128 STAT. 2978 PUBLIC LAW 113–274—DEC. 18, 2014 (1) the National Science Foundation; (2) the National Institute of Standards and Technology; (3) the Department of Homeland Security; (4) other Federal agencies; (5) other Federal and private research laboratories, research entities, and universities; (6) institutions of higher education; (7) relevant nonprofit organizations; and (8) international partners of the United States. (e) NATIONAL SCIENCE FOUNDATION COMPUTER AND NETWORK SECURITY RESEARCH GRANT AREAS.—Section 4(a)(1) of the Cyber Security Research and Development Act (15 U.S.C. 7403(a)(1)) is amended— (1) in subparagraph (H), by striking ‘‘and’’ at the end; (2) in subparagraph (I), by striking the period at the end and inserting a semicolon; and (3) by adding at the end the following: ‘‘(J) secure fundamental protocols that are integral to inter-network communications and data exchange; ‘‘(K) secure software engineering and software assurance, including— ‘‘(i) programming languages and systems that include fundamental security features; ‘‘(ii) portable or reusable code that remains secure when deployed in various environments; ‘‘(iii) verification and validation technologies to ensure that requirements and specifications have been implemented; and ‘‘(iv) models for comparison and metrics to assure that required standards have been met; ‘‘(L) holistic system security that— ‘‘(i) addresses the building of secure systems from trusted and untrusted components; ‘‘(ii) proactively reduces vulnerabilities; ‘‘(iii) addresses insider threats; and ‘‘(iv) supports privacy in conjunction with improved security; ‘‘(M) monitoring and detection; ‘‘(N) mitigation and rapid recovery methods; ‘‘(O) security of wireless networks and mobile devices; and ‘‘(P) security of cloud infrastructure and services.’’. (f) RESEARCH ON THE SCIENCE OF CYBERSECURITY.—The head of each agency and department identified under section 101(a)(3)(B) of the High-Performance Computing Act of 1991 (15 U.S.C. 5511(a)(3)(B)), through existing programs and activities, shall support research that will lead to the development of a scientific foundation for the field of cybersecurity, including research that increases understanding of the underlying principles of securing complex networked systems, enables repeatable experimentation, and creates quantifiable security metrics. dkrause on DSKHT7XVN1PROD with PUBLAWS SEC. 202. COMPUTER AND NETWORK SECURITY RESEARCH CENTERS. Section 4(b) of the Cyber Security Research and Development Act (15 U.S.C. 7403(b)) is amended— (1) in paragraph (3), by striking ‘‘the research areas’’ and inserting the following: ‘‘improving the security and resiliency VerDate Mar 15 2010 07:01 Mar 03, 2015 Jkt 049139 PO 00274 Frm 00008 Fmt 6580 Sfmt 6581 E:\PUBLAW\PUBL274.113 PUBL274

Select target paragraph3