex software-intensive
systems that are secure and reliable when first deployed;
(B) how to test and verify that software and hardware,
whether developed locally or obtained from a third party,
is free of significant known security flaws;
(C) how to test and verify that software and hardware
obtained from a third party correctly implements stated
functionality, and only that functionality;
(D) how to guarantee the privacy of an individual,
including that individual’s identity, information, and lawful
transactions when stored in distributed systems or transmitted over networks;
dkrause on DSKHT7XVN1PROD with PUBLAWS
Deadline.
VerDate Mar 15 2010
07:01 Mar 03, 2015
Jkt 049139
PO 00274
Frm 00004
Fmt 6580
Sfmt 6581
E:\PUBLAW\PUBL274.113
PUBL274