Federal · Title 15 — Commerce and Trade

15 U.S.C. § 278g: Security standards and guidelines for agencies on use and management of Internet of Things devices

Read the full statutory text
Not later than 90 days after December 4, 2020 , the Director of the Institute shall develop and publish under section 278g–3 of this title standards and guidelines for the Federal Government on the appropriate use and management by agencies of Internet of Things devices owned or controlled by an agency and connected to information systems owned or controlled by an agency, including minimum information security requirements for managing cybersecurity risks associated with such devices. examples of possible security vulnerabilities of Internet of Things devices; and considerations for managing the security vulnerabilities of Internet of Things devices; and Secure Development. Identity management. Patching. Configuration management. In developing the standards and guidelines under paragraph (1), the Director of the Institute shall consider relevant standards, guidelines, and best practices developed by the private sector, agencies, and public-private partnerships. Not later than 180 days after the date on which the Director of the Institute completes the development of the standards and guidelines required under subsection (a), the Director of OMB shall review agency information security policies and principles on the basis of the standards and guidelines published under subsection (a) pertaining to Internet of Things devices owned or controlled by agencies (excluding agency information security policies and principles pertaining to Internet of Things of devices owned or controlled by agencies that are or comprise a national security system) for consistency with the standards and guidelines submitted under subsection (a) and issue such policies and principles as may be necessary to ensure those policies and principles are consistent with such standards and guidelines. consult with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security; and ensure such policies and principles are consistent with the information security requirements under subchapter II of chapter 35 of title 44. Any policy or principle issued by the Director of OMB under paragraph (1) shall not apply to national security systems. review such standards and guidelines; and revise such standards and guidelines as appropriate. Not later than 180 days after the Director of the Institute makes a revision pursuant to paragraph (1), the Director of OMB, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall update any policy or principle issued under subsection (b)(1) as necessary to ensure those policies and principles are consistent with the review and any revision under paragraph (1) under this subsection and paragraphs (2) and (3) of subsection (b). The Federal Acquisition Regulation shall be revised as necessary to implement any standards and guidelines promulgated in this section.

Verify at the official source: Federal legislative text

Facing this? Know exactly what happens next.

MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.

This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.