---
kind: "section"
citation: "15 U.S.C. § 278g–3b"
title: "15"
title_heading: "Commerce and Trade"
number: "278g–3b"
heading: "Security standards and guidelines for agencies on use and management of Internet of Things devices"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/15/278g-3b"
units:
  - "Chapter 7 — National Institute of Standards and Technology"
---

# §278g–3b. Security standards and guidelines for agencies on use and management of Internet of Things devices

- (a) **National Institute of Standards and Technology development of standards and guidelines for use of Internet of Things devices by agencies—**
  - (1) **In general—** Not later than 90 days after December 4, 2020, the [Director of the Institute](/usc/15/278g–3a.md?p=3) shall develop and publish under [section 278g–3 of this title](/usc/15/278g–3.md) standards and guidelines for the Federal Government on the appropriate use and management by [agencies](/usc/15/278g–3a.md?p=1) of Internet of Things [devices](/usc/15/55.md?p=d) owned or controlled by an [agency](/usc/15/278g–3a.md?p=1) and connected to [information systems](/usc/15/278g–3a.md?p=4) owned or controlled by an [agency](/usc/15/278g–3a.md?p=1), including minimum information security requirements for managing cybersecurity risks associated with such [devices](/usc/15/55.md?p=d).
  - (2) **Consistency with ongoing efforts—** The [Director of the Institute](/usc/15/278g–3a.md?p=3) shall ensure that the standards and guidelines developed under [paragraph (1)](#a-1) are consistent with the efforts of the National Institute of Standards and Technology in effect on December 4, 2020—
    - (A) regarding—
      - (i) examples of possible [security vulnerabilities](/usc/15/278g–3a.md?p=8) of Internet of Things [devices](/usc/15/55.md?p=d); and
      - (ii) considerations for managing the [security vulnerabilities](/usc/15/278g–3a.md?p=8) of Internet of Things [devices](/usc/15/55.md?p=d); and
    - (B) with respect to the following considerations for Internet of Things [devices](/usc/15/55.md?p=d):
      - (i) Secure Development.
      - (ii) Identity management.
      - (iii) Patching.
      - (iv) Configuration management.
  - (3) **Considering relevant standards—** In developing the standards and guidelines under [paragraph (1)](#a-1), the [Director of the Institute](/usc/15/278g–3a.md?p=3) shall consider relevant standards, guidelines, and best practices developed by the private sector, [agencies](/usc/15/278g–3a.md?p=1), and public-private partnerships.
- (b) **Review of agency information security policies and principles—**
  - (1) **Requirement—** Not later than 180 days after the date on which the [Director of the Institute](/usc/15/278g–3a.md?p=3) completes the development of the standards and guidelines required under [subsection (a)](#a), the [Director of OMB](/usc/15/278g–3a.md?p=2) shall review [agency](/usc/15/278g–3a.md?p=1) information security policies and principles on the basis of the standards and guidelines published under [subsection (a)](#a) pertaining to Internet of Things [devices](/usc/15/55.md?p=d) owned or controlled by [agencies](/usc/15/278g–3a.md?p=1) (excluding [agency](/usc/15/278g–3a.md?p=1) information security policies and principles pertaining to Internet of Things of [devices](/usc/15/55.md?p=d) owned or controlled by [agencies](/usc/15/278g–3a.md?p=1) that are or comprise a [national security system](/usc/15/278g–3a.md?p=5)) for consistency with the standards and guidelines submitted under [subsection (a)](#a) and issue such policies and principles as may be necessary to ensure those policies and principles are consistent with such standards and guidelines.
  - (2) **Review—** In reviewing [agency](/usc/15/278g–3a.md?p=1) information security policies and principles under [paragraph (1)](#b-1) and issuing policies and principles under such paragraph, as may be necessary, the [Director of OMB](/usc/15/278g–3a.md?p=2) shall—
    - (A) consult with the Director of the Cybersecurity and Infrastructure Security [Agency](/usc/15/278g–3a.md?p=1) of the Department of Homeland Security; and
    - (B) ensure such policies and principles are consistent with the information security requirements under subchapter II of chapter 35 of title 44.
  - (3) **National security systems—** Any policy or principle issued by the [Director of OMB](/usc/15/278g–3a.md?p=2) under [paragraph (1)](#b-1) shall not apply to [national security systems](/usc/15/278g–3a.md?p=5).
- (c) **Quinquennial review and revision—**
  - (1) **Review and revision of NIST standards and guidelines—** Not later than 5 years after the date on which the [Director of the Institute](/usc/15/278g–3a.md?p=3) publishes the standards and guidelines under [subsection (a)](#a), and not less frequently than once every 5 years thereafter, the [Director of the Institute](/usc/15/278g–3a.md?p=3), shall—
    - (A) review such standards and guidelines; and
    - (B) revise such standards and guidelines as appropriate.
  - (2) **Updated OMB policies and principles for agencies—** Not later than 180 days after the [Director of the Institute](/usc/15/278g–3a.md?p=3) makes a revision pursuant to [paragraph (1)](#c-1), the [Director of OMB](/usc/15/278g–3a.md?p=2), in consultation with the Director of the Cybersecurity and Infrastructure Security [Agency](/usc/15/278g–3a.md?p=1) of the Department of Homeland Security, shall update any policy or principle issued under [subsection (b)(1)](#b-1) as necessary to ensure those policies and principles are consistent with the review and any revision under [paragraph (1)](#c-1) under this subsection and paragraphs [(2)](#b-2) and [(3)](#b-3) of subsection (b).
- (d) **Revision of Federal Acquisition Regulation—** The Federal Acquisition Regulation shall be revised as necessary to implement any standards and guidelines promulgated in this section.

## Source credit

(Pub. L. 116–207, § 4, Dec. 4, 2020, 134 Stat. 1002.)

## Notes

### Editorial Notes

### Codification

Section was enacted as part of the Internet of Things Cybersecurity Improvement Act of 2020, also known as the IoT Cybersecurity Improvement Act of 2020, and not as part of the National Institute of Standards and Technology Act which comprises this chapter.

### Statutory Notes and Related Subsidiaries

### Definitions

For definitions of terms used in this section, see section 278g–3a of this title.
