ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

15 U.S.C. § 278g–3eContractor compliance with coordinated disclosure of security vulnerabilities relating to agency Internet of Things devices

submitted 6 years ago by Pub. L. 116-207 to r/title-15-COMMERCE-AND-TRADE · 435 words · no verdicts yet

in plain englishAI-generated · not legal advice

Agencies generally cannot buy or use IoT devices that fail NIST's security standards. Agency heads can waive this ban for national security, research, or if the device is secured another way. The Comptroller General must report on waivers every two years.

(a) Prohibition on procurement and use: (1) In general: An agency head cannot buy, renew a contract for, or use an IoT device if the agency's Chief Information Officer finds, during a required contract review under section 11319(b)(1)(C) of title 40, that using the device would break the standards under section 278g–3b or the guidelines under section 278g–3c. (2) Simplified acquisition threshold: Despite section 1905 of title 41, this rule applies even to small contracts at or below the simplified acquisition threshold. (b) Waiver: (1) Authority: An agency head can waive this ban for a specific device if the agency's Chief Information Officer decides the waiver is needed for national security, needed for research, or that the device is secured through other effective methods suited to what it does. (2) Agency process: OMB's Director must create a standard process for each agency's Chief Information Officer to use in deciding whether to grant this waiver. (c) Reports to Congress: (1) Report: Every 2 years during the 6 years starting December 4, 2020, the Comptroller General must report to three named House and Senate committees on how well the waiver process is working, with recommended best practices for buying IoT devices, and a list of every device that got a waiver in the past 2 years plus which legal reason justified each waiver. (2) Classification of report: Each report must be unclassified, but may have a classified annex containing the device and waiver-reason details. (d) Effective date: The ban starts 2 years after December 4, 2020.
the actual law source: uscode.house.gov ↗public domain
(a) Prohibition on procurement and use
(1) In general

The head of an agency is prohibited from procuring or obtaining, renewing a contract to procure or obtain, or using an Internet of Things device, if the Chief Information Officer of that agency determines during a review required by section 11319(b)(1)(C) of title 40 of a contract for such device that the use of such device prevents compliance with the standards and guidelines developed under section 278g–3b of this title or the guidelines published under section 278g–3c of this title with respect to such device.

(2) Simplified acquisition threshold

Notwithstanding section 1905 of title 41, the requirements under paragraph (1) shall apply to a contract or subcontract in amounts not greater than the simplified acquisition threshold.

(b) Waiver
(1) Authority

The head of an agency may waive the prohibition under subsection (a)(1) with respect to an Internet of Things device if the Chief Information Officer of that agency determines that—

(A)

the waiver is necessary in the interest of national security;

(B)

procuring, obtaining, or using such device is necessary for research purposes; or

(C)

such device is secured using alternative and effective methods appropriate to the function of such device.

(2) Agency process

The Director of OMB shall establish a standardized process for the Chief Information Officer of each agency to follow in determining whether the waiver under paragraph (1) may be granted.

(c) Reports to Congress
(1) Report

Every 2 years during the 6-year period beginning on December 4, 2020, the Comptroller General of the United States shall submit to the Committee on Oversight and Reform of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs of the Senate a report—

(A)

on the effectiveness of the process established under subsection (b)(2);

(B)

that contains recommended best practices for the procurement of Internet of Things devices; and

(C)

that lists—

(i)

the number and type of each Internet of Things device for which a waiver under subsection (b)(1) was granted during the 2-year period prior to the submission of the report; and

(ii)

the legal authority under which each such waiver was granted, such as whether the waiver was granted pursuant to subparagraph (A), (B), or (C) of such subsection.

(2) Classification of report

Each report submitted under this subsection shall be submitted in unclassified form, but may include a classified annex that contains the information described under paragraph (1)(C).

(d) Effective date

The prohibition under subsection (a)(1) shall take effect 2 years after December 4, 2020.

Source credit: (Pub. L. 116–207, § 7, Dec. 4, 2020, 134 Stat. 1005.)

history & why it existsrecord from the source credit
  • 2020Enacted · Pub. L. 116-207 · 134 Stat. 1005

A history note hasn’t been published yet. The record shows enactment by Pub. L. 116-207 on 2020-12-04.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case