News

Bill that requires security standards for government purchases of IoT devices signed into law

Legislation requiring security standards for any Internet of Things (IoT) device purchased with government money was signed into law this week.

The IoT Cybersecurity Improvement Act, introduced by Reps. Will Hurd (R-TX) and Robin Kelly (D-IL), requires the National Institute of Standards and Technology (NIST) to publish standards and guidelines on the use and management of IoT devices by the federal government. This should include minimum information security requirements for managing cybersecurity risks associated with IoT devices. The law also directs the Office of Management and Budget (OMB) to review federal government information security policies and make any necessary changes to ensure they are consistent with NIST’s recommendations. Also, NIST and OMB are required to update IoT security standards, guidelines, and policies at least every five years.

“My philosophy is simple and has remained the same: the only way we get big things done in Congress is by working together. My bipartisan effort with Rep. Kelly to ensure taxpayer dollars are only being used to purchase IoT devices that meet basic, minimum security requirements is the perfect example of that,” Hurd said. “While IoT devices improve and enhance nearly every aspect of our society, economy, and everyday lives, these devices must be secure in order to protect Americans’ personal data. I’m proud this is my 17th piece of legislation to be signed into law in 5 years, and I’m working to add to that number before the end of my term.”

The law also prohibits the procurement or use by federal agencies of IoT devices that do not comply with these security requirements. It also directs the OMB to develop and implement policies necessary to address security vulnerabilities relating to federal agency information systems, including IoT devices, consistent with NIST’s guidelines.
Require contractors providing IoT devices to the U.S. government to adopt coordinated vulnerability

“The bipartisan Internet of Things Cybersecurity Improvement Act is a critical step towards strengthening U.S. government IT systems and will help officials patch existing vulnerabilities to protect our national security and the personal information of American families,” Kelly said. “This law would not have been possible without the leadership of Senators Warner and Gardner passing it through the Senate and Representative Hurd through the House. This is a perfect example of two sides coming together to make our country more secure and prosperous.”

Dave Kovaleski

Recent Posts

New Raytheon advanced ground system gives U.S. advanced warning for space-based missiles

Thanks to work by Raytheon, an advanced new ground system for space-based missile warning recently…

1 day ago

FBI Report: Older population hit by more than $3.4B in scam losses in 2023

According to the latest Elder Fraud Report from the Federal Bureau of Investigation (FBI), 2023…

1 day ago

Protect and Serve Act would elevate the harming or attempted harm of law enforcement to a federal crime

Following the deaths of four police officers while executing an arrest warrant in North Carolina…

2 days ago

U.S. Reps. Steil, Dean introduce legislation to target human trafficking among other countries

As a way to crackdown on human trafficking, two U.S. representatives recently introduced the Exposing…

2 days ago

DoD challenge brings opportunities for nine new ideas in talent management

A Department of Defense (DoD) 2040 Task Force (D2T) challenge on talent management innovation drew…

5 days ago

TSA publishes final rule on Flight Training Security Program improvements

For the first time since its creation in 2004, the Transportation Security Administration’s (TSA) Flight…

5 days ago

This website uses cookies.