PUBLIC LAW 115–236—AUG. 14, 2018
132 STAT. 2445
dkrause on DSKBC28HB2PROD with PUBLAWS
of the data collected or stored on the information systems
or devices of the implementing small business concern;
(C) include elements, that promote awareness of
simple, basic controls, a workplace cybersecurity culture,
and third-party stakeholder relationships, to assist small
business concerns in mitigating common cybersecurity
risks;
(D) include case studies of practical application;
(E) are technology-neutral and can be implemented
using technologies that are commercial and off-the-shelf;
and
(F) are based on international standards to the extent
possible, and are consistent with the Stevenson-Wydler
Technology Innovation Act of 1980 (15 U.S.C. 3701 et seq.).
(3) NATIONAL CYBERSECURITY AWARENESS AND EDUCATION
PROGRAM.—The Director shall ensure that the resources
disseminated under paragraph (1) are consistent with the
efforts of the Director under section 401 of the Cybersecurity
Enhancement Act of 2014 (15 U.S.C. 7451).
(4) SMALL BUSINESS DEVELOPMENT CENTER CYBER
STRATEGY.—In carrying out paragraph (1), the Director, to the
extent practicable, shall consider any methods included in the
Small Business Development Center Cyber Strategy developed
under section 1841(a)(3)(B) of the National Defense Authorization Act for Fiscal Year 2017 (Public Law 114–328).
(5) VOLUNTARY RESOURCES.—The use of the resources
disseminated under paragraph (1) shall be considered voluntary.
(6) UPDATES.—The Director shall review and, if necessary,
update the resources disseminated under paragraph (1) in
accordance with the requirements under paragraph (2).
(7) PUBLIC AVAILABILITY.—The Director and the head of
each Federal agency that so elects shall make prominently
available on the respective agency’s public Internet website
information about the resources and updates to the resources
disseminated under paragraph (1). The Director and the heads
shall each ensure that the information they respectively make
prominently available is consistent, clear, and concise.
(d) OTHER FEDERAL CYBERSECURITY REQUIREMENTS.—Nothing
in this section may be construed to supersede, alter, or otherwise
affect any cybersecurity requirements applicable to Federal agencies.
VerDate Sep 11 2014
06:22 Jun 26, 2019
Jkt 089139
PO 00236
Frm 00003
Fmt 6580
Sfmt 6581
E:\PUBLAW\PUBL236.115
Review.
Web posting.
PUBL236