ARTICLE
26 November 2020

Congress Sends IoT Cybersecurity Measure To President Trump's Desk

AG
Akin Gump Strauss Hauer & Feld LLP

Contributor

Akin is a law firm focused on providing extraordinary client service, a rewarding environment for our diverse workforce and exceptional legal representation irrespective of ability to pay. The deep transactional, litigation, regulatory and policy experience we bring to client engagements helps us craft innovative, effective solutions and strategies.
On Tuesday, November 17, the Senate passed H.R. 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2020, by unanimous consent.
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

On Tuesday, November 17, the Senate passed H.R. 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2020, by unanimous consent. The bill, which previously passed the House of Representatives in September after being introduced by Reps. Robin Kelly (D-IL) and Will Hurd (R-TX), would require the National Institute of Standards and Technology (NIST) to develop standards and guidelines for the federal government on "the appropriate use and management by agencies of [IoT] devices owned or controlled by an agency and connected to information systems owned or controlled by an agency" within 90 days of enactment. While an identical measure, S. 734, was introduced in the Senate by Sens. Mark Warner (D-VA) and Cory Gardner (R-CO), the Senate ended up taking up the House bill.

These standards include "minimum information security requirements for managing cybersecurity risks associated with [IoT] devices." The bill also directs NIST to consider relevant standards and best practices developed by the private sector, agencies and public-private partnerships. The IoT Cybersecurity Improvement Act also requires, no later than 180 days after enactment, that NIST to develop guidelines for reporting and publishing cybersecurity vulnerabilities in IoT devices owned or controlled by federal agencies and contractors.

While lawmakers have recognized the benefits of connected devices, many have expressed concerns about IoT device security. As a result, state lawmakers have also recently begun to take action to regulate the devices. In 2018, California Gov. Jerry Brown signed SB-327 into law, making California the first state to enact legislation regulating the security of IoT devices. Oregon quickly followed suit, and Gov. Kate Brown signed Bill 2395 into law in May 2019. Both measures came into force in January 2020 and require safeguards to defend against "unauthorized access, destruction, use, modification or disclosure" of information.

The bipartisan IoT Cybersecurity Improvement Act now awaits President Trump's signature. Should the bill be signed into law, its final impact remains unknown as the scope of NIST's related guidelines have yet to be determined.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More