ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

15 U.S.C. § 278g–3cGuidelines on the disclosure process for security vulnerabilities relating to information systems, including Internet of Things devices

submitted 6 years ago by Pub. L. 116-207 to r/title-15-COMMERCE-AND-TRADE · 378 words · no verdicts yet

in plain englishAI-generated · not legal advice

The Institute had 180 days to write guidelines for reporting and fixing security flaws. These cover agency information systems, including IoT devices. The guidelines also address contractor reporting, and OMB and Homeland Security oversee them.

(a) In general: Within 180 days of December 4, 2020, the Institute's Director, after consulting cybersecurity researchers, private industry experts, and the Secretary, had to develop and publish, under section 278g–3, guidelines covering: how to report, coordinate, publish, and receive information about a security vulnerability in an agency's information systems (including IoT devices), and how to resolve it; and, for contractors (and subcontractors at any level) that supply an agency with an information system or IoT device, how they should receive vulnerability information and share information about fixing it. (b) Elements: The guidelines must, as much as practical, follow industry best practices and International Standards Organization Standards 29147 and 30111 (or successor or other widely used standards). They must cover receiving vulnerability information about agency-owned systems and IoT devices, and sharing how those vulnerabilities get fixed. They must also match the policies and procedures created under section 659(m) of title 6. (c) Information items: The guidelines must give example content for what information a contractor or subcontractor providing an information system or IoT device should report, coordinate, publish, or receive under this section. (d) Oversight: The Director of OMB oversees how these guidelines get carried out. (e) Operational and technical assistance: The Secretary, working with OMB's Director, must run the guidelines and give agencies operational and technical help using them.
the actual law source: uscode.house.gov ↗public domain
(a) In general

Not later than 180 days after December 4, 2020, the Director of the Institute, in consultation with such cybersecurity researchers and private sector industry experts as the Director considers appropriate, and in consultation with the Secretary, shall develop and publish under section 278g–3 of this title guidelines—

(1)

for the reporting, coordinating, publishing, and receiving of information about—

(A)

a security vulnerability relating to information systems owned or controlled by an agency (including Internet of Things devices owned or controlled by an agency); and

(B)

the resolution of such security vulnerability; and

(2)

for a contractor providing to an agency an information system (including an Internet of Things device) and any subcontractor thereof at any tier providing such information system to such contractor, on—

(A)

receiving information about a potential security vulnerability relating to the information system; and

(B)

disseminating information about the resolution of a security vulnerability relating to the information system.

(b) Elements

The guidelines published under subsection (a) shall—

(1)

to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely-used standard;

(2)

incorporate guidelines on—

(A)

receiving information about a potential security vulnerability relating to an information system owned or controlled by an agency (including an Internet of Things device); and

(B)

disseminating information about the resolution of a security vulnerability relating to an information system owned or controlled by an agency (including an Internet of Things device); and

(3)

be consistent with the policies and procedures produced under section 659(m) of title 6.

(c) Information items

The guidelines published under subsection (a) shall include example content, on the information items that should be reported, coordinated, published, or received pursuant to this section by a contractor, or any subcontractor thereof at any tier, providing an information system (including Internet of Things device) to the Federal Government.

(d) Oversight

The Director of OMB shall oversee the implementation of the guidelines published under subsection (a).

(e) Operational and technical assistance

The Secretary, in consultation with the Director of OMB, shall administer the implementation of the guidelines published under subsection (a) and provide operational and technical assistance in implementing such guidelines.

Source credit: (Pub. L. 116–207, § 5, Dec. 4, 2020, 134 Stat. 1004.)

history & why it existsrecord from the source credit
  • 2020Enacted · Pub. L. 116-207 · 134 Stat. 1004

A history note hasn’t been published yet. The record shows enactment by Pub. L. 116-207 on 2020-12-04.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case