National Institute of Standards and Technology programs

15 U.S. Code § 7406. National Institute of Standards and Technology programs

(a), (b) Omitted
(c) Security automation and checklists for Government systems
(1) In general
The Director of the National Institute of Standards and Technology shall, as necessary, develop and revise security automation standards, associated reference materials (including protocols), and checklists providing settings and option selections that minimize the security risks associated with each information technology hardware or software system and security tool that is, or is likely to become, widely used within the Federal Government, thereby enabling standardized and interoperable technologies, architectures, and frameworks for continuous monitoring of information security within the Federal Government.
(2) Priorities for developmentThe Director of the National Institute of Standards and Technology shall establish priorities for the development of standards, reference materials, and checklists under this subsection on the basis of—
(A)
the security risks associated with the use of the system;
(B)
the number of agencies that use a particular system or security tool;
(C)
the usefulness of the standards, reference materials, or checklists to Federal agencies that are users or potential users of the system;
(D)
the effectiveness of the associated standard, reference material, or checklist in creating or enabling continuous monitoring of information security; or
(E)
such other factors as the Director of the National Institute of Standards and Technology determines to be appropriate.
This document is only available to subscribers. Please log in or purchase access.