The Director of the National Institute of Standards and Technology (referred to in this section as the "Director"), in consultation with appropriate Federal agencies, industry, educational institutions, National Laboratories, the Networking and Information Technology Research and Development program, and other organizations shall continue to coordinate a national cybersecurity awareness and education program, that includes activities such as-
In carrying out the authority described in subsection (a), the Director, in consultation with appropriate Federal agencies, shall leverage existing programs designed to inform the public of safety and security of products or services, including self-certifications and independently verified assessments regarding the quantification and valuation of information security risk.
The Director, in cooperation with relevant Federal agencies and other stakeholders, shall build upon programs and plans in effect as of December 18, 2014, to develop and implement a strategic plan to guide Federal programs and activities in support of the national cybersecurity awareness and education program under subsection (a).
The strategic plan developed and implemented under paragraph (1) shall include an indication of how the Director will carry out this section.
Not later than 1 year after December 18, 2014, and every 5 years thereafter, the Director shall transmit the strategic plan under subsection (c) to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Science, Space, and Technology of the House of Representatives.
In carrying out subsection (a), the Director of the Office of Management and Budget may seek input from the Director of the National Institute of Standards and Technology, in coordination with the Department of Homeland Security, the Department of Defense, the Office of Personnel Management, and such agencies as the Director of the National Institute of Standards and Technology considers relevant, to develop quantifiable metrics for evaluating Federally funded cybersecurity workforce programs and initiatives based on the outcomes of such programs and initiatives.
Pursuant to section 272(b)(4) of this title, the Director shall establish cooperative agreements between the National Initiative for Cybersecurity Education (NICE) of the Institute and regional alliances or partnerships for cybersecurity education and workforce.
The cooperative agreements established under paragraph (1) shall advance the goals of the National Initiative for Cybersecurity Education Cybersecurity Workforce Framework (NIST Special Publication 800-181), or successor framework, by facilitating local and regional partnerships to-
The Director may award financial assistance to a regional alliance or partnership with whom the Director enters into a cooperative agreement under paragraph (1) in order to assist the regional alliance or partnership in carrying out the terms of the cooperative agreement.
The aggregate amount of financial assistance awarded under subparagraph (A) per cooperative agreement shall not exceed $200,000.
The Director may not award financial assistance to a regional alliance or partnership under subparagraph (A) unless the regional alliance or partnership agrees that, with respect to the costs to be incurred by the regional alliance or partnership in carrying out the cooperative agreement for which the assistance was awarded, the regional alliance or partnership will make available (directly or through donations from public or private entities) non-Federal contributions, including in-kind contributions, in an amount equal to 50 percent of Federal funds provided under the award.
A regional alliance or partnership seeking to enter into a cooperative agreement under paragraph (1) and receive financial assistance under paragraph (3) shall submit to the Director an application therefore at such time, in such manner, and containing such information as the Director may require.
Each application submitted under subparagraph (A) shall include the following:
In awarding financial assistance under paragraph (3)(A), the Director shall give priority consideration to a regional alliance or partnership that includes an institution of higher education that is designated as a National Center of Academic Excellence in Cybersecurity or which received an award under the Federal Cyber Scholarship for Service program located in the State or region of the regional alliance or partnership.
Each cooperative agreement for which financial assistance is awarded under paragraph (3) shall be subject to audit requirements under part 200 of title 2, Code of Federal Regulations (relating to uniform administrative requirements, cost principles, and audit requirements for Federal awards), or successor regulation.
Upon completion of a cooperative agreement under paragraph (1), the regional alliance or partnership that participated in the agreement shall submit to the Director a report on the activities of the regional alliance or partnership under the agreement, which may include training and education outcomes.
Each report submitted under subparagraph (A) by a regional alliance or partnership shall include the following:
15 U.S.C. § 7443
EDITORIAL NOTES
CODIFICATIONSection was classified to section 7451 of this title prior to renumbering by Pub. L. 116-283.
AMENDMENTS2021-Subsec. (a)(6) to (10). Pub. L. 116-283, §9401(a), added pars. (6) to (9) and redesignated former par. (6) as (10). Subsec. (c). Pub. L. 116-283, §9401(b), designated existing provisions as par. (1), inserted heading, and added par. (2).Subsec. (e). Pub. L. 116-283, §9401(e), added subsec. (e).Subsec. (f). Pub. L. 116-283, §9401(f), added subsec. (f).
STATUTORY NOTES AND RELATED SUBSIDIARIES
CYBERSECURITY CAREER PATHWAYS Pub. L. 116-283 title XCIV, §9401(c), Jan. 1, 2021, 134 Stat. 4806, provided that:"(1) IDENTIFICATION OF MULTIPLE CYBERSECURITY CAREER PATHWAYS.-In carrying out subsection (a) of such section [meaning 15 U.S.C. 7451(a), now 15 U.S.C. 7443(a)] and not later than 540 days after the date of the enactment of this Act [Jan. 1, 2021], the Director of the National Institute of Standards and Technology shall, in coordination with the Secretary of Defense, the Secretary of Homeland Security, the Director of the Office of Personnel Management, and the heads of other appropriate agencies, use a consultative process with other Federal agencies, academia, and industry to identify multiple career pathways for cybersecurity work roles that can be used in the private and public sectors."(2) REQUIREMENTS.-The Director shall ensure that the multiple cybersecurity career pathways identified under paragraph (1) indicate the knowledge, skills, and abilities, including relevant education, training, internships, apprenticeships, certifications, and other experiences, that- "(A) align with employers' cybersecurity skill needs, including proficiency level requirements, for its workforce; and "(B) prepare an individual to be successful in entering or advancing in a cybersecurity career. "(3) EXCHANGE PROGRAM.-Consistent with requirements under chapter 37 of title 5, United States Code, the Director of the National Institute of Standards and Technology, in coordination with the Director of the Office of Personnel Management, may establish a voluntary program for the exchange of employees engaged in one of the cybersecurity work roles identified in the National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework (NIST Special Publication 800-181), or successor framework, between the National Institute of Standards and Technology and private sector institutions, including nonpublic or commercial businesses, research institutions, or institutions of higher education, as the Director of the National Institute of Standards and Technology considers feasible."
PROFICIENCY TO PERFORM CYBERSECURITY TASKS Pub. L. 116-283 title XCIV, §9401(d), Jan. 1, 2021, 134 Stat. 4806, provided that: "Not later than 540 days after the date of the enactment of this Act [Jan. 1, 2021], the Director of the National Institute of Standards and Technology shall, in coordination with the Secretary of Defense, the Secretary of Homeland Security, and the heads of other appropriate agencies-"(1) in carrying out subsection (a) of such section [meaning 15 U.S.C. 7451(a), now 15 U.S.C. 7443(a)], assess the scope and sufficiency of efforts to measure an individual's capability to perform specific tasks found in the National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework (NIST Special Publication 800-181) at all proficiency levels; and "(2) submit to Congress a report-"(A) on the findings of the Director with respect to the assessment carried out under paragraph (1); and "(B) with recommendations for effective methods for measuring the cybersecurity proficiency of learners."