128 STAT. 2980
PUBLIC LAW 113–274—DEC. 18, 2014
‘‘(B) the number of agencies that use a particular
system or security tool;
‘‘(C) the usefulness of the standards, reference materials, or checklists to Federal agencies that are users or
potential users of the system;
‘‘(D) the effectiveness of the associated standard, reference material, or checklist in creating or enabling continuous monitoring of information security; or
‘‘(E) such other factors as the Director of the National
Institute of Standards and Technology determines to be
appropriate.
‘‘(3) EXCLUDED SYSTEMS.—The Director of the National
Institute of Standards and Technology may exclude from the
application of paragraph (1) any information technology hardware or software system or security tool for which such Director
determines that the development of a standard, reference material, or checklist is inappropriate because of the infrequency
of use of the system, the obsolescence of the system, or the
lack of utility or impracticability of developing a standard,
reference material, or checklist for the system.
‘‘(4) DISSEMINATION OF STANDARDS AND RELATED MATERIALS.—The Director of the National Institute of Standards
and Technology shall ensure that Federal agencies are informed
of the availability of any standard, reference material, checklist,
or other item developed under this subsection.
‘‘(5) AGENCY USE REQUIREMENTS.—The development of
standards, reference materials, and checklists under paragraph
(1) for an information technology hardware or software system
or tool does not—
‘‘(A) require any Federal agency to select the specific
settings or options recommended by the standard, reference
material, or checklist for the system;
‘‘(B) establish conditions or prerequisites for Federal
agency procurement or deployment of any such system;
‘‘(C) imply an endorsement of any such system by
the Director of the National Institute of Standards and
Technology; or
‘‘(D) preclude any Federal agency from procuring or
deploying other information technology hardware or software systems for which no such standard, reference material, or checklist has been developed or identified under
paragraph (1).’’.
dkrause on DSKHT7XVN1PROD with PUBLAWS
SEC. 204. NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY
CYBERSECURITY RESEARCH AND DEVELOPMENT.
Section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) is amended—
(1) by redesignating subsection (e) as subsection (f); and
(2) by inserting after subsection (d) the following:
‘‘(e) INTRAMURAL SECURITY RESEARCH.—As part of the research
activities conducted in accordance with subsection (d)(3), the
Institute shall, to the extent practicable and appropriate—
‘‘(1) conduct a research program to develop a unifying and
standardized identity, privilege, and access control management
framework for the execution of a wide variety of resource protection policies and that is amenable to implementation within
VerDate Mar 15 2010
07:01 Mar 03, 2015
Jkt 049139
PO 00274
Frm 00010
Fmt 6580
Sfmt 6581
E:\PUBLAW\PUBL274.113
PUBL274