Pub. L. 107-347, tit. III, sec. 303

NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY.

EnactedYear: 2002Length: 1,002 wordsOfficial source
SEC. 303. NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. Section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3), is amended by striking the text and inserting the following: “(a) In General.—The Institute shall— “(1) have the mission of developing standards, guidelines, and associated methods and techniques for information systems; “(2) develop standards and guidelines, including minimum requirements, for information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency, other than national security systems (as defined in section 3542(b)(2) of title 44, United States Code); and “(3) develop standards and guidelines, including minimum requirements, for providing adequate information security for all agency operations and assets, but such standards and guidelines shall not apply to national security systems. “(b) Minimum Requirements for Standards and Guidelines.—The standards and guidelines required by subsection (a) shall include, at a minimum— “(1)(A) standards to be used by all agencies to categorize all information and information systems collected or maintained by or on behalf of each agency based on the objectives of providing appropriate levels of information security according to a range of risk levels; “(B) guidelines recommending the types of information and information systems to be included in each such category; and116 STAT. 2958 “(C) minimum information security requirements for information and information systems in each such category; “(2) a definition of and guidelines concerning detection and handling of information security incidents; and “(3) guidelines developed in conjunction with the Department of Defense, including the National Security Agency, for identifying an information system as a national security system consistent with applicable requirements for national security systems, issued in accordance with law and as directed by the President. “(c) Development of Standards and Guidelines.—In developing standards and guidelines required by subsections (a) and (b), the Institute shall— “(1) consult with other agencies and offices and the private sector (including the Director of the Office of Management and Budget, the Departments of Defense and Energy, the National Security Agency, the General Accounting Office, and the Secretary of Homeland Security) to assure— “(A) use of appropriate information security policies, procedures, and techniques, in order to improve information security and avoid unnecessary and costly duplication of effort; and “(B) that such standards and guidelines are complementary with standards and guidelines employed for the protection of national security systems and information contained in such systems; “(2) provide the public with an opportunity to comment on proposed standards and guidelines; “(3) submit to the Secretary of Commerce for promulgation under section 11331 of title 40, United States Code— “(A) standards, as required under subsection (b)(1)(A), no later than 12 months after the date of the enactment of this section; and “(B) minimum information security requirements for each category, as required under subsection (b)(1)(C), no later than 36 months after the date of the enactment of this section; “(4) issue guidelines as required under subsection (b)(1)(B), no later than 18 months after the date of the enactment of this section; “(5) to the maximum extent practicable, ensure that such standards and guidelines do not require the use or procurement of specific products, including any specific hardware or software; “(6) to the maximum extent practicable, ensure that such standards and guidelines provide for sufficient flexibility to permit alternative solutions to provide equivalent levels of protection for identified information security risks; and “(7) to the maximum extent practicable, use flexible, performance-based standards and guidelines that permit the use of off-the-shelf commercially developed information security products. “(d) Information Security Functions.—The Institute shall— “(1) submit standards developed pursuant to subsection (a), along with recommendations as to the extent to which these should be made compulsory and binding, to the Secretary of Commerce for promulgation under section 11331 of title 40, United States Code;116 STAT. 2959 “(2) provide technical assistance to agencies, upon request, regarding— “(A) compliance with the standards and guidelines developed under subsection (a); “(B) detecting and handling information security incidents; and “(C) information security policies, procedures, and practices; “(3) conduct research, as needed, to determine the nature and extent of information security vulnerabilities and techniques for providing cost-effective information security; “(4) develop and periodically revise performance indicators and measures for agency information security policies and practices; “(5) evaluate private sector information security policies and practices and commercially available information technologies to assess potential application by agencies to strengthen information security; “(6) assist the private sector, upon request, in using and applying the results of activities under this section; “(7) evaluate security policies and practices developed for national security systems to assess potential application by agencies to strengthen information security; “(8) periodically assess the effectiveness of standards and guidelines developed under this section and undertake revisions as appropriate; “(9) solicit and consider the recommendations of the Information Security and Privacy Advisory Board, established by section 21, regarding standards and guidelines developed under subsection (a) and submit such recommendations to the Secretary of Commerce with such standards submitted to the Secretary; and “(10) prepare an annual public report on activities undertaken in the previous year, and planned for the coming year, to carry out responsibilities under this section. “(e) Definitions.—As used in this section— “(1) the term ‘agency’ has the same meaning as provided in section 3502(1) of title 44, United States Code; “(2) the term ‘information security’ has the same meaning as provided in section 3542(b)(1) of such title; “(3) the term ‘information system’ has the same meaning as provided in section 3502(8) of such title; “(4) the term ‘information technology’ has the same meaning as provided in section 11101 of title 40, United States Code; and “(5) the term ‘national security system’ has the same meaning as provided in section 3542(b)(2) of title 44, United States Code. “(f) Authorization of Appropriations.—There are authorized to be appropriated to the Secretary of Commerce $20,000,000 for each of fiscal years 2003, 2004, 2005, 2006, and 2007 to enable the National Institute of Standards and Technology to carry out the provisions of this section.”.
Pub. L. 107-347, tit. III, sec. 303: NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. | Justis AI