yourstate.us
15 U.S.C. § 7406

National Institute of Standards and Technology programs

United States · Title 15 — COMMERCE AND TRADE · Status: effective

Get this as JSONEmbed this
Cite this
Citation
15 U.S.C. § 7406, National Institute of Standards and Technology programs, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/442380
Permanent ID
ys:prov:442380@1
SHA-256
dfa32a907007be42b32b3e43d1c39b8429a35244cafb9af24407c25883dc9641

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

The Director of the National Institute of Standards and Technology shall, as necessary, develop and revise security automation standards, associated reference materials (including protocols), and checklists providing settings and option selections that minimize the security risks associated with each information technology hardware or software system and security tool that is, or is likely to become, widely used within the Federal Government, thereby enabling standardized and interoperable technologies, architectures, and frameworks for continuous monitoring of information security within the Federal Government. The Director of the National Institute of Standards and Technology shall establish priorities for the development of standards, reference materials, and checklists under this subsection on the basis of— The Director of the National Institute of Standards and Technology may exclude from the application of paragraph (1) any information technology hardware or software system or security tool for which such Director determines that the development of a standard, reference material, or checklist is inappropriate because of the infrequency of use of the system, the obsolescence of the system, or the lack of utility or impracticability of developing a standard, reference material, or checklist for the system. The Director of the National Institute of Standards and Technology shall ensure that Federal agencies are informed of the availability of any standard, reference material, checklist, or other item developed under this subsection. The development of standards, reference materials, and checklists under paragraph (1) for an information technology hardware or software system or tool does not— In developing the agencywide information security program required by section 3554(b) of title 44, an agency that deploys a computer hardware or software system for which the Director of the National Institute of Standards and Technology has developed a checklist under subsection (c) of this section— Paragraph (1) does not apply to any computer hardware or software system for which the National Institute of Standards and Technology does not have responsibility under section 278g–3(a)(3) of this title.

Legislative history

The public laws that enacted or amended this section. Tallies are for the whole bill as it passed each chamber — often an omnibus covering far more than this provision — not a vote on this section alone.

  • Enacted byPub. L. 107-305(H.R. 3394)2002-11-27
    Cyber Security Research and Development Act
    House: 400–12Senate: no recorded tally
  • Amended byPub. L. 113-274(S. 1353)2014-12-18
    Cybersecurity Enhancement Act of 2014
    House: no recorded tallySenate: no recorded tally
  • Amended byPub. L. 113-283(S. 2521)2014-12-18
    Federal Information Security Modernization Act of 2014
    House: no recorded tallySenate: no recorded tally