Internet of Things (IoT) Cybersecurity Improvement Act of 2017
A BILL
To provide minimal cybersecurity operational standards for Internet-connected devices purchased by Federal agencies, and for other purposes.
Sec. 2 Definitions
Sec. 3 Contractor responsibilities with respect to Internet-connected device cybersecurity
“(k) This section shall not apply to a person who—
“(1) in good faith, engaged in researching the cybersecurity of an Internet-connected device of the class, model, or type provided by a contractor to a department or agency of the United States; and
“(2) acted in compliance with the guidelines required to be issued by the National Protection and Programs Directorate, and adopted by the contractor described in paragraph (1), under section 3(b) of the Internet of Things (IoT) Cybersecurity Improvement Act of 2017.”
“(d) Limitation of liability—A person shall not be held liable under this section if the individual—
“(1) in good faith, engaged in researching the cybersecurity of an Internet-connected device of the class, model, or type provided by a contractor to a department or agency of the United States; and
“(2) acted in compliance with the guidelines required to be issued by the National Protection and Programs Directorate, and adopted by the contractor described in paragraph (1), under section 3(b) of the Internet of Things (IoT) Cybersecurity Improvement Act of 2017.”
“(d) Limitation of liability—Subsection (a) shall not apply to a person who—
“(1) in good faith, engaged in researching the cybersecurity of an Internet-connected device of the class, model, or type provided by a contractor to a department or agency of the United States; and
“(2) acted in compliance with the guidelines required to be issued by the National Protection and Programs Directorate, and adopted by the contractor described in paragraph (1), under section 3(b) of the Internet of Things (IoT) Cybersecurity Improvement Act of 2017.”