US Codex
Bill
Notes

H.R. 1668 — what changed

Internet of Things Cybersecurity Improvement Act of 2020

From Introduced in House to Reported in House. 5 sections amended and 2 added between Introduced in House and Reported in House.

Sec. 2 Definitions

In this Act:

(1)
Agency— The term agency has the meaning given such term in section 3502 of title 44, United States Code.
(2)
added Covered device— The term covered device means a physical object that—
(2)
removed Covered device—
(A)
removed In general— The term covered device means a physical object that—
(i)
removed is capable of connecting to and is in regular connection with the internet;
(ii)
removed has computer processing capabilities that can collect, send, or receive data; and
(iii)
removed is not a general-purpose computing device, including personal computing systems, smart mobile communications devices, programmable logic controls, and mainframe computing systems.
(A)
changed Modification of definition— The Director of the Office is capable of Management and Budget shall establish a process by which—being in regular connection with—
(i)
added the Internet; or
(ii)
changed interested parties may petition for a device network that is not described in subparagraph (A) connected to be considered a device that is not the Internet on a covered device; andrecurring basis;
(B)
added has computer processing capabilities of collecting, sending, or receiving data; and
(C)
added is not a—
(i)
added general-purpose computing device;
(ii)
added personal computing system;
(iii)
added smart mobile communications device;
(iv)
added programmable logic controller with an industrial control system specifically not designed for connection to the internet;
(v)
added mainframe computing system; or
(vi)
added subcomponent of a device.
(ii)
removed the Director acts upon any petition submitted under clause (i) in a timely manner.
(3)
changed Security vulnerability—Director of OMB— The term security vulnerability means any attribute of hardware, firmware, software, or combination of 2 or more Director of these factors that could enable OMB means the compromise Director of the confidentiality, integrity, or availability Office of an information system or its information or physical devices to which it is connected.Management and Budget.
(4)
added Director of the Institute— The term Director of the Institute means the Director of the National Institute of Standards and Technology.
(5)
added Security vulnerability— The term security vulnerability has the meaning given that term under section 102(17) of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501(17)).

Sec. 3 Completion of ongoing efforts relating to considerations for managing Internet of things cybersecurity risks

added Not later than December 31, 2019, the Director of the National Institute of Standards and Technology shall complete the efforts of the Institute in effect on the date of the enactment of this Act regarding considerations for managing the security vulnerabilities of Internet of Things devices and examples of possible cybersecurity capabilities of such devices by publishing a report that includes, at a minimum, the following considerations for covered devices:

(1)
added Secure development.
(a)
removed Completion of ongoing efforts relating to considerations for managing Internet of Things cybersecurity risks—
(1)
removed In general— The Director of the National Institute of Standards and Technology shall ensure that the efforts of the Institute in effect on the date of the enactment of this Act regarding considerations for managing Internet of Things cybersecurity risks, especially regarding examples of possible cybersecurity capabilities of Internet of Things devices, are completed no later than September 30, 2019.
(2)
removed Matters addressed— In ensuring efforts are completed under paragraph (1), the Director shall also ensure that such efforts address, at a minimum, the following considerations for covered devices:
(A)
removed Secure Development.
(2)
renumbered was (2)(3)(4) Identity management.
(3)
renumbered was (2)(3)(5) Patching.
(4)
renumbered was (2)(3)(6) Configuration management.
(b)
removed Development of recommended standards for use of Internet of Things devices by Federal Government—
(1)
removed In general— Not later than March 31, 2020, the Director of the Institute shall develop recommendations for the Federal Government on the appropriate use and management by the Federal Government of Internet of Things devices owned or controlled by the Federal Government, including minimum information security requirements for managing cybersecurity risks associated with such devices.
(2)
removed Consistency with ongoing efforts— The Director of the Institute shall ensure that the recommendations and standards developed under paragraph (1) are consistent with the efforts referred to in subsection (a), especially with respect to the examples of possible cybersecurity capabilities referred to in such subsection.
(c)
removed Institute Report on cybersecurity considerations stemming from the convergence of Information Technology, Internet of Things, and Operational Technology devices, networks and systems— Not later than 180 days following the enactment of this Act, the Director of the Institute shall publish a draft report related to the increasing convergence of traditional Information Technology devices, networks, and systems with Internet of Things devices, networks and systems and Operational Technology devices, networks and systems, including considerations for managing cybersecurity risks associated with such trends.

Sec. 4 Security standards for use of covered devices by the Federal Government

(a)
added Guidelines required—
(1)
added Guidelines— Not later than 6 months after the date on which the report under section 3 is completed, the Director of the Institute shall develop under section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g-3), and submit to the Director of OMB, guidelines on—
(A)
added the appropriate use and management by the agencies of covered devices owned or controlled by the agencies; and
(B)
added minimum information security requirements for managing security vulnerabilities associated with such devices.
(2)
added Development of guidelines— In developing the guidelines submitted under paragraph (1), the Director of the Institute shall—
(A)
added consider relevant standards and best practices developed by the private sector, agencies, and public-private partnerships; and
(B)
added ensure that such guidelines are consistent with the considerations published in the report described under section 3.
(b)
added Promulgation of standards—
(1)
added Standards— Not later than 180 days after the date on which the Director of the Institute completes the development of the guidelines required under subsection (a), the Director of OMB, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall—
(A)
added promulgate standards on the basis of the guidelines submitted under subsection (a) pertaining to covered devices owned or controlled by agencies, except those considered national security systems as defined by section 3552(b)(6) of title 44, United States Code; and
(B)
added ensure such standards are consistent with the information security requirements under subchapter II of chapter 35 of title 44, United States Code.
(2)
added Quinquennial review and revision— Not later than 5 years after the date on which the Director of OMB promulgates the standards under paragraph (1), and not less frequently than once every 5 years thereafter, the Director of OMB, in consultation with and the Director of the Institute and the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall—
(A)
added review such standards; and
(B)
added revise such standards as appropriate.
(a)
removed Revisions to the Federal acquisition regulation— Not later than 180 days after the date on which the Director of the National Institute of Standards and Technology completes the development of the recommendations required under section 3(b), the Director of the Office of Management and Budget shall issue guidelines for each agency that are consistent with such recommendations.
(b)
removed Requirement— In issuing the guidelines required under subsection (a), the Director of the Office of Management and Budget shall ensure that the guidelines are consistent with the information security requirements in subchapter II of chapter 35 of title 44, United States Code.
(c)
changed Quinquennial reviews and revisions—Revision of Federal Acquisition Regulation— Not less frequently than once every 5 years—The Federal Acquisition Regulation shall be revised to implement any standard promulgated under subsection (b).
(1)
removed the Director of the Office of Management and Budget and the Director of the National Institute of Standards and Technology shall review the policies issued under subsection (a); and
(2)
removed the Director of the Office of Management and Budget shall, in consultation with the Director of the National Institute of Standards and Technology, revise such policies.

Sec. 5 Petition to exclude certain devices

(a)
changed In general—Petition— Not later than 180 days after the date of the enactment of this Act, the The Director of OMB shall establish a process by which an interested party may petition the National Institute Director of Standards and Technology shall, OMB for a device described in consultation with such cybersecurity researchers and private-sector industry experts as the Director considers appropriate, publish guidance on policies and procedures section 2(2) to not be considered a covered device for the reporting, coordinating, publishing, and receiving purpose of information about—standards promulgated under section 4(b).
(1)
removed a security vulnerability relating to a covered device used by the Federal Government; and
(2)
removed the resolution of such security vulnerability.
(b)
changed Elements—Grants of petition— The guidance published Director of OMB shall grant a petition under subsection (a) shall include the following:(a)—
(1)
changed Policies and procedures described in subsection (a) that, to the maximum extent practicable, are aligned with Standards 29147 and 30111 of the International Standards Organization, or any successor standards. Such policies and procedures shall include policies and procedures for a contractor or vendor providing on a covered device to the Federal Government on—limited basis;
(A)
removed receiving information about a potential security vulnerability relating to the covered device; and
(B)
removed disseminating information about the resolution of a security vulnerability relating to the covered device.
(2)
changed Guidance, including example content, on the information items that should be produced through the implementation of the security vulnerability disclosure process of the contractor.in a timely manner; and
(3)
added only if the interested party demonstrates that—
(A)
added the procurement of such a covered device with limited data processing and software functionality would be unfeasible; or
(B)
added the procurement of a covered device that does not meet the standards promulgated by the Director of OMB under this Act is necessary for national security or for research purposes.
(c)
added Report—
(1)
added In general— Not later than one year after the date of the enactment of this Act, and annually thereafter for each of the following four years, the Director of OMB shall submit to the appropriate congressional committees a report on the process established by the Director of OMB for granting or denying waivers under this section.
(2)
added Assessment of implementation— The reports required under paragraph (1) shall include, at a minimum, the following:
(A)
added An assessment of the waiver evaluation process.
(B)
added A description of the methods established to carry out such assessment.
(C)
added A classified appendix listing the types and number of devices for each agency granted a waiver and the reasons for such waiver.
(3)
added Appropriate congressional committees defined— In this subsection, the term appropriate congressional committees means the Committees on Oversight and Reform and Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate.

Sec. 6 Coordinated disclosure of security vulnerabilities relating to covered devices

(a)
changed Agency guidelines required—In general— Not later than 180 days after the date on which of the guidance required under section 4 is published, enactment of this Act, the Director of the Office of Management and Budget shall, Institute, in consultation with the Administrator Director of Cybersecurity and Infrastructure Security Agency of the General Services Administration, issue guidelines for each agency on reporting, coordinating, publishing, Department of Homeland Security, shall develop under section 20 of the National Institute of Standards and receiving information about—Technology Act (15 U.S.C. 278g-3) and submit to the Director of OMB, guidelines—
(1)
changed a security vulnerability relating to a covered device used by for the agency; andreporting, coordinating, publishing, and receiving of information about—
(A)
added a security vulnerability relating to a covered device owned or controlled by an agency; and
(B)
added the resolution of such security vulnerability;
(2)
changed for contractors providing a covered device to the resolution of Federal Government, and any subcontractor thereof at any tier providing such security vulnerability.device to such contractors on—
(A)
added receiving information about a potential security vulnerability relating to the covered device; and
(B)
added disseminating information about the resolution of a security vulnerability relating to the covered device; and
(3)
added on the type of information about security vulnerabilities that should be reported to the Federal Government, including examples thereof.
(b)
changed Contractor and vendor compliance with National Institute Development of Standards and Technology guidance—guidelines— The In developing the guidelines required by under subsection (a) shall include a limitation that prohibits an agency from acquiring or using any covered device from a contractor or vendor if (a), the contractor or vendor fails to comply with Director of the guidance published under section 5(a).Institute shall—
(1)
added consult with such cybersecurity researchers and private sector industry experts as the Director considers appropriate;
(2)
added to the maximum extent practicable, align such guidelines with Standards 29147 and 30111 of the International Standards Organization, or any successor standards thereof; and
(3)
added ensure such guidelines are consistent with the policies and procedures developed under section 2209(m) of the Homeland Security Act of 2002 (6 U.S.C. 659(m)).
(c)
added Promulgation of standards—
(1)
added In general— Not later than 180 days after the date on which the guidelines under subsection (a) are submitted, the Director of OMB, in consultation with the Administrator of General Services and the Secretary of Homeland Security, shall promulgate standards on the basis of such guidelines.
(2)
added Contract requirement for subcontracts— The standards promulgated under paragraph (1) shall include a requirement for any contract related to a covered device to include a clause that requires each contractor that provides a covered device under the contract to an agency to ensure that any covered device obtained through a subcontract, at any tier, complies with the standards and regulations promulgated under this section with respect to such covered device.
(3)
added Consistency with the Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure Technology Act— The Director of OMB shall ensure that the standards promulgated under paragraph (1) are consistent with section 101 of the Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure Technology Act (6 U.S.C. 663 note; Public Law 115–390).
(d)
added Revision of Federal Acquisition Regulation— The Federal Acquisition Regulation shall be revised to implement the standards promulgated under subsection (c).
(c)
removed Consistency with guidance from National Institute of Standards and Technology— The Director shall ensure that the guidelines issued under subsection (a) are consistent with the guidance published under section 5(a).

Sec. 7 Contractor compliance with standards and regulations

added
(a)
added In general—
(1)
added Determination—
(A)
added Compliance required— Before awarding a contract to an offeror for the procurement of a covered device, or renewing a contract to procure or obtain a covered device from a contractor, the agency Chief Information Officer shall determine if such offeror or contractor has complied with each standard promulgated under section 6(c) with respect to such covered device.
(B)
added Simplified acquisition threshold— Notwithstanding section 1905 of title 41, United States Code, the requirements under subparagraph (A) shall apply to a contract or subcontract in amounts not greater than the simplified acquisition threshold.
(2)
added Prohibition on use or procurement— The head of an agency may not procure or obtain, or renew a contract to procure or obtain, a covered device if the agency Chief Information Officer determines under paragraph (1)(A) that such offeror or contractor has not complied with a standard promulgated under section 6(c) with respect to such covered device.
(b)
added Waiver— The head of an agency may waive the prohibition under subsection (a)(2) if the procurement of such covered device is necessary for national security or for research purposes.
(c)
added Effective date— The prohibition under subsection (a) shall take effect one year after the date of the enactment of this Act.

Sec. 8 Institute report on cybersecurity considerations stemming from the convergence of information technology, internet of things, and operational technology devices, networks and systems

added

added Not later than 1 year after the date of the enactment of this Act, the Director of the Institute shall publish a report on the increasing convergence, including considerations for managing potential security vulnerabilities associated with such convergence, of traditional information technology devices, networks, and systems with—

(1)
added covered devices, networks and systems; and
(2)
added operational technology devices, networks and systems.