Section text and notes
National Institute of Standards and Technology development of standards and guidelines for use of Internet of Things devices by agencies
In general
section 278g–3 of this titleNot later than 90 days after , the Director of the Institute shall develop and publish under standards and guidelines for the Federal Government on the appropriate use and management by agencies of Internet of Things devices owned or controlled by an agency and connected to information systems owned or controlled by an agency, including minimum information security requirements for managing cybersecurity risks associated with such devices.
Consistency with ongoing efforts
Considering relevant standards
In developing the standards and guidelines under paragraph (1), the Director of the Institute shall consider relevant standards, guidelines, and best practices developed by the private sector, agencies, and public-private partnerships.
Review of agency information security policies and principles
Requirement
Not later than 180 days after the date on which the Director of the Institute completes the development of the standards and guidelines required under subsection (a), the Director of OMB shall review agency information security policies and principles on the basis of the standards and guidelines published under subsection (a) pertaining to Internet of Things devices owned or controlled by agencies (excluding agency information security policies and principles pertaining to Internet of Things of devices owned or controlled by agencies that are or comprise a national security system) for consistency with the standards and guidelines submitted under subsection (a) and issue such policies and principles as may be necessary to ensure those policies and principles are consistent with such standards and guidelines.
Review
National security systems
Any policy or principle issued by the Director of OMB under paragraph (1) shall not apply to national security systems.
Quinquennial review and revision
Review and revision of NIST standards and guidelines
Updated OMB policies and principles for agencies
Not later than 180 days after the Director of the Institute makes a revision pursuant to paragraph (1), the Director of OMB, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall update any policy or principle issued under subsection (b)(1) as necessary to ensure those policies and principles are consistent with the review and any revision under paragraph (1) under this subsection and paragraphs (2) and (3) of subsection (b).
Revision of Federal Acquisition Regulation
The Federal Acquisition Regulation shall be revised as necessary to implement any standards and guidelines promulgated in this section.
Pub. L. 116–207, § 4134 Stat. 1002 (, , .)
Editorial Notes
Codification
Section was enacted as part of the Internet of Things Cybersecurity Improvement Act of 2020, also known as the IoT Cybersecurity Improvement Act of 2020, and not as part of the National Institute of Standards and Technology Act which comprises this chapter.
Statutory Notes and Related Subsidiaries
Definitions
section 278g–3a of this titleFor definitions of terms used in this section, see .