PUBLIC LAW 113–274—DEC. 18, 2014 128 STAT. 2985 (3) RETAIN PERCENTAGE.—A qualified institution of higher education may retain a percentage of any repayment the institution collects under this subsection to defray administrative costs associated with the collection. The Director of the National Science Foundation shall establish a single, fixed percentage that will apply to all eligible entities. (l) EXCEPTIONS.—The Director of the National Science Foundation may provide for the partial or total waiver or suspension of any service or payment obligation by an individual under this section whenever compliance by the individual with the obligation is impossible or would involve extreme hardship to the individual, or if enforcement of such obligation with respect to the individual would be unconscionable. (m) EVALUATION AND REPORT.—The Director of the National Science Foundation shall evaluate and report periodically to Congress on the success of recruiting individuals for scholarships under this section and on hiring and retaining those individuals in the public sector workforce. TITLE IV—CYBERSECURITY AWARENESS AND PREPAREDNESS 15 USC prec. 7451. SEC. 401. NATIONAL CYBERSECURITY AWARENESS AND EDUCATION PROGRAM. (a) NATIONAL CYBERSECURITY AWARENESS AND EDUCATION PROGRAM.—The Director of the National Institute of Standards and dkrause on DSKHT7XVN1PROD with PUBLAWS Applicability. 15 USC 7451. Consultation. Technology (referred to in this section as the ‘‘Director’’), in consultation with appropriate Federal agencies, industry, educational institutions, National Laboratories, the Networking and Information Technology Research and Development program, and other organizations shall continue to coordinate a national cybersecurity awareness and education program, that includes activities such as— (1) the widespread dissemination of cybersecurity technical standards and best practices identified by the Director; (2) efforts to make cybersecurity best practices usable by individuals, small to medium-sized businesses, educational institutions, and State, local, and tribal governments; (3) increasing public awareness of cybersecurity, cyber safety, and cyber ethics; (4) increasing the understanding of State, local, and tribal governments, institutions of higher education, and private sector entities of— (A) the benefits of ensuring effective risk management of information technology versus the costs of failure to do so; and (B) the methods to mitigate and remediate vulnerabilities; (5) supporting formal cybersecurity education programs at all education levels to prepare and improve a skilled cybersecurity and computer science workforce for the private sector and Federal, State, local, and tribal government; and (6) promoting initiatives to evaluate and forecast future cybersecurity workforce needs of the Federal Government and develop strategies for recruitment, training, and retention. VerDate Mar 15 2010 07:01 Mar 03, 2015 Jkt 049139 PO 00274 Frm 00015 Fmt 6580 Sfmt 6581 E:\PUBLAW\PUBL274.113 PUBL274

Select target paragraph3