PUBLIC LAW 113–274—DEC. 18, 2014 128 STAT. 2979 of information technology, reducing cyber vulnerabilities, and anticipating and mitigating consequences of cyber attacks on critical infrastructure, by conducting research in the areas’’; (2) by striking ‘‘the center’’ in paragraph (4)(D) and inserting ‘‘the Center’’; and (3) in paragraph (5)— (A) by striking ‘‘and’’ at the end of subparagraph (C); (B) by striking the period at the end of subparagraph (D) and inserting a semicolon; and (C) by adding at the end the following: ‘‘(E) the demonstrated capability of the applicant to conduct high performance computation integral to complex computer and network security research, through on-site or off-site computing; ‘‘(F) the applicant’s affiliation with private sector entities involved with industrial research described in subsection (a)(1); ‘‘(G) the capability of the applicant to conduct research in a secure environment; ‘���(H) the applicant’s affiliation with existing research programs of the Federal Government; ‘‘(I) the applicant’s experience managing public-private partnerships to transition new technologies into a commercial setting or the government user community; ‘‘(J) the capability of the applicant to conduct interdisciplinary cybersecurity research, basic and applied, such as in law, economics, or behavioral sciences; and ‘‘(K) the capability of the applicant to conduct research in areas such as systems security, wireless security, networking and protocols, formal methods and high-performance computing, nanotechnology, or industrial control systems.’’. dkrause on DSKHT7XVN1PROD with PUBLAWS SEC. 203. CYBERSECURITY AUTOMATION AND CHECKLISTS FOR GOVERNMENT SYSTEMS. Section 8(c) of the Cyber Security Research and Development Act (15 U.S.C. 7406(c)) is amended to read as follows: ‘‘(c) SECURITY AUTOMATION AND CHECKLISTS FOR GOVERNMENT SYSTEMS.— ‘‘(1) IN GENERAL.—The Director of the National Institute of Standards and Technology shall, as necessary, develop and revise security automation standards, associated reference materials (including protocols), and checklists providing settings and option selections that minimize the security risks associated with each information technology hardware or software system and security tool that is, or is likely to become, widely used within the Federal Government, thereby enabling standardized and interoperable technologies, architectures, and frameworks for continuous monitoring of information security within the Federal Government. ‘‘(2) PRIORITIES FOR DEVELOPMENT.—The Director of the National Institute of Standards and Technology shall establish priorities for the development of standards, reference materials, and checklists under this subsection on the basis of— ‘‘(A) the security risks associated with the use of the system; VerDate Mar 15 2010 07:01 Mar 03, 2015 Jkt 049139 PO 00274 Frm 00009 Fmt 6580 Sfmt 6581 E:\PUBLAW\PUBL274.113 PUBL274

Select target paragraph3