(1)
Covered device—
(A)
In general— The term covered device—
(i)
means a physical object that—
(I)
is capable of connecting to and is in regular connection with the Internet; and
(II)
has computer processing capabilities that can collect, send, or receive data; and
(ii)
does not include advanced or general-purpose computing devices, including personal computing systems, smart mobile communications devices, programmable logic controls, and mainframe computing systems.
(B)
OMB exemption— The Director may exempt additional devices under subparagraph (A)(ii) through a process in which interested parties may submit a petition for the exemption. The Director shall act in an expedited manner on any such petition submitted.
(2)
Director— The term Director means the Director of the Office of Management and Budget.
(3)
Executive agency— The term executive agency has the meaning given the term in section 133 of title 41, United States Code.
(4)
Firmware— The term firmware means a computer program and the data stored in hardware, typically in read-only memory or programmable read-only memory, such that the program and data cannot be dynamically written or modified during execution of the program.
(5)
Fixed or hard-coded credential— The term fixed or hard-coded credential means a value, such as a password, token, cryptographic key, or other data element used as part of an authentication mechanism for granting remote access to an information system or the information of the system, that is—
(A)
established by a product vendor or service provider; and
(B)
incapable of being modified or revoked by the user or manufacturer lawfully operating the information system, except through a firmware update.
(6)
Gateway product— The term gateway product means a node or device that connects to multiple networks using standard protocols.
(7)
Hardware— The term hardware means the physical components of an information system.
(8)
NIST— The term NIST means the National Institute of Standards and Technology.
(9)
Non-compliant device— The term non-compliant device means a covered device that does not meet the baseline security requirements established in section 3(a)(2)(A).
(10)
Properly authenticated update— The term properly authenticated update means an update, remediation, or technical fix to a hardware, firmware, or software component issued by a product vendor or service provider used to correct particular problems with the component, and that, in the case of software or firmware, contains some method of authenticity protection, such as a digital signature, so that unauthorized updates and rollbacks of authorized updates can be automatically detected and rejected.
(11)
Security vulnerability— The term security vulnerability means any attribute of hardware, firmware, software, process, or procedure or a combination of 2 or more of these attributes that could enable or facilitate the defeat or compromise of the confidentiality, integrity, or availability of an information system or the information or physical devices of an information system to which an information system is connected.
(12)
Software— The term software means a computer program and associated data that may be dynamically written or modified.
(13)
Vendor— The term vendor, with respect to a technology, product, system, service, or application, means—
(A)
in the case of a purchase by the Government, the entity that developed the technology, product, system, service, or application; or
(B)
in the case of a purchase by a contractor, the entity that is responsible for maintaining the technology, product, system, service, or application.