ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

15 U.S.C. § 278g–3bSecurity standards and guidelines for agencies on use and management of Internet of Things devices

submitted 6 years ago by Pub. L. 116-207 to r/title-15-COMMERCE-AND-TRADE · 635 words · no verdicts yet

in plain englishAI-generated · not legal advice

The Institute had 90 days to write federal IoT device security standards for agencies. OMB then had to check agency policies against those standards. Both must review and update this work every five years.

(a) National Institute of Standards and Technology development of standards and guidelines for use of Internet of Things devices by agencies: (1) In general: Within 90 days of December 4, 2020, the Institute's Director had to develop and publish, under section 278g–3, standards and guidelines for how agencies should use and manage Internet of Things (IoT) devices they own or control that connect to their information systems — including minimum security requirements for managing the cybersecurity risks those devices create. (2) Consistency with ongoing efforts: The Director had to make sure these standards matched the Institute's existing work as of December 4, 2020, on possible IoT security weaknesses and how to manage them, and covered secure development, identity management, patching, and configuration management for IoT devices. (3) Considering relevant standards: While writing the standards, the Director had to consider relevant standards, guidelines, and best practices already developed by the private sector, agencies, and public-private partnerships. (b) Review of agency information security policies and principles: (1) Requirement: Within 180 days after the Institute finished those standards, the Director of OMB had to review agency security policies for IoT devices against the new standards (excluding IoT devices that are part of national security systems), and issue whatever policies were needed to bring agencies in line. (2) Review: While doing this review and issuing policies, OMB's Director had to consult the Director of the Cybersecurity and Infrastructure Security Agency, and make sure the policies matched the security requirements in subchapter II of chapter 35 of title 44. (3) National security systems: Any policy OMB issued this way does not apply to national security systems. (c) Quinquennial review and revision: (1) Review and revision of NIST standards and guidelines: Starting 5 years after the Institute published its standards, and at least every 5 years after that, the Institute's Director must review and, if needed, revise the standards. (2) Updated OMB policies and principles for agencies: Within 180 days after each Institute revision, OMB's Director, working with the Cybersecurity and Infrastructure Security Agency, must update agency policies to match. (d) Revision of Federal Acquisition Regulation: The Federal Acquisition Regulation must be revised as needed to put this section's standards into practice.
the actual law source: uscode.house.gov ↗public domain
(a) National Institute of Standards and Technology development of standards and guidelines for use of Internet of Things devices by agencies
(1) In general

Not later than 90 days after December 4, 2020, the Director of the Institute shall develop and publish under section 278g–3 of this title standards and guidelines for the Federal Government on the appropriate use and management by agencies of Internet of Things devices owned or controlled by an agency and connected to information systems owned or controlled by an agency, including minimum information security requirements for managing cybersecurity risks associated with such devices.

(2) Consistency with ongoing efforts

The Director of the Institute shall ensure that the standards and guidelines developed under paragraph (1) are consistent with the efforts of the National Institute of Standards and Technology in effect on December 4, 2020—

(A)

regarding—

(i)

examples of possible security vulnerabilities of Internet of Things devices; and

(ii)

considerations for managing the security vulnerabilities of Internet of Things devices; and

(B)

with respect to the following considerations for Internet of Things devices:

(i)

Secure Development.

(ii)

Identity management.

(iii)

Patching.

(iv)

Configuration management.

(3) Considering relevant standards

In developing the standards and guidelines under paragraph (1), the Director of the Institute shall consider relevant standards, guidelines, and best practices developed by the private sector, agencies, and public-private partnerships.

(b) Review of agency information security policies and principles
(1) Requirement

Not later than 180 days after the date on which the Director of the Institute completes the development of the standards and guidelines required under subsection (a), the Director of OMB shall review agency information security policies and principles on the basis of the standards and guidelines published under subsection (a) pertaining to Internet of Things devices owned or controlled by agencies (excluding agency information security policies and principles pertaining to Internet of Things of devices owned or controlled by agencies that are or comprise a national security system) for consistency with the standards and guidelines submitted under subsection (a) and issue such policies and principles as may be necessary to ensure those policies and principles are consistent with such standards and guidelines.

(2) Review

In reviewing agency information security policies and principles under paragraph (1) and issuing policies and principles under such paragraph, as may be necessary, the Director of OMB shall—

(A)

consult with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security; and

(B)

ensure such policies and principles are consistent with the information security requirements under subchapter II of chapter 35 of title 44.

(3) National security systems

Any policy or principle issued by the Director of OMB under paragraph (1) shall not apply to national security systems.

(c) Quinquennial review and revision
(1) Review and revision of NIST standards and guidelines

Not later than 5 years after the date on which the Director of the Institute publishes the standards and guidelines under subsection (a), and not less frequently than once every 5 years thereafter, the Director of the Institute, shall—

(A)

review such standards and guidelines; and

(B)

revise such standards and guidelines as appropriate.

(2) Updated OMB policies and principles for agencies

Not later than 180 days after the Director of the Institute makes a revision pursuant to paragraph (1), the Director of OMB, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall update any policy or principle issued under subsection (b)(1) as necessary to ensure those policies and principles are consistent with the review and any revision under paragraph (1) under this subsection and paragraphs (2) and (3) of subsection (b).

(d) Revision of Federal Acquisition Regulation

The Federal Acquisition Regulation shall be revised as necessary to implement any standards and guidelines promulgated in this section.

Source credit: (Pub. L. 116–207, § 4, Dec. 4, 2020, 134 Stat. 1002.)

history & why it existsrecord from the source credit
  • 2020Enacted · Pub. L. 116-207 · 134 Stat. 1002

A history note hasn’t been published yet. The record shows enactment by Pub. L. 116-207 on 2020-12-04.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case