PUBLIC LAW 113–274—DEC. 18, 2014
128 STAT. 2979
of information technology, reducing cyber vulnerabilities, and
anticipating and mitigating consequences of cyber attacks on
critical infrastructure, by conducting research in the areas’’;
(2) by striking ‘‘the center’’ in paragraph (4)(D) and
inserting ‘‘the Center’’; and
(3) in paragraph (5)—
(A) by striking ‘‘and’’ at the end of subparagraph (C);
(B) by striking the period at the end of subparagraph
(D) and inserting a semicolon; and
(C) by adding at the end the following:
‘‘(E) the demonstrated capability of the applicant to
conduct high performance computation integral to complex
computer and network security research, through on-site
or off-site computing;
‘‘(F) the applicant’s affiliation with private sector entities involved with industrial research described in subsection (a)(1);
‘‘(G) the capability of the applicant to conduct research
in a secure environment;
‘���(H) the applicant’s affiliation with existing research
programs of the Federal Government;
‘‘(I) the applicant’s experience managing public-private
partnerships to transition new technologies into a commercial setting or the government user community;
‘‘(J) the capability of the applicant to conduct interdisciplinary cybersecurity research, basic and applied, such
as in law, economics, or behavioral sciences; and
‘‘(K) the capability of the applicant to conduct research
in areas such as systems security, wireless security, networking and protocols, formal methods and high-performance computing, nanotechnology, or industrial control systems.’’.
dkrause on DSKHT7XVN1PROD with PUBLAWS
SEC. 203. CYBERSECURITY AUTOMATION AND CHECKLISTS FOR
GOVERNMENT SYSTEMS.
Section 8(c) of the Cyber Security Research and Development
Act (15 U.S.C. 7406(c)) is amended to read as follows:
‘‘(c) SECURITY AUTOMATION AND CHECKLISTS FOR GOVERNMENT
SYSTEMS.—
‘‘(1) IN GENERAL.—The Director of the National Institute
of Standards and Technology shall, as necessary, develop and
revise security automation standards, associated reference
materials (including protocols), and checklists providing settings and option selections that minimize the security risks
associated with each information technology hardware or software system and security tool that is, or is likely to become,
widely used within the Federal Government, thereby enabling
standardized and interoperable technologies, architectures, and
frameworks for continuous monitoring of information security
within the Federal Government.
‘‘(2) PRIORITIES FOR DEVELOPMENT.—The Director of the
National Institute of Standards and Technology shall establish
priorities for the development of standards, reference materials,
and checklists under this subsection on the basis of—
‘‘(A) the security risks associated with the use of the
system;
VerDate Mar 15 2010
07:01 Mar 03, 2015
Jkt 049139
PO 00274
Frm 00009
Fmt 6580
Sfmt 6581
E:\PUBLAW\PUBL274.113
PUBL274