Federal
Improving Cybersecurity of Small Organizations Act of 2020
Source: Congress.gov ·
1,798 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
116TH CONGRESS
2D SESSION
S. 4731
To require the Director of the Cybersecurity and Infrastructure Security
Agency to establish cybersecurity guidance for small organizations, and
for other purposes.
IN THE SENATE OF THE UNITED STATES
SEPTEMBER 24, 2020
Ms. ROSEN (for herself and Mr. CORNYN) introduced the following bill; which
was read twice and referred to the Committee on Homeland Security and
Governmental Affairs
A BILL
To require the Director of the Cybersecurity and Infrastruc-
ture Security Agency to establish cybersecurity guidance
for small organizations, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Improving Cybersecu-
4
rity of Small Organizations Act of 2020’’.
5
SEC. 2. IMPROVING CYBERSECURITY OF SMALL ORGANIZA-
6
TIONS.
7
(a) DEFINITIONS.—In this section:
8
VerDate Sep 11 2014
04:27 Oct 16, 2020
Jkt 019200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\S4731.IS
S4731
kjohnson on DSK79L0C42PROD with BILLS
2
•S 4731 IS
(1) ADMINISTRATION.—The term ‘‘Administra-
1
tion’’ means the Small Business Administration.
2
(2) ADMINISTRATOR.—The term ‘‘Adminis-
3
trator’’ means the Administrator of the Administra-
4
tion.
5
(3) COMMISSION.—The term ‘‘Commission’’
6
means the Federal Trade Commission.
7
(4) CYBERSECURITY
GUIDANCE.—The term
8
‘‘cybersecurity guidance’’ means the cybersecurity
9
guidance documented and promoted in the resource
10
maintained under section 3(a).
11
(5) DIRECTOR.—The term ‘‘Director’’ means
12
the Director of the Cybersecurity and Infrastructure
13
Security Agency.
14
(6) NIST.—The term ‘‘NIST’’ means the Na-
15
tional Institute of Standards and Technology.
16
(7) SECRETARY.—The term ‘‘Secretary’’ means
17
the Secretary of Commerce.
18
(8) SMALL BUSINESS.—The term ‘‘small busi-
19
ness’’ has the meaning given the term ‘‘small busi-
20
ness concern’’ in section 3 of the Small Business Act
21
(15 U.S.C. 632).
22
(9) SMALL
GOVERNMENTAL
JURISDICTION.—
23
The term ‘‘small governmental jurisdiction’’ has the
24
VerDate Sep 11 2014
04:27 Oct 16, 2020
Jkt 019200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\S4731.IS
S4731
kjohnson on DSK79L0C42PROD with BILLS
3
•S 4731 IS
meaning given the term in section 601 of title 5,
1
United States Code.
2
(10) SMALL
NONPROFIT.—The term ‘‘small
3
nonprofit’’ has the meaning given the term ‘‘small
4
organization’’ in section 601 of title 5, United States
5
Code.
6
(11) SMALL ORGANIZATION.—The term ‘‘small
7
organization’’ means an organization that is unlikely
8
to employ a specialist in cybersecurity, including—
9
(A) a small business;
10
(B) a small nonprofit; and
11
(C) a small governmental jurisdiction.
12
(b) CYBERSECURITY GUIDANCE.—
13
(1) IN GENERAL.—The Director shall maintain
14
cybersecurity guidance that documents and promotes
15
evidence-based cybersecurity policies and controls for
16
use by small organizations, which shall—
17
(A) include simple, basic controls that have
18
the most impact in protecting small organiza-
19
tions against common cybersecurity threats and
20
risks;
21
(B) include guidance to address common
22
cybersecurity threats and risks posed by elec-
23
tronic devices that are personal to the employ-
24
ees and contractors of small organizations, as
25
VerDate Sep 11 2014
04:27 Oct 16, 2020
Jkt 019200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\S4731.IS
S4731
kjohnson on DSK79L0C42PROD with BILLS
4
•S 4731 IS
well as electronic devices that are issued to
1
those employees and contractors by small orga-
2
nizations; and
3
(C) recommend—
4
(i) measures to improve the cybersecu-
5
rity of small organizations; and
6
(ii) configurations and settings for
7
some of the most commonly used software
8
that can improve the cybersecurity of small
9
organizations.
10
(2) CONSISTENCY.—The Director shall ensure
11
the cybersecurity guidance maintained under para-
12
graph (1) is consistent with—
13
(A) cybersecurity resources developed by
14
NIST, as required by the NIST Small Business
15
Cybersecurity Act (Public Law 115–236); and
16
(B) the most recent version of the Cyberse-
17
curity Framework, or successor resource, main-
18
tained by NIST.
19
(3) GUIDANCE FOR SPECIFIC TYPES OF SMALL
20
ORGANIZATIONS.—The Director may include cyber-
21
security guidance, as required under paragraph (1),
22
appropriate for specific types of small organizations
23
in addition to guidance applicable for all small orga-
24
nizations.
25
VerDate Sep 11 2014
04:27 Oct 16, 2020
Jkt 019200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\S4731.IS
S4731
kjohnson on DSK79L0C42PROD with BILLS
5
•S 4731 IS
(4) UPDATES.—
1
(A) IN GENERAL.—The Director shall re-
2
view the cybersecurity guidance maintained
3
under paragraph (1) not less frequently than
4
annually and update the cybersecurity guidance
5
as appropriate.
6
(B) CONSULTATION.—In updating the cy-
7
bersecurity guidance under subparagraph (A),
8
the Director shall, to the degree practicable and
9
as appropriate, consult with—
10
(i) the Administrator, the Secretary,
11
and the Commission;
12
(ii)
small
organizations,
insurers,
13
State governments, companies that work
14
with small organizations, and academic
15
and Federal and non-Federal experts in
16
cybersecurity; and
17
(iii) any other entity as determined by
18
the Director.
19
(5) USER INTERFACE.—As appropriate, the Di-
20
rector shall consult with experts regarding the de-
21
sign of a user interface for the cybersecurity guid-
22
ance.
23
(c) PROMOTION OF CYBERSECURITY GUIDANCE FOR
24
SMALL BUSINESSES.—
25
VerDate Sep 11 2014
04:27 Oct 16, 2020
Jkt 019200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\S4731.IS
S4731
kjohnson on DSK79L0C42PROD with BILLS
6
•S 4731 IS
(1) PUBLIC AVAILABILITY.—The cybersecurity
1
guidance maintained under subsection (b)(1) shall
2
be—
3
(A) made available, prominently and free
4
of charge, on the public website of the Cyberse-
5
curity Infrastructure Security Agency; and
6
(B) linked to from relevant portions of the
7
websites of the Administration and the Minority
8
Business Development Agency.
9
(2) PROMOTION
GENERALLY.—The Director,
10
the Administrator, and the Secretary shall, to the
11
degree practicable, promote the cybersecurity guid-
12
ance through relevant resources that are intended
13
for or known to be regularly used by small organiza-
14
tions, including agency documents, websites, and
15
events.
16
(d) REPORT ON INCENTIVIZING CYBERSECURITY FOR
17
SMALL ORGANIZATIONS.—
18
(1) IN GENERAL.—Not later than 1 year after
19
the date of enactment of this Act, the Secretary
20
shall submit to Congress a report describing meth-
21
ods to incentivize small organizations to improve
22
their cybersecurity, including through the adoption
23
of policies, controls, products and services that have
24
been demonstrated to reduce cybersecurity risk.
25
VerDate Sep 11 2014
04:27 Oct 16, 2020
Jkt 019200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\S4731.IS
S4731
kjohnson on DSK79L0C42PROD with BILLS
7
•S 4731 IS
(2) MATTERS TO BE INCLUDED.—The report
1
required under paragraph (1) shall—
2
(A) identify barriers or challenges for
3
small organizations in purchasing or acquiring
4
products and services that promote the cyberse-
5
curity;
6
(B) assess market availability, market pric-
7
ing, and affordability of products and services
8
that promote the cybersecurity for small organi-
9
zations, with particular attention to identifying
10
high-risk and underserved sectors or regions;
11
(C) estimate the cost of tax breaks, grants,
12
subsidies, or other incentives to increase the
13
adoption of policies and controls or acquisition
14
of products and services that promote the cy-
15
bersecurity of small organizations;
16
(D) as practicable, consult the certifi-
17
cations and requirement for cloud services de-
18
scribed in the final report of the Cyberspace So-
19
larium Commission established under section
20
1652 of the John S. McCain National Defense
21
Authorization Act for Fiscal Year 2019 (Public
22
Law 115–232; 132 Stat. 2140);
23
VerDate Sep 11 2014
04:27 Oct 16, 2020
Jkt 019200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\S4731.IS
S4731
kjohnson on DSK79L0C42PROD with BILLS
8
•S 4731 IS
(E) describe evidence-based cybersecurity
1
controls and policies that improve cybersecurity
2
for small organizations;
3
(F) with respect to the incentives described
4
in subparagraph (C), recommend measures that
5
can effectively improve cybersecurity at scale
6
for small organizations; and
7
(G) include any other matters as the Sec-
8
retary determines relevant.
9
(3) GUIDANCE FOR SPECIFIC TYPES OF SMALL
10
ORGANIZATIONS.—In preparing the report required
11
under paragraph (1), the Secretary may include
12
matters applicable for specific types of small organi-
13
zations in addition to matters applicable to all small
14
organizations.
15
(4) CONSULTATION.—In preparing the report
16
required under paragraph (1), the Secretary shall
17
consult with—
18
(A) the Administrator, the Director, and
19
the Commission; and
20
(B) small organizations, insurers of risks
21
related to cybersecurity, State governments, cy-
22
bersecurity and information technology compa-
23
nies that work with small organizations, and
24
VerDate Sep 11 2014
04:27 Oct 16, 2020
Jkt 019200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\S4731.IS
S4731
kjohnson on DSK79L0C42PROD with BILLS
9
•S 4731 IS
academic and Federal and non-Federal experts
1
in cybersecurity.
2
(e) PERIODIC CENSUS ON STATE OF CYBERSECURITY
3
OF SMALL BUSINESSES.—
4
(1) IN GENERAL.—Not later than 1 year after
5
the date of enactment of this Act and not less fre-
6
quently than every 24 months thereafter for not
7
more than 10 years, the Administrator shall submit
8
to Congress and make publicly available data on the
9
state of cybersecurity of small businesses, includ-
10
ing—
11
(A) adoption of the cybersecurity guidance
12
among small businesses;
13
(B) the most significant and widespread
14
cybersecurity threats facing small businesses;
15
(C) the amount small businesses spend on
16
cybersecurity products and services; and
17
(D) the personnel small businesses dedi-
18
cate to cybersecurity (including the amount of
19
total personnel time, whether by employees or
20
contractors, dedicated to cybersecurity efforts).
21
(2) FORM.—The report required under para-
22
graph (1) shall be produced in unclassified form but
23
may contain a classified annex.
24
VerDate Sep 11 2014
04:27 Oct 16, 2020
Jkt 019200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6201
E:\BILLS\S4731.IS
S4731
kjohnson on DSK79L0C42PROD with BILLS
10
•S 4731 IS
(3) CONSULTATION.—In preparing the report
1
required under paragraph (1), the Administrator
2
shall consult with—
3
(A) the Secretary, the Director, and the
4
Commission; and
5
(B) small businesses, insurers of risks re-
6
lated to cybersecurity, cybersecurity and infor-
7
mation technology companies that work with
8
small businesses, and academic and Federal
9
and non-Federal experts in cybersecurity.
10
Æ
VerDate Sep 11 2014
04:27 Oct 16, 2020
Jkt 019200
PO 00000
Frm 00010
Fmt 6652
Sfmt 6301
E:\BILLS\S4731.IS
S4731
kjohnson on DSK79L0C42PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.