NIST Small Business Cybersecurity Act
The NIST Small Business Cybersecurity Act requires the Director of the National Institute of Standards and Technology to provide guidance to help small businesses reduce their cybersecurity risks.
This guidance includes resources such as guidelines, tools, best practices, standards, and methodologies to assist small businesses in identifying, assessing, managing, and reducing cybersecurity risks.
The resources provided are voluntary and are designed to be applicable and usable by a wide range of small businesses, regardless of the nature and size of the business or the data collected or stored.
The Act emphasizes the importance of promoting awareness of basic cybersecurity controls, establishing a workplace cybersecurity culture, and fostering relationships with third-party stakeholders to mitigate common cybersecurity risks.
Small businesses are encouraged to implement these resources using commercial and off-the-shelf technologies, based on international standards and consistent with existing cybersecurity laws and regulations.
The Act also requires the Director to disseminate updates and make information about the resources available on public websites.