<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill v2.8 20020720//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>S. 1152</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20110607">June 7, 2011</action-date>
			<action-desc><sponsor name-id="S306">Mr. Menendez</sponsor> introduced
			 the following bill; which was read twice and referred to the
			 <committee-name committee-id="SSCM00">Committee on Commerce, Science, and
			 Transportation</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To advance cybersecurity research, development, and
		  technical standards, and for other purposes.</official-title>
	</form>
	<legis-body id="H7A1096ACC46049FBBAE67A40AF17965D" style="OLC">
		<section id="HB3A7D4DCC5C446E1A5B135F29AEFDA72" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Cybersecurity Enhancement Act of
			 2011</short-title></quote>.</text>
		</section><title id="HB74A413E5C45492B84EAA36978F037DE"><enum>I</enum><header>Research and
			 Development</header>
			<section display-inline="no-display-inline" id="H0AFEF29EE0574E68BBA239F966CF8268"><enum>101.</enum><header>Definitions</header><text display-inline="no-display-inline">In this title:</text>
				<paragraph id="H61AF6D9A9678419FB40AABA996CCE354"><enum>(1)</enum><header>National
			 coordination office</header><text>The term <term>National Coordination
			 Office</term> means the National Coordination Office for the Networking and
			 Information Technology Research and Development program.</text>
				</paragraph><paragraph id="HECB7394E67704CA482DFDBAD24B83D74"><enum>(2)</enum><header>Program</header><text>The
			 term <term>Program</term> means the Networking and Information Technology
			 Research and Development program which has been established under section 101
			 of the High-Performance Computing Act of 1991 (15 U.S.C. 5511).</text>
				</paragraph></section><section id="H7C17DFDB0696482480F44BF66A266190"><enum>102.</enum><header>Findings</header><text display-inline="no-display-inline">Section 2 of the Cyber Security Research and
			 Development Act (15 U.S.C. 7401) is amended—</text>
				<paragraph id="HFF99ED196FA048988D9405C236C44936"><enum>(1)</enum><text>by amending
			 paragraph (1) to read as follows:</text>
					<quoted-block id="HFCB73895470B47B4AC01F61BCA5A2200" style="OLC">
						<paragraph id="H74F66D661B9043EAB882FADE3036909C"><enum>(1)</enum><text display-inline="yes-display-inline">Advancements in information and
				communications technology have resulted in a globally interconnected network of
				government, commercial, scientific, and education infrastructures, including
				critical infrastructures for electric power, natural gas and petroleum
				production and distribution, telecommunications, transportation, water supply,
				banking and finance, and emergency and government
				services.</text>
						</paragraph><after-quoted-block>;</after-quoted-block></quoted-block>
				</paragraph><paragraph id="HCDF697E8E78F47178136E42A5737E7CB"><enum>(2)</enum><text>in paragraph (2),
			 by striking <quote>Exponential increases in interconnectivity have facilitated
			 enhanced communications, economic growth,</quote> and inserting <quote>These
			 advancements have significantly contributed to the growth of the United States
			 economy</quote>;</text>
				</paragraph><paragraph id="HF40DDDE526DC438482A50AE2D62E2AB3"><enum>(3)</enum><text>by amending
			 paragraph (3) to read as follows:</text>
					<quoted-block display-inline="no-display-inline" id="HA227EB2C6DE74FDCA4C78FD45B5CDB3F" style="OLC">
						<paragraph id="H5B108BCEC2DC457D905D8044AD854001"><enum>(3)</enum><text display-inline="yes-display-inline">The Cyberspace Policy Review published by
				the President in May, 2009, concluded that our information technology and
				communications infrastructure is vulnerable and has <quote>suffered intrusions
				that have allowed criminals to steal hundreds of millions of dollars and
				nation-states and other entities to steal intellectual property and sensitive
				military information</quote>.</text>
						</paragraph><after-quoted-block>;
				and</after-quoted-block></quoted-block>
				</paragraph><paragraph id="HD4AEFF92A8DD496B998ACB8DBB4587D1"><enum>(4)</enum><text>by amending
			 paragraph (6) to read as follows:</text>
					<quoted-block display-inline="no-display-inline" id="H872D3BA3182049DA972E50717D78AE44" style="OLC">
						<paragraph id="H6F961760E6964109B17E1E9126CAD0EA"><enum>(6)</enum><text display-inline="yes-display-inline">While African-Americans, Hispanics, and
				Native Americans constitute 33 percent of the college-age population, members
				of these minorities comprise less than 20 percent of bachelor degree recipients
				in the field of computer
				sciences.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></section><section id="HFA0556A63B464AB1B5DBA522F5B8D324"><enum>103.</enum><header>Cybersecurity
			 strategic research and development plan</header>
				<subsection id="HD5305B73F3324821A879E39F5DD1B8C4"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Not later than 12
			 months after the date of enactment of this Act, the agencies identified in
			 subsection 101(a)(3)(B)(i) through (x) of the High-Performance Computing Act of
			 1991 (15 U.S.C. 5511(a)(3)(B)(i) through (x)) or designated under section
			 101(a)(3)(B)(xi) of such Act, working through the National Science and
			 Technology Council and with the assistance of the National Coordination Office,
			 shall transmit to Congress a strategic plan based on an assessment of
			 cybersecurity risk to guide the overall direction of Federal cybersecurity and
			 information assurance research and development for information technology and
			 networking systems. Once every 3 years after the initial strategic plan is
			 transmitted to Congress under this section, such agencies shall prepare and
			 transmit to Congress an update of such plan.</text>
				</subsection><subsection id="H35A7E99772A8486D9E60CC1A9074A14A"><enum>(b)</enum><header>Contents of
			 plan</header><text>The strategic plan required under subsection (a)
			 shall—</text>
					<paragraph id="H98FD8985D47746AB95B254348C5F5AEB"><enum>(1)</enum><text>specify and
			 prioritize near-term, mid-term and long-term research objectives, including
			 objectives associated with the research areas identified in section 4(a)(1) of
			 the Cyber Security Research and Development Act (15 U.S.C. 7403(a)(1)) and how
			 the near-term objectives complement research and development areas in which the
			 private sector is actively engaged;</text>
					</paragraph><paragraph id="HC36A6557F1CD4116967AA20EE6F14DD9"><enum>(2)</enum><text display-inline="yes-display-inline">describe how the Program will focus on
			 innovative, transformational technologies with the potential to enhance the
			 security, reliability, resilience, and trustworthiness of the digital
			 infrastructure;</text>
					</paragraph><paragraph id="HDC27DC65B18F459494D83800D3ACF24F"><enum>(3)</enum><text>describe how the
			 Program will foster the transfer of research and development results into new
			 cybersecurity technologies and applications for the benefit of society and the
			 national interest, including through the dissemination of best practices and
			 other outreach activities;</text>
					</paragraph><paragraph id="HA78861116F7048819C0802641CA5A8BB"><enum>(4)</enum><text>describe how the
			 Program will establish and maintain a national research infrastructure for
			 creating, testing, and evaluating the next generation of secure networking and
			 information technology systems;</text>
					</paragraph><paragraph id="H8896DD4B24254D54A9314ECAC04C8019"><enum>(5)</enum><text display-inline="yes-display-inline">describe how the Program will facilitate
			 access by academic researchers to the infrastructure described in paragraph
			 (4), as well as to relevant data, including event data; and</text>
					</paragraph><paragraph id="H512F4B13510F4132853CA6BE42E41FDF"><enum>(6)</enum><text display-inline="yes-display-inline">describe how the Program will engage
			 females and individuals identified in section 33 or 34 of the Science and
			 Engineering Equal Opportunities Act (42 U.S.C. 1885a or 1885b) to foster a more
			 diverse workforce in this area.</text>
					</paragraph></subsection><subsection id="HB8CFFFCB55224D6993726B30AA1A9BF6"><enum>(c)</enum><header>Development of
			 roadmap</header><text>The agencies described in subsection (a) shall develop
			 and annually update an implementation roadmap for the strategic plan required
			 in this section. Such roadmap shall—</text>
					<paragraph id="H25ACAA6ABE0745D8B12FA39969AE627D"><enum>(1)</enum><text>specify the role
			 of each Federal agency in carrying out or sponsoring research and development
			 to meet the research objectives of the strategic plan, including a description
			 of how progress toward the research objectives will be evaluated;</text>
					</paragraph><paragraph id="HCA11C9B9F118427A94468FB01544CC20"><enum>(2)</enum><text>specify the
			 funding allocated to each major research objective of the strategic plan and
			 the source of funding by agency for the current fiscal year; and</text>
					</paragraph><paragraph id="H36575545C07E47A7A5A78F0F5248F09C"><enum>(3)</enum><text>estimate the
			 funding required for each major research objective of the strategic plan for
			 the following 3 fiscal years.</text>
					</paragraph></subsection><subsection id="H724E227183C84E049CF8DDED6A213F2D"><enum>(d)</enum><header>Recommendations</header><text>In
			 developing and updating the strategic plan under subsection (a), the agencies
			 involved shall solicit recommendations and advice from—</text>
					<paragraph id="HA3DF656BBBB14DD68CD2089045E1621D"><enum>(1)</enum><text>the advisory
			 committee established under section 101(b)(1) of the High-Performance Computing
			 Act of 1991 (15 U.S.C. 5511(b)(1)); and</text>
					</paragraph><paragraph id="H78A0AE566C784CBA9AAB0C55F8126FBF"><enum>(2)</enum><text display-inline="yes-display-inline">a wide range of stakeholders, including
			 industry, academia, including representatives of minority serving institutions
			 and community colleges, and other relevant organizations and
			 institutions.</text>
					</paragraph></subsection><subsection id="H21BDE19160F646C4A7440BE7933A5BF5"><enum>(e)</enum><header>Appending to
			 report</header><text>The implementation roadmap required under subsection (c),
			 and its annual updates, shall be appended to the report required under section
			 101(a)(2)(D) of the High-Performance Computing Act of 1991 (15 U.S.C.
			 5511(a)(2)(D)).</text>
				</subsection></section><section id="H6CB13CD19A384BBC81DBD6C32C77D23A"><enum>104.</enum><header>Social and
			 behavioral research in cybersecurity</header><text display-inline="no-display-inline">Section 4(a)(1) of the Cyber Security
			 Research and Development Act (15 U.S.C. 7403(a)(1)) is amended—</text>
				<paragraph id="HA5C189F74CA445689D51DF340C2F6ED9"><enum>(1)</enum><text>by inserting
			 <quote>and usability</quote> after <quote>to the structure</quote>;</text>
				</paragraph><paragraph id="HBED97EA3A5944261BB731CE973BF58C0"><enum>(2)</enum><text>in subparagraph
			 (H), by striking <quote>and</quote> after the semicolon;</text>
				</paragraph><paragraph id="H3C94B52AEE5A46488A7BABA4FEC8B05F"><enum>(3)</enum><text>in subparagraph
			 (I), by striking the period at the end and inserting <quote>; and</quote>;
			 and</text>
				</paragraph><paragraph id="HC6078E77CF814E1498CB9733BA9B34D5"><enum>(4)</enum><text>by adding at the
			 end the following new subparagraph:</text>
					<quoted-block id="H655A563E42CA4E17B3ED4841787ADD78" style="OLC">
						<subparagraph id="H29E88399A07D4E43B3EF34D12F91A8FA"><enum>(J)</enum><text>social and
				behavioral factors, including human-computer interactions, usability, user
				motivations, and organizational
				cultures.</text>
						</subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></section><section id="HBA312F496BD84682BE9908D9E22FA12F"><enum>105.</enum><header>National
			 Science Foundation cybersecurity research and development programs</header>
				<subsection id="H3FD854C52E524AF3959B0DB198861303"><enum>(a)</enum><header>Computer and
			 network security research areas</header><text display-inline="yes-display-inline">Section 4(a)(1) of the Cyber Security
			 Research and Development Act (15 U.S.C. 7403(a)(1)) is amended—</text>
					<paragraph id="H4AFCC6B88CA740E78F0BE7D0C47D984B"><enum>(1)</enum><text>in subparagraph
			 (A) by inserting <quote>identity management,</quote> after
			 <quote>cryptography,</quote>; and</text>
					</paragraph><paragraph id="H08F901F3CFCD407593ECD12EA2EF5176"><enum>(2)</enum><text>in subparagraph
			 (I), by inserting <quote>, crimes against children, and organized crime</quote>
			 after <quote>intellectual property</quote>.</text>
					</paragraph></subsection><subsection id="HEF213EFB4DD1491BBA81FEDA3AC218CB"><enum>(b)</enum><header>Computer and
			 network security research grants</header><text>Section 4(a)(3) of such Act (15
			 U.S.C. 7403(a)(3)) is amended by striking subparagraphs (A) through (E) and
			 inserting the following new subparagraphs:</text>
					<quoted-block id="H25EAEC3C68F54EB68A9C7EA7F672B520" style="OLC">
						<subparagraph id="H80C033B73A4F4D239DF2D67E0E6DECF4"><enum>(A)</enum><text>$90,000,000 for
				fiscal year 2012;</text>
						</subparagraph><subparagraph id="HD63CA4E32BFF47089136C6FA6FF88F61"><enum>(B)</enum><text>$90,000,000 for
				fiscal year 2013; and</text>
						</subparagraph><subparagraph id="HAD37E50F760E4EC09A8E81D8C222D8F3"><enum>(C)</enum><text>$90,000,000 for
				fiscal year
				2014.</text>
						</subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="H3278731E27D643BB88C0B1BA046C73D4"><enum>(c)</enum><header>Computer and
			 network security research centers</header><text>Section 4(b) of such Act (15
			 U.S.C. 7403(b)) is amended—</text>
					<paragraph id="H53B571C2B89342848808D02B729EEA21"><enum>(1)</enum><text>in paragraph
			 (4)—</text>
						<subparagraph id="HDB551A07AE69424D85CFBAE9E604FE5B"><enum>(A)</enum><text>in subparagraph
			 (C), by striking <quote>and</quote> after the semicolon;</text>
						</subparagraph><subparagraph id="H7485BF0D66A64B1995622C4B72868DDF"><enum>(B)</enum><text display-inline="yes-display-inline">in subparagraph (D), by striking the period
			 and inserting <quote>; and</quote>; and</text>
						</subparagraph><subparagraph id="HB911F692DC1B436DB12E307E01716FE3"><enum>(C)</enum><text>by adding at the
			 end the following new subparagraph:</text>
							<quoted-block display-inline="no-display-inline" id="HE6D41DA89CEA44AA986F30448E454D45" style="OLC">
								<subparagraph id="H0D174CF3C15F4A3A8D66C6B4D1944A71"><enum>(E)</enum><text display-inline="yes-display-inline">how the center will partner with government
				laboratories, for-profit entities, other institutions of higher education, or
				nonprofit research institutions.</text>
								</subparagraph><after-quoted-block>;
				and</after-quoted-block></quoted-block>
						</subparagraph></paragraph><paragraph id="H14A00B09E50448B7B957707011D05694"><enum>(2)</enum><text display-inline="yes-display-inline">in paragraph (7) by striking subparagraphs
			 (A) through (E) and inserting the following new subparagraphs:</text>
						<quoted-block display-inline="no-display-inline" id="HFD00E000BCCE424C85273771A0044A64" style="OLC">
							<subparagraph id="H1FE19936CF4C4D0CBD4494B9C9ACA21D"><enum>(A)</enum><text display-inline="yes-display-inline">$4,500,000 for fiscal year 2012;</text>
							</subparagraph><subparagraph id="HA8E114FDEA574061B556EFD2923E4AD1"><enum>(B)</enum><text>$4,500,000 for
				fiscal year 2013; and</text>
							</subparagraph><subparagraph id="HB1EADE21D66148DEAA6B686476EFDE02"><enum>(C)</enum><text>$4,500,000 for
				fiscal year
				2014.</text>
							</subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection><subsection id="HACFCE43B1DB74751B67D0EDDDC37B90D"><enum>(d)</enum><header>Computer and
			 network security capacity building grants</header><text display-inline="yes-display-inline">Section 5(a)(6) of such Act (15 U.S.C.
			 7404(a)(6)) is amended by striking subparagraphs (A) through (E) and inserting
			 the following new subparagraphs:</text>
					<quoted-block display-inline="no-display-inline" id="H68C4D2698D1A438F911C7C5D55AFDF35" style="OLC">
						<subparagraph id="H3B13AC52DBEE4BC7A80AE1288EFE692F"><enum>(A)</enum><text display-inline="yes-display-inline">$19,000,000 for fiscal year 2012;</text>
						</subparagraph><subparagraph id="H54ABB9E3F9984B98BEB12B26E44673A6"><enum>(B)</enum><text>$19,000,000 for
				fiscal year 2013; and</text>
						</subparagraph><subparagraph id="HC3549FD59CD84D6BBAC466EEDE23A5D3"><enum>(C)</enum><text>$19,000,000 for
				fiscal year
				2014.</text>
						</subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="H12B30353F6104975AFC1ADAC6A1D6A8E"><enum>(e)</enum><header>Scientific and
			 advanced technology act grants</header><text display-inline="yes-display-inline">Section 5(b)(2) of such Act (15 U.S.C.
			 7404(b)(2)) is amended by striking subparagraphs (A) through (E) and inserting
			 the following new subparagraphs:</text>
					<quoted-block display-inline="no-display-inline" id="H6D94991B2CE34996A87D3638D918B0DF" style="OLC">
						<subparagraph id="HCE5AB76260CD4AFB83E8A7E09B1B3A45"><enum>(A)</enum><text display-inline="yes-display-inline">$2,500,000 for fiscal year 2012;</text>
						</subparagraph><subparagraph id="H2DC08A96334A4A01A070CFEDF5AEE1A1"><enum>(B)</enum><text>$2,500,000 for
				fiscal year 2013; and</text>
						</subparagraph><subparagraph id="H6BB9C876E8D845B19295DE239D8BAC24"><enum>(C)</enum><text>$2,500,000 for
				fiscal year
				2014.</text>
						</subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="HB552AABA0A134ECBBBD32E509C1DD9D6"><enum>(f)</enum><header>Graduate
			 traineeships in computer and network security</header><text display-inline="yes-display-inline">Section 5(c)(7) of such Act (15 U.S.C.
			 7404(c)(7)) is amended by striking subparagraphs (A) through (E) and inserting
			 the following new subparagraphs:</text>
					<quoted-block display-inline="no-display-inline" id="HB7C74482D5AE481D9821E5790A91470E" style="OLC">
						<subparagraph id="H0DB92340B1CB4394B2EFC6E1EF1FD949"><enum>(A)</enum><text display-inline="yes-display-inline">$24,000,000 for fiscal year 2012;</text>
						</subparagraph><subparagraph id="H610824165E4947C1B5124D17CB09A2F3"><enum>(B)</enum><text>$24,000,000 for
				fiscal year 2013; and</text>
						</subparagraph><subparagraph id="HCB2DEA3D201E4D129A5C87841929A1DB"><enum>(C)</enum><text>$24,000,000 for
				fiscal year
				2014.</text>
						</subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="H72D04B67F67E40D19E5D1FBD68D750CE"><enum>(g)</enum><header>Cyber security
			 faculty development traineeship program</header><text>Section 5(e) of such Act
			 (15 U.S.C. 7404(e)) is repealed.</text>
				</subsection></section><section id="HC1D8EB65198E4B768B4790367B5C78F5"><enum>106.</enum><header>Federal cyber
			 scholarship for service program</header>
				<subsection id="H9CD73D1AAF3846A3B8D78D88284B339E"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The Director of the
			 National Science Foundation shall continue a Scholarship for Service program
			 under section 5(a) of the Cyber Security Research and Development Act (15
			 U.S.C. 7404(a)) to recruit and train the next generation of Federal
			 cybersecurity professionals and to increase the capacity of the higher
			 education system to produce an information technology workforce with the skills
			 necessary to enhance the security of the Nation’s communications and
			 information infrastructure.</text>
				</subsection><subsection id="H95DB537EEF3F4A93A51032F357B8525A"><enum>(b)</enum><header>Characteristics
			 of program</header><text>The program under this section shall—</text>
					<paragraph id="H069E6C5225E844F092FCFC95CC137960"><enum>(1)</enum><text display-inline="yes-display-inline">provide, through qualified institutions of
			 higher education, scholarships that provide tuition, fees, and a competitive
			 stipend for up to 2 years to students pursing a bachelor’s or master’s degree
			 and up to 3 years to students pursuing a doctoral degree in a cybersecurity
			 field;</text>
					</paragraph><paragraph id="HCEEA581DC4514A53A5A8C2219C68E511"><enum>(2)</enum><text display-inline="yes-display-inline">provide the scholarship recipients with
			 summer internship opportunities or other meaningful temporary appointments in
			 the Federal information technology workforce; and</text>
					</paragraph><paragraph id="H4C313E76BA6A418F853AC53B5CB53A92"><enum>(3)</enum><text>increase the
			 capacity of institutions of higher education throughout all regions of the
			 United States to produce highly qualified cybersecurity professionals, through
			 the award of competitive, merit-reviewed grants that support such activities
			 as—</text>
						<subparagraph id="H29AE9A53D1874920A2A7FDA78782779D"><enum>(A)</enum><text>faculty
			 professional development, including technical, hands-on experiences in the
			 private sector or government, workshops, seminars, conferences, and other
			 professional development opportunities that will result in improved
			 instructional capabilities;</text>
						</subparagraph><subparagraph id="H5955629D8C0847C188AD2B85217DA62F"><enum>(B)</enum><text display-inline="yes-display-inline">institutional partnerships, including
			 minority serving institutions and community colleges; and</text>
						</subparagraph><subparagraph id="H54D641177C244507BE2684B022BD2A4C"><enum>(C)</enum><text>development of
			 cybersecurity-related courses and curricula.</text>
						</subparagraph></paragraph></subsection><subsection id="H946235C48CEE4A57B3363EC7454C460D"><enum>(c)</enum><header>Scholarship
			 requirements</header>
					<paragraph id="H209C97B8FBBF4321A9132E04AF3CC485"><enum>(1)</enum><header>Eligibility</header><text display-inline="yes-display-inline">Scholarships under this section shall be
			 available only to students who—</text>
						<subparagraph id="H40318AF5A32D4EE583AF4C45230C6293"><enum>(A)</enum><text>are citizens or
			 permanent residents of the United States;</text>
						</subparagraph><subparagraph id="HD878991558BC472EA63344C7F777F67A"><enum>(B)</enum><text>are full-time
			 students in an eligible degree program, as determined by the Director, that is
			 focused on computer security or information assurance at an awardee
			 institution; and</text>
						</subparagraph><subparagraph id="H62394BEC89C940A8967F473AE2D24695"><enum>(C)</enum><text display-inline="yes-display-inline">accept the terms of a scholarship pursuant
			 to this section.</text>
						</subparagraph></paragraph><paragraph id="H6AE7D604CD9142DA827B33E0DABEC454"><enum>(2)</enum><header>Selection</header><text display-inline="yes-display-inline">Individuals shall be selected to receive
			 scholarships primarily on the basis of academic merit, with consideration given
			 to financial need, to the goal of promoting the participation of individuals
			 identified in section 33 or 34 of the Science and Engineering Equal
			 Opportunities Act (42 U.S.C. 1885a or 1885b), and to veterans. For purposes of
			 this paragraph, the term <term>veteran</term> means a person who—</text>
						<subparagraph id="H0E371D68C64241F699BEC6D96E8E8D43"><enum>(A)</enum><text display-inline="yes-display-inline">served on active duty (other than active
			 duty for training) in the Armed Forces of the United States for a period of
			 more than 180 consecutive days, and who was discharged or released therefrom
			 under conditions other than dishonorable; or</text>
						</subparagraph><subparagraph id="H78866E2198F44FEB92E0B6329878E6F7"><enum>(B)</enum><text>served on active
			 duty (other than active duty for training) in the Armed Forces of the United
			 States and was discharged or released from such service for a service-connected
			 disability before serving 180 consecutive days.</text>
						</subparagraph><continuation-text continuation-text-level="paragraph">For purposes
			 of subparagraph (B), the term <term>service-connected</term> has the meaning
			 given such term under section 101 of title 38, United States Code.</continuation-text></paragraph><paragraph id="HE4F9508E72024E538DECBA88E0D807D3"><enum>(3)</enum><header>Service
			 obligation</header><text display-inline="yes-display-inline">If an individual
			 receives a scholarship under this section, as a condition of receiving such
			 scholarship, the individual upon completion of their degree must serve as a
			 cybersecurity professional within the Federal workforce for a period of time as
			 provided in paragraph (5). If a scholarship recipient is not offered employment
			 by a Federal agency or a federally funded research and development center, the
			 service requirement can be satisfied at the Director’s discretion by—</text>
						<subparagraph id="H5892B2E0E1554E5EAC1C167398C4C42D"><enum>(A)</enum><text>serving as a
			 cybersecurity professional in a State, local, or tribal government agency;
			 or</text>
						</subparagraph><subparagraph id="H8F21513DA8EF4850B14CF7BEEBE03057"><enum>(B)</enum><text>teaching
			 cybersecurity courses at an institution of higher education.</text>
						</subparagraph></paragraph><paragraph id="H91A335E8FC55427495EFDB0CA5CAB8F3"><enum>(4)</enum><header>Conditions of
			 support</header><text display-inline="yes-display-inline">As a condition of
			 acceptance of a scholarship under this section, a recipient shall agree to
			 provide the awardee institution with annual verifiable documentation of
			 employment and up-to-date contact information.</text>
					</paragraph><paragraph id="HA5340D089D7E42549C017D56D6AD4D9D"><enum>(5)</enum><header>Length of
			 service</header><text display-inline="yes-display-inline">The length of service
			 required in exchange for a scholarship under this subsection shall be 1 year
			 more than the number of years for which the scholarship was received.</text>
					</paragraph></subsection><subsection id="HFCEA06D88525482492DEA9890F742CEC"><enum>(d)</enum><header>Failure To
			 complete service obligation</header>
					<paragraph display-inline="no-display-inline" id="HEA93DE0986B1495289E42FFE6BC47BD3"><enum>(1)</enum><header>General
			 rule</header><text>If an individual who has received a scholarship under this
			 section—</text>
						<subparagraph id="H18BCBBCD1DDD4967875DC3EAE0F3C618"><enum>(A)</enum><text>fails to maintain
			 an acceptable level of academic standing in the educational institution in
			 which the individual is enrolled, as determined by the Director;</text>
						</subparagraph><subparagraph id="HA27E1BF47BEC45ED9A41639EC8B706CE"><enum>(B)</enum><text>is dismissed from
			 such educational institution for disciplinary reasons;</text>
						</subparagraph><subparagraph id="HDE18FB987BDE448C99171B4D3164F79E"><enum>(C)</enum><text>withdraws from the
			 program for which the award was made before the completion of such
			 program;</text>
						</subparagraph><subparagraph id="HB33064BF68CD40EEA214BAF08EB843DE"><enum>(D)</enum><text>declares that the
			 individual does not intend to fulfill the service obligation under this
			 section; or</text>
						</subparagraph><subparagraph id="HADFF2A57274A4A06BA4B029C490120F7"><enum>(E)</enum><text>fails to fulfill
			 the service obligation of the individual under this section,</text>
						</subparagraph><continuation-text continuation-text-level="paragraph">such
			 individual shall be liable to the United States as provided in paragraph
			 (3).</continuation-text></paragraph><paragraph id="H51717EA5DEF7491E97F2CEE834AF0341"><enum>(2)</enum><header>Monitoring
			 compliance</header><text display-inline="yes-display-inline">As a condition of
			 participating in the program, a qualified institution of higher education
			 receiving a grant under this section shall—</text>
						<subparagraph id="HE7A95C8A7E7F4E79BF46A52C34D8E1CA"><enum>(A)</enum><text>enter into an
			 agreement with the Director of the National Science Foundation to monitor the
			 compliance of scholarship recipients with respect to their service obligation;
			 and</text>
						</subparagraph><subparagraph id="HD56975A5C83847F1B02AB8E7358A5BA5"><enum>(B)</enum><text>provide to the
			 Director, on an annual basis, post-award employment information required under
			 subsection (c)(4) for scholarship recipients through the completion of their
			 service obligation.</text>
						</subparagraph></paragraph><paragraph id="H63A79D592589463F93455F2A9C11148B"><enum>(3)</enum><header>Amount of
			 repayment</header>
						<subparagraph id="HF211F4DFCE25417E895D0AD28344985F"><enum>(A)</enum><header>Less than one
			 year of service</header><text>If a circumstance described in paragraph (1)
			 occurs before the completion of 1 year of a service obligation under this
			 section, the total amount of awards received by the individual under this
			 section shall be repaid or such amount shall be treated as a loan to be repaid
			 in accordance with subparagraph (C).</text>
						</subparagraph><subparagraph id="H39657ABF773A4E98972A3BCADBD3368F"><enum>(B)</enum><header>More than one
			 year of service</header><text>If a circumstance described in subparagraph (D)
			 or (E) of paragraph (1) occurs after the completion of 1 year of a service
			 obligation under this section, the total amount of scholarship awards received
			 by the individual under this section, reduced by the ratio of the number of
			 years of service completed divided by the number of years of service required,
			 shall be repaid or such amount shall be treated as a loan to be repaid in
			 accordance with subparagraph (C).</text>
						</subparagraph><subparagraph id="H1790650915FB48818949811E11F264E4"><enum>(C)</enum><header>Repayments</header><text display-inline="yes-display-inline">A loan described in subparagraph (A) or (B)
			 shall be treated as a Federal Direct Unsubsidized Stafford Loan under part D of
			 title IV of the Higher Education Act of 1965 (20 U.S.C. 1087a and following),
			 and shall be subject to repayment, together with interest thereon accruing from
			 the date of the scholarship award, in accordance with terms and conditions
			 specified by the Director (in consultation with the Secretary of Education) in
			 regulations promulgated to carry out this paragraph.</text>
						</subparagraph></paragraph><paragraph id="H0D30F105178E40938B6EFC98EFAAE9A2"><enum>(4)</enum><header>Collection of
			 repayment</header>
						<subparagraph id="H8D61976991904DAE9B25BA00D56B218E"><enum>(A)</enum><header>In
			 general</header><text>In the event that a scholarship recipient is required to
			 repay the scholarship under this subsection, the institution providing the
			 scholarship shall—</text>
							<clause id="H373396E33F824B34940071DC66DC4E12"><enum>(i)</enum><text>be
			 responsible for determining the repayment amounts and for notifying the
			 recipient and the Director of the amount owed; and</text>
							</clause><clause id="HF6498216013443308C66A18BA4F5767F"><enum>(ii)</enum><text>collect such
			 repayment amount within a period of time as determined under the agreement
			 described in paragraph (2), or the repayment amount shall be treated as a loan
			 in accordance with paragraph (3)(C).</text>
							</clause></subparagraph><subparagraph id="HD519F8D13B984AE8A45EA8345DC8A560"><enum>(B)</enum><header>Returned to
			 treasury</header><text>Except as provided in subparagraph (C) of this
			 paragraph, any such repayment shall be returned to the Treasury of the United
			 States.</text>
						</subparagraph><subparagraph id="H39C87FA0402447979D0AB60F1BC2B44E"><enum>(C)</enum><header>Retain
			 percentage</header><text>An institution of higher education may retain a
			 percentage of any repayment the institution collects under this paragraph to
			 defray administrative costs associated with the collection. The Director shall
			 establish a single, fixed percentage that will apply to all eligible
			 entities.</text>
						</subparagraph></paragraph><paragraph id="HB93D9EC2736D4B5C8C723CFA8A5218B0"><enum>(5)</enum><header>Exceptions</header><text>The
			 Director may provide for the partial or total waiver or suspension of any
			 service or payment obligation by an individual under this section whenever
			 compliance by the individual with the obligation is impossible or would involve
			 extreme hardship to the individual, or if enforcement of such obligation with
			 respect to the individual would be unconscionable.</text>
					</paragraph></subsection><subsection id="H6E3D9ABCB271482B877297A78061E48A"><enum>(e)</enum><header>Hiring
			 authority</header><text>For purposes of any law or regulation governing the
			 appointment of individuals in the Federal civil service, upon successful
			 completion of their degree, students receiving a scholarship under this section
			 shall be hired under the authority provided for in section 213.3102(r) of title
			 5, Code of Federal Regulations, and be exempted from competitive service. Upon
			 fulfillment of the service term, such individuals shall be converted to a
			 competitive service position without competition if the individual meets the
			 requirements for that position.</text>
				</subsection></section><section id="H8C156764D5484FEDABBE1F103C69B633"><enum>107.</enum><header>Cybersecurity
			 workforce assessment</header><text display-inline="no-display-inline">Not later
			 than 180 days after the date of enactment of this Act the President shall
			 transmit to the Congress a report addressing the cybersecurity workforce needs
			 of the Federal Government. The report shall include—</text>
				<paragraph id="HAAA744EDCF7547FE88492BD13F5A67C1"><enum>(1)</enum><text display-inline="yes-display-inline">an examination of the current state of and
			 the projected needs of the Federal cybersecurity workforce, including a
			 comparison of the different agencies and departments, and an analysis of the
			 capacity of such agencies and departments to meet those needs;</text>
				</paragraph><paragraph id="H824A68972B3D427BB83224150DC67443"><enum>(2)</enum><text display-inline="yes-display-inline">an analysis of the sources and availability
			 of cybersecurity talent, a comparison of the skills and expertise sought by the
			 Federal Government and the private sector, an examination of the current and
			 future capacity of United States institutions of higher education, including
			 community colleges, to provide cybersecurity professionals with those skills
			 sought by the Federal Government and the private sector, and a description of
			 how successful programs are engaging the talents of females and individuals
			 identified in section 33 or 34 of the Science and Engineering Equal
			 Opportunities Act (42 U.S.C. 1885a or 1885b);</text>
				</paragraph><paragraph id="HAAB29EDA72E1478EB8D940DBFA5C5FFC"><enum>(3)</enum><text>an examination of
			 the effectiveness of the National Centers of Academic Excellence in Information
			 Assurance Education, the Centers of Academic Excellence in Research, and the
			 Federal Cyber Scholarship for Service programs in promoting higher education
			 and research in cybersecurity and information assurance and in producing a
			 growing number of professionals with the necessary cybersecurity and
			 information assurance expertise;</text>
				</paragraph><paragraph id="H0D194FB0511E437DA084180386949B8D"><enum>(4)</enum><text display-inline="yes-display-inline">an analysis of any barriers to the Federal
			 Government recruiting and hiring cybersecurity talent, including barriers
			 relating to compensation, the hiring process, job classification, and hiring
			 flexibilities; and</text>
				</paragraph><paragraph id="H24E29557CAD647E0BFA28389108AB8FC"><enum>(5)</enum><text display-inline="yes-display-inline">recommendations for Federal policies to
			 ensure an adequate, well-trained Federal cybersecurity workforce.</text>
				</paragraph></section><section id="H1307549BBAB64A5C921BF87F38BD3E3F"><enum>108.</enum><header>Cybersecurity
			 university-industry task force</header>
				<subsection id="HA3A39A2742064853A2C806BC400390C0"><enum>(a)</enum><header>Establishment of
			 university-Industry task force</header><text>Not later than 180 days after the
			 date of enactment of this Act, the Director of the Office of Science and
			 Technology Policy shall convene a task force to explore mechanisms for carrying
			 out collaborative research and development activities for cybersecurity through
			 a consortium or other appropriate entity with participants from institutions of
			 higher education and industry.</text>
				</subsection><subsection id="H60B2E9827F6147C7923FB83441504C48"><enum>(b)</enum><header>Functions</header><text>The
			 task force shall—</text>
					<paragraph id="H1DEC485B8DC54A228D367E9EA8636DC7"><enum>(1)</enum><text>develop options
			 for a collaborative model and an organizational structure for such entity under
			 which the joint research and development activities could be planned, managed,
			 and conducted effectively, including mechanisms for the allocation of resources
			 among the participants in such entity for support of such activities;</text>
					</paragraph><paragraph id="H24AC36BE77B147858D24D7DC7924C155"><enum>(2)</enum><text display-inline="yes-display-inline">propose a process for developing a research
			 and development agenda for such entity, including guidelines to ensure an
			 appropriate scope of work focused on nationally significant challenges and
			 requiring collaboration;</text>
					</paragraph><paragraph id="H72F5C1D8D29042DEBB033B8445825C0A"><enum>(3)</enum><text>define the roles
			 and responsibilities for the participants from institutions of higher education
			 and industry in such entity;</text>
					</paragraph><paragraph id="H1B3E51C83A7741B6925505EB91CB5CB1"><enum>(4)</enum><text display-inline="yes-display-inline">propose guidelines for assigning
			 intellectual property rights, for the transfer of research and development
			 results to the private sector; and</text>
					</paragraph><paragraph id="H4C0D80F350564ECE86D3BCDD63CAB6E9"><enum>(5)</enum><text>make
			 recommendations for how such entity could be funded from Federal, State, and
			 nongovernmental sources.</text>
					</paragraph></subsection><subsection id="H153DFA34CFED49E7BBDC41000B6A9856"><enum>(c)</enum><header>Composition</header><text display-inline="yes-display-inline">In establishing the task force under
			 subsection (a), the Director of the Office of Science and Technology Policy
			 shall appoint an equal number of individuals from institutions of higher
			 education, including minority-serving institutions and community colleges, and
			 from industry with knowledge and expertise in cybersecurity.</text>
				</subsection><subsection id="HF24E077564A84ABE838623C53A4D3CD3"><enum>(d)</enum><header>Report</header><text display-inline="yes-display-inline">Not later than 12 months after the date of
			 enactment of this Act, the Director of the Office of Science and Technology
			 Policy shall transmit to the Congress a report describing the findings and
			 recommendations of the task force.</text>
				</subsection></section><section id="HFAD128DC343C430CA04C5376C14AFD1E"><enum>109.</enum><header>Cybersecurity
			 checklist development and dissemination</header><text display-inline="no-display-inline">Section 8(c) of the Cyber Security Research
			 and Development Act (15 U.S.C. 7406(c)) is amended to read as follows:</text>
				<quoted-block id="H9F220F02A4A346CF95B1169353B6982A" style="OLC">
					<subsection id="HD7F58A8D4F6641D09480EA991D57006B"><enum>(c)</enum><header>Checklists for
				government systems</header>
						<paragraph id="H5360BB7DEE504949B6554DB367AA0256"><enum>(1)</enum><header>In
				general</header><text>The Director of the National Institute of Standards and
				Technology shall develop or identify and revise or adapt as necessary,
				checklists, configuration profiles, and deployment recommendations for products
				and protocols that minimize the security risks associated with each computer
				hardware or software system that is, or is likely to become, widely used within
				the Federal Government.</text>
						</paragraph><paragraph id="HE2763F9F6E3D4C0FBBFBB2EDE38F2133"><enum>(2)</enum><header>Priorities for
				development</header><text>The Director of the National Institute of Standards
				and Technology shall establish priorities for the development of checklists
				under this subsection. Such priorities may be based on the security risks
				associated with the use of each system, the number of agencies that use a
				particular system, the usefulness of the checklist to Federal agencies that are
				users or potential users of the system, or such other factors as the Director
				determines to be appropriate.</text>
						</paragraph><paragraph id="H20649307056447CAA2C5CC8B06DE002B"><enum>(3)</enum><header>Excluded
				systems</header><text>The Director of the National Institute of Standards and
				Technology may exclude from the requirements of paragraph (1) any computer
				hardware or software system for which the Director determines that the
				development of a checklist is inappropriate because of the infrequency of use
				of the system, the obsolescence of the system, or the inutility or
				impracticability of developing a checklist for the system.</text>
						</paragraph><paragraph id="H30558588C89F40BB9E9A409DE25B1F86"><enum>(4)</enum><header>Automation
				specifications</header><text>The Director of the National Institute of
				Standards and Technology shall develop automated security specifications (such
				as the Security Content Automation Protocol) with respect to checklist content
				and associated security related data.</text>
						</paragraph><paragraph id="H96DC9B241E3242CA97E24C68C9D29901"><enum>(5)</enum><header>Dissemination of
				checklists</header><text display-inline="yes-display-inline">The Director of
				the National Institute of Standards and Technology shall ensure that Federal
				agencies are informed of the availability of any product developed or
				identified under the National Checklist Program for any information system,
				including the Security Content Automation Protocol and other automated security
				specifications.</text>
						</paragraph><paragraph id="H0A389DD03DF94864BE547CA7DCC86D31"><enum>(6)</enum><header>Agency use
				requirements</header><text display-inline="yes-display-inline">The development
				of a checklist under paragraph (1) for a computer hardware or software system
				does not—</text>
							<subparagraph id="H6024E587102A4E929FA801BBDAA1807C"><enum>(A)</enum><text>require any
				Federal agency to select the specific settings or options recommended by the
				checklist for the system;</text>
							</subparagraph><subparagraph id="H10AFEE9E0E61458789D5F22281031A60"><enum>(B)</enum><text>establish
				conditions or prerequisites for Federal agency procurement or deployment of any
				such system;</text>
							</subparagraph><subparagraph id="H345B7A6F2AA8432BB7474531B6DA61EC"><enum>(C)</enum><text>imply an
				endorsement of any such system by the Director of the National Institute of
				Standards and Technology; or</text>
							</subparagraph><subparagraph id="H5DD6A04807A248CCAF6DA5CDB3490126"><enum>(D)</enum><text>preclude any
				Federal agency from procuring or deploying other computer hardware or software
				systems for which no such checklist has been developed or identified under
				paragraph
				(1).</text>
							</subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
			</section><section id="HED7F61661170466BB514D571FE9D59DF"><enum>110.</enum><header>National
			 Institute of Standards and Technology cybersecurity research and
			 development</header><text display-inline="no-display-inline">Section 20 of the
			 National Institute of Standards and Technology Act (15 U.S.C. 278g–3) is
			 amended by redesignating subsection (e) as subsection (f), and by inserting
			 after subsection (d) the following:</text>
				<quoted-block id="HE490D604DB8D45159B4B0B23C2E03861">
					<subsection id="H14506D6BE4E7426DAEA86A8E7E01B429"><enum>(e)</enum><header>Intramural
				security research</header><text>As part of the research activities conducted in
				accordance with subsection (d)(3), the Institute shall—</text>
						<paragraph id="HDDAB00F040A140BCACDD1B09F5322AA4"><enum>(1)</enum><text>conduct a research
				program to develop a unifying and standardized identity, privilege, and access
				control management framework for the execution of a wide variety of resource
				protection policies and that is amenable to implementation within a wide
				variety of existing and emerging computing environments;</text>
						</paragraph><paragraph id="H69EDFF320DB548BF92A1059144605F7E"><enum>(2)</enum><text>carry out research
				associated with improving the security of information systems and
				networks;</text>
						</paragraph><paragraph id="HA195D53523DB44559001A78C90C778AD"><enum>(3)</enum><text>carry out research
				associated with improving the testing, measurement, usability, and assurance of
				information systems and networks; and</text>
						</paragraph><paragraph id="H43DEB6957E554E3080F20F2E9DA11069"><enum>(4)</enum><text>carry out research
				associated with improving security of industrial control
				systems.</text>
						</paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
			</section></title><title id="HEFEEA1CF16184A25B87C30150936A6F7"><enum>II</enum><header>Advancement of
			 Cybersecurity Technical Standards</header>
			<section id="HB24E3AFBB36F4B9D85D57393F77AEB5B"><enum>201.</enum><header>Definitions</header><text display-inline="no-display-inline">In this title:</text>
				<paragraph id="HCDA064E799B04065A5864FEAD3515847"><enum>(1)</enum><header>Director</header><text>The
			 term <term>Director</term> means the Director of the National Institute of
			 Standards and Technology.</text>
				</paragraph><paragraph id="HF7EA62382FC444D5A579F35D79016A57"><enum>(2)</enum><header>Institute</header><text display-inline="yes-display-inline">The term <term>Institute</term> means the
			 National Institute of Standards and Technology.</text>
				</paragraph></section><section id="H8CA197D3F65F493C85117CCD28E67FD8"><enum>202.</enum><header>International
			 cybersecurity technical standards</header><text display-inline="no-display-inline">The Director, in coordination with
			 appropriate Federal authorities, shall—</text>
				<paragraph id="HDB6623E960D744E4865A7D4995FC921D"><enum>(1)</enum><text display-inline="yes-display-inline">ensure coordination of United States
			 Government representation in the international development of technical
			 standards related to cybersecurity; and</text>
				</paragraph><paragraph id="HCB119EABBB3B45B990B540E4A86CB1E1"><enum>(2)</enum><text display-inline="yes-display-inline">not later than 1 year after the date of
			 enactment of this Act, develop and transmit to the Congress a proactive plan to
			 engage international standards bodies with respect to the development of
			 technical standards related to cybersecurity.</text>
				</paragraph></section><section id="H661E0743EFD54129B9FB2E431AB71F15"><enum>203.</enum><header>Promoting
			 cybersecurity awareness and education</header>
				<subsection id="H1C211ED73C1A45C4BCC727BBCF1F83A3"><enum>(a)</enum><header>Program</header><text display-inline="yes-display-inline">The Director, in collaboration with
			 relevant Federal agencies, industry, educational institutions, and other
			 organizations, shall maintain a cybersecurity awareness and education program
			 to increase public awareness of cybersecurity risks, consequences, and best
			 practices through—</text>
					<paragraph id="HCD310D7AB8DD41559107863987B0A85C"><enum>(1)</enum><text>the widespread
			 dissemination of cybersecurity technical standards and best practices
			 identified by the Institute; and</text>
					</paragraph><paragraph id="H47235F5FD74143F1B8C449F8344D5923"><enum>(2)</enum><text display-inline="yes-display-inline">efforts to make cybersecurity technical
			 standards and best practices usable by individuals, small to medium-sized
			 businesses, State, local, and tribal governments, and educational
			 institutions.</text>
					</paragraph></subsection><subsection id="H760DBB53EC77414F9F5861ACCC0C15B3"><enum>(b)</enum><header>Manufacturing
			 extension partnership</header><text display-inline="yes-display-inline">The
			 Director shall, to the extent appropriate, implement subsection (a) through the
			 Manufacturing Extension Partnership program under section 25 of the National
			 Institute of Standards and Technology Act (15 U.S.C. 278k).</text>
				</subsection><subsection id="H8B1604247A7C437FB9B3F82F216EFAE4"><enum>(c)</enum><header>Report to
			 Congress</header><text>Not later than 90 days after the date of enactment of
			 this Act, the Director shall transmit to the Congress a report containing a
			 strategy for implementation of this section.</text>
				</subsection></section><section id="H3EA92A89609F43919AE5B5A0E241DB4A"><enum>204.</enum><header>Identity
			 management research and development</header><text display-inline="no-display-inline">The Director shall continue a program to
			 support the development of technical standards, metrology, testbeds, and
			 conformance criteria, taking into account appropriate user concerns, to—</text>
				<paragraph id="H66D67C98C50F43E2A046901EB43C9990"><enum>(1)</enum><text>improve
			 interoperability among identity management technologies;</text>
				</paragraph><paragraph id="HEC336D0F033D4589B94F2FC986A4E64A"><enum>(2)</enum><text>strengthen
			 authentication methods of identity management systems;</text>
				</paragraph><paragraph id="H2597C48FDE914F048E4BA3DF7231C10B"><enum>(3)</enum><text>improve privacy
			 protection in identity management systems, including health information
			 technology systems, through authentication and security protocols; and</text>
				</paragraph><paragraph id="HD427823A91DE4D33B22F16C87D39B764"><enum>(4)</enum><text>improve the
			 usability of identity management systems.</text>
				</paragraph></section></title></legis-body>
</bill>
