Federal
IoT Cybersecurity Improvement Act of 2019
Source: Congress.gov ·
3,383 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
Calendar No. 215
116TH CONGRESS
1ST SESSION
S. 734
[Report No. 116–112]
To leverage Federal Government procurement power to encourage increased
cybersecurity for Internet of Things devices, and for other purposes.
IN THE SENATE OF THE UNITED STATES
MARCH 11, 2019
Mr. WARNER (for himself, Mr. GARDNER, Ms. HASSAN, Mr. DAINES, Ms.
CORTEZ MASTO, and Mr. ROUNDS) introduced the following bill; which
was read twice and referred to the Committee on Homeland Security and
Governmental Affairs
SEPTEMBER 23, 2019
Reported by Mr. JOHNSON, with an amendment
[Strike out all after the enacting clause and insert the part printed in italic]
A BILL
To leverage Federal Government procurement power to en-
courage increased cybersecurity for Internet of Things
devices, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
VerDate Sep 11 2014
01:52 Sep 24, 2019
Jkt 089200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\S734.RS
S734
pamtmann on DSKBC07HB2PROD with BILLS
2
•S 734 RS
SECTION 1. SHORT TITLE.
1
This Act may be cited as the ‘‘Internet of Things Cy-
2
bersecurity Improvement Act of 2019’’ or the ‘‘IoT Cyber-
3
security Improvement Act of 2019’’.
4
SEC. 2. DEFINITIONS.
5
In this Act:
6
(1)
AGENCY.—The
term
‘‘agency’’
has
the
7
meaning given such term in section 3502 of title 44,
8
United States Code.
9
(2) COVERED DEVICE.—
10
(A) IN GENERAL.—The term ‘‘covered de-
11
vice’’ means a physical object that—
12
(i) is capable of connecting to and is
13
in regular connection with the Internet;
14
(ii) has computer processing capabili-
15
ties that can collect, send, or receive data;
16
and
17
(iii) is not a general-purpose com-
18
puting
device,
including
personal
com-
19
puting systems, smart mobile communica-
20
tions devices, programmable logic controls,
21
and mainframe computing systems.
22
(B) MODIFICATION OF DEFINITION.—The
23
Director of the Office of Management and
24
Budget shall establish a process by which—
25
VerDate Sep 11 2014
01:52 Sep 24, 2019
Jkt 089200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6401
E:\BILLS\S734.RS
S734
pamtmann on DSKBC07HB2PROD with BILLS
3
•S 734 RS
(i) interested parties may petition for
1
a device that is not described in subpara-
2
graph (A) to be considered a device that is
3
not a covered device; and
4
(ii) the Director acts upon any peti-
5
tion submitted under clause (i) in a timely
6
manner.
7
(3) SECURITY VULNERABILITY.—The term ‘‘se-
8
curity vulnerability’’ means any attribute of hard-
9
ware, firmware, software, or combination of 2 or
10
more of these factors that could enable the com-
11
promise of the confidentiality, integrity, or avail-
12
ability of an information system or its information
13
or physical devices to which it is connected.
14
SEC. 3. NATIONAL INSTITUTE OF STANDARDS AND TECH-
15
NOLOGY
CONSIDERATIONS
AND
REC-
16
OMMENDATIONS
REGARDING
MANAGING
17
INTERNET
OF
THINGS
CYBERSECURITY
18
RISKS.
19
(a) COMPLETION OF ONGOING EFFORTS RELATING
20
TO
CONSIDERATIONS
FOR
MANAGING
INTERNET
OF
21
THINGS CYBERSECURITY RISKS.—
22
(1) IN GENERAL.—The Director of the National
23
Institute of Standards and Technology shall ensure
24
that the efforts of the Institute in effect on the date
25
VerDate Sep 11 2014
01:52 Sep 24, 2019
Jkt 089200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6401
E:\BILLS\S734.RS
S734
pamtmann on DSKBC07HB2PROD with BILLS
4
•S 734 RS
of the enactment of this Act regarding consider-
1
ations for managing Internet of Things cybersecurity
2
risks, especially regarding examples of possible cy-
3
bersecurity capabilities of Internet of Things devices,
4
are completed no later than September 30, 2019.
5
(2) MATTERS ADDRESSED.—In ensuring efforts
6
are completed under paragraph (1), the Director
7
shall also ensure that such efforts address, at a min-
8
imum, the following considerations for covered de-
9
vices:
10
(A) Secure Development.
11
(B) Identity management.
12
(C) Patching.
13
(D) Configuration management.
14
(b) DEVELOPMENT OF RECOMMENDED STANDARDS
15
FOR USE OF INTERNET OF THINGS DEVICES BY FED-
16
ERAL GOVERNMENT.—
17
(1) IN GENERAL.—Not later than March 31,
18
2020, the Director of the Institute shall develop rec-
19
ommendations for the Federal Government on the
20
appropriate use and management by the Federal
21
Government of Internet of Things devices owned or
22
controlled by the Federal Government, including
23
minimum
information
security
requirements
for
24
VerDate Sep 11 2014
01:52 Sep 24, 2019
Jkt 089200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6401
E:\BILLS\S734.RS
S734
pamtmann on DSKBC07HB2PROD with BILLS
5
•S 734 RS
managing cybersecurity risks associated with such
1
devices.
2
(2) CONSISTENCY WITH ONGOING EFFORTS.—
3
The Director of the Institute shall ensure that the
4
recommendations and standards developed under
5
paragraph (1) are consistent with the efforts re-
6
ferred to in subsection (a), especially with respect to
7
the examples of possible cybersecurity capabilities re-
8
ferred to in such subsection.
9
(c) INSTITUTE REPORT ON CYBERSECURITY CONSID-
10
ERATIONS STEMMING FROM THE CONVERGENCE OF IN-
11
FORMATION TECHNOLOGY, INTERNET OF THINGS, AND
12
OPERATIONAL TECHNOLOGY DEVICES, NETWORKS AND
13
SYSTEMS.—Not later than 180 days following the enact-
14
ment of this Act, the Director of the Institute shall publish
15
a draft report related to the increasing convergence of tra-
16
ditional Information Technology devices, networks, and
17
systems with Internet of Things devices, networks and sys-
18
tems and Operational Technology devices, networks and
19
systems, including considerations for managing cybersecu-
20
rity risks associated with such trends.
21
VerDate Sep 11 2014
01:52 Sep 24, 2019
Jkt 089200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6401
E:\BILLS\S734.RS
S734
pamtmann on DSKBC07HB2PROD with BILLS
6
•S 734 RS
SEC. 4. POLICIES FOR FEDERAL AGENCIES ON USE AND
1
MANAGEMENT OF INTERNET OF THINGS DE-
2
VICES.
3
(a) REVISIONS TO THE FEDERAL ACQUISITION REG-
4
ULATION.—Not later than 180 days after the date on
5
which the Director of the National Institute of Standards
6
and Technology completes the development of the rec-
7
ommendations required under section 3(b), the Director
8
of the Office of Management and Budget shall issue guide-
9
lines for each agency that are consistent with such rec-
10
ommendations.
11
(b) REQUIREMENT.—In issuing the guidelines re-
12
quired under subsection (a), the Director of the Office of
13
Management and Budget shall ensure that the guidelines
14
are consistent with the information security requirements
15
in subchapter II of chapter 35 of title 44, United States
16
Code.
17
(c) QUINQUENNIAL REVIEWS AND REVISIONS.—Not
18
less frequently than once every 5 years—
19
(1) the Director of the Office of Management
20
and Budget and the Director of the National Insti-
21
tute of Standards and Technology shall review the
22
policies issued under subsection (a); and
23
(2) the Director of the Office of Management
24
and Budget shall, in consultation with the Director
25
VerDate Sep 11 2014
01:52 Sep 24, 2019
Jkt 089200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6401
E:\BILLS\S734.RS
S734
pamtmann on DSKBC07HB2PROD with BILLS
7
•S 734 RS
of the National Institute of Standards and Tech-
1
nology, revise such policies.
2
SEC. 5. NATIONAL INSTITUTE OF STANDARDS AND TECH-
3
NOLOGY GUIDANCE ON COORDINATED DIS-
4
CLOSURE
OF
SECURITY
VULNERABILITIES
5
RELATING
TO
INTERNET
OF
THINGS
DE-
6
VICES.
7
(a) IN GENERAL.—Not later than 180 days after the
8
date of the enactment of this Act, the Director of the Na-
9
tional Institute of Standards and Technology shall, in con-
10
sultation with such cybersecurity researchers and private-
11
sector industry experts as the Director considers appro-
12
priate, publish guidance on policies and procedures for the
13
reporting, coordinating, publishing, and receiving of infor-
14
mation about—
15
(1) a security vulnerability relating to a covered
16
device used by the Federal Government; and
17
(2) the resolution of such security vulnerability.
18
(b) ELEMENTS.—The guidance published under sub-
19
section (a) shall include the following:
20
(1) Policies and procedures described in sub-
21
section (a) that, to the maximum extent practicable,
22
are aligned with Standards 29147 and 30111 of the
23
International Standards Organization, or any suc-
24
cessor standards. Such policies and procedures shall
25
VerDate Sep 11 2014
01:52 Sep 24, 2019
Jkt 089200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6401
E:\BILLS\S734.RS
S734
pamtmann on DSKBC07HB2PROD with BILLS
8
•S 734 RS
include policies and procedures for a contractor or
1
vendor providing a covered device to the Federal
2
Government on—
3
(A) receiving information about a potential
4
security vulnerability relating to the covered de-
5
vice; and
6
(B) disseminating information about the
7
resolution of a security vulnerability relating to
8
the covered device.
9
(2) Guidance, including example content, on the
10
information items that should be produced through
11
the implementation of the security vulnerability dis-
12
closure process of the contractor.
13
SEC. 6. GUIDELINES FOR FEDERAL AGENCIES ON COORDI-
14
NATED
DISCLOSURE
OF
SECURITY
15
VULNERABILITIES RELATING TO INTERNET
16
OF THINGS DEVICES.
17
(a) AGENCY GUIDELINES REQUIRED.—Not later
18
than 180 days after the date on which the guidance re-
19
quired under section 4 is published, the Director of the
20
Office of Management and Budget shall, in consultation
21
with the Administrator of the General Services Adminis-
22
tration, issue guidelines for each agency on reporting, co-
23
ordinating, publishing, and receiving information about—
24
VerDate Sep 11 2014
01:52 Sep 24, 2019
Jkt 089200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6401
E:\BILLS\S734.RS
S734
pamtmann on DSKBC07HB2PROD with BILLS
9
•S 734 RS
(1) a security vulnerability relating to a covered
1
device used by the agency; and
2
(2) the resolution of such security vulnerability.
3
(b) CONTRACTOR AND VENDOR COMPLIANCE WITH
4
NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY
5
GUIDANCE.—The guidelines required by subsection (a)
6
shall include a limitation that prohibits an agency from
7
acquiring or using any covered device from a contractor
8
or vendor if the contractor or vendor fails to comply with
9
the guidance published under section 5(a).
10
(c) CONSISTENCY WITH GUIDANCE FROM NATIONAL
11
INSTITUTE OF STANDARDS AND TECHNOLOGY.—The Di-
12
rector shall ensure that the guidelines issued under sub-
13
section (a) are consistent with the guidance published
14
under section 5(a).
15
SECTION 1. SHORT TITLE.
16
This Act may be cited as the ‘‘Internet of Things Cy-
17
bersecurity Improvement Act of 2019’’ or the ‘‘IoT Cyberse-
18
curity Improvement Act of 2019’’.
19
SEC. 2. DEFINITIONS.
20
In this Act:
21
(1) AGENCY.—The term ‘‘agency’’ has the mean-
22
ing given such term in section 3502 of title 44,
23
United States Code.
24
VerDate Sep 11 2014
01:52 Sep 24, 2019
Jkt 089200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6203
E:\BILLS\S734.RS
S734
pamtmann on DSKBC07HB2PROD with BILLS
10
•S 734 RS
(2) DIRECTOR.—The term ‘‘Director’’ means the
1
Director of the National Institute of Standards and
2
Technology.
3
(3) INFORMATION SYSTEM.—The term ‘‘informa-
4
tion system’’ has the meaning given the term in sec-
5
tion 3502 of title 44, United States Code.
6
(4) SECRETARY.—The term ‘‘Secretary’’ means
7
the Secretary of Homeland Security.
8
(5) SECURITY VULNERABILITY.—The term ‘‘secu-
9
rity vulnerability’’ has the meaning given the term in
10
section 102 of the Cybersecurity Information Sharing
11
Act of 2015 (6 U.S.C. 1501).
12
SEC. 3. NATIONAL INSTITUTE OF STANDARDS AND TECH-
13
NOLOGY
CONSIDERATIONS
AND
REC-
14
OMMENDATIONS
REGARDING
MANAGING
15
INTERNET
OF
THINGS
CYBERSECURITY
16
RISKS.
17
(a) DEVELOPMENT OF RECOMMENDED GUIDELINES
18
FOR USE OF INTERNET OF THINGS DEVICES BY FEDERAL
19
GOVERNMENT.—
20
(1) IN
GENERAL.—Not later than March 31,
21
2020, the Director shall develop standards and guide-
22
lines for the Federal Government on the appropriate
23
use and management by the Federal Government of
24
Internet of Things devices owned or controlled by the
25
VerDate Sep 11 2014
01:52 Sep 24, 2019
Jkt 089200
PO 00000
Frm 00010
Fmt 6652
Sfmt 6203
E:\BILLS\S734.RS
S734
pamtmann on DSKBC07HB2PROD with BILLS
11
•S 734 RS
Federal Government, including minimum informa-
1
tion security requirements for managing cybersecurity
2
risks associated with such devices.
3
(2) CONSISTENCY WITH ONGOING EFFORTS.—The
4
Director shall ensure that the standards and guide-
5
lines developed under paragraph (1) are consistent
6
with the efforts of the National Institute of Standards
7
and Technology in effect on the date of enactment of
8
this Act regarding considerations for managing Inter-
9
net of Things cybersecurity risks, especially regarding
10
examples of possible cybersecurity capabilities of
11
Internet of Things devices, and in particular with re-
12
spect to the following considerations for Internet of
13
Things devices:
14
(A) Secure development.
15
(B) Identity management.
16
(C) Patching.
17
(D) Configuration management.
18
(b) INSTITUTE REPORT ON CYBERSECURITY CONSID-
19
ERATIONS STEMMING FROM THE CONVERGENCE OF INFOR-
20
MATION TECHNOLOGY, INTERNET OF THINGS, AND OPER-
21
ATIONAL TECHNOLOGY DEVICES, NETWORKS, AND SYS-
22
TEMS.—Not later than 180 days after the date of enactment
23
of this Act, the Director shall brief the appropriate commit-
24
tees of Congress on the increasing convergence of traditional
25
VerDate Sep 11 2014
01:52 Sep 24, 2019
Jkt 089200
PO 00000
Frm 00011
Fmt 6652
Sfmt 6203
E:\BILLS\S734.RS
S734
pamtmann on DSKBC07HB2PROD with BILLS
12
•S 734 RS
information technology devices, networks, and systems with
1
Internet of Things devices, networks, and systems and oper-
2
ational technology devices, networks, and systems, including
3
considerations for managing cybersecurity risks and secu-
4
rity vulnerabilities associated with such trends.
5
SEC. 4. POLICIES AND PRINCIPLES FOR FEDERAL AGEN-
6
CIES ON USE AND MANAGEMENT OF INTER-
7
NET OF THINGS DEVICES.
8
(a) IN GENERAL.—Not later than 180 days after the
9
date on which the Director completes the development of the
10
standards and guidelines required under section 3(a), the
11
Director of the Office of Management and Budget, in con-
12
sultation with the Secretary, shall issue policies and prin-
13
ciples for each agency that are consistent with such stand-
14
ards and guidelines.
15
(b) REQUIREMENT.—In issuing the policies, prin-
16
ciples, standards, or guidelines required under subsection
17
(a), the Director of the Office of Management and Budget,
18
in consultation with the Secretary, shall ensure that the
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.