<?xml version="1.0" encoding="UTF-8"?><BillSummaries>
<item congress="116" measure-type="hr" measure-number="1668" measure-id="id116hr1668" originChamber="HOUSE" orig-publish-date="2019-03-11" update-date="2020-12-14">
<title>IoT Cybersecurity Improvement Act of 2020</title>
<summary summary-id="id116hr1668v49" currentChamber="BOTH" update-date="2020-12-14">
<action-date>2020-12-04</action-date>
<action-desc>Public Law</action-desc>
<summary-text><![CDATA[<p><b>Internet of Things Cybersecurity Improvement Act of 2020 or the IoT Cybersecurity Improvement Act of 2020</b></p> <p>This bill requires the National Institute of Standards and Technology (NIST) and the Office of Management and Budget (OMB) to take specified steps to increase cybersecurity for Internet of Things (IoT) devices. IoT is the extension of internet connectivity into physical devices and everyday objects.</p> <p>Specifically, the bill requires NIST to develop and publish standards and guidelines for the federal government on the appropriate use and management by agencies of IoT devices owned or controlled by an agency and connected to information systems owned or controlled by an agency, including minimum information security requirements for managing cybersecurity risks associated with such devices.</p> <p>The bill requires the OMB to review agency information security policies and principles on the basis of the NIST standards and guidelines and issue such policies and principles as necessary to ensure the agency policies and principles are consistent with the NIST standards and guidelines. </p> <p>NIST shall review and revise, as appropriate, the standards and guidelines every five years. The OMB shall update any policy or principle to be consistent with NIST revisions. </p> <p>NIST shall develop and publish guidelines for agency, contractor, and subcontractor communications regarding security vulnerabilities.</p><p>The OMB shall develop and oversee the implementation of policies, principles, standards, or guidelines as necessary to address security vulnerabilities of information systems. </p><p>An agency is prohibited from procuring, obtaining, or using an IoT device if the agency determines during a review of a contract that the use of such device prevents compliance with the standards and guidelines, subject to a waiver where necessary for national security, for research purposes, or where such device is secured using alternative effective methods. </p><p>The Government Accountability Office shall report to Congress on broader IoT efforts.</p>]]></summary-text>
</summary>
<summary summary-id="id116hr1668v55" currentChamber="SENATE" update-date="2020-12-14">
<action-date>2020-11-17</action-date>
<action-desc>Passed Senate</action-desc>
<summary-text><![CDATA[<p><b>Internet of Things Cybersecurity Improvement Act of 2020 or the IoT Cybersecurity Improvement Act of 2020</b></p> <p>This bill requires the National Institute of Standards and Technology (NIST) and the Office of Management and Budget (OMB) to take specified steps to increase cybersecurity for Internet of Things (IoT) devices. IoT is the extension of internet connectivity into physical devices and everyday objects.</p> <p>Specifically, the bill requires NIST to develop and publish standards and guidelines for the federal government on the appropriate use and management by agencies of IoT devices owned or controlled by an agency and connected to information systems owned or controlled by an agency, including minimum information security requirements for managing cybersecurity risks associated with such devices.</p> <p>The bill requires the OMB to review agency information security policies and principles on the basis of the NIST standards and guidelines and issue such policies and principles as necessary to ensure the agency policies and principles are consistent with the NIST standards and guidelines. </p> <p>NIST shall review and revise, as appropriate, the standards and guidelines every five years. The OMB shall update any policy or principle to be consistent with NIST revisions. </p> <p>NIST shall develop and publish guidelines for agency, contractor, and subcontractor communications regarding security vulnerabilities.</p><p>The OMB shall develop and oversee the implementation of policies, principles, standards, or guidelines as necessary to address security vulnerabilities of information systems. </p><p>An agency is prohibited from procuring, obtaining, or using an IoT device if the agency determines during a review of a contract that the use of such device prevents compliance with the standards and guidelines, subject to a waiver where necessary for national security, for research purposes, or where such device is secured using alternative effective methods. </p><p>The Government Accountability Office shall report to Congress on broader IoT efforts.</p>]]></summary-text>
</summary>
<summary summary-id="id116hr1668v53" currentChamber="HOUSE" update-date="2020-12-14">
<action-date>2020-09-14</action-date>
<action-desc>Passed House</action-desc>
<summary-text><![CDATA[<p><b>Internet of Things Cybersecurity Improvement Act of 2020 or the IoT Cybersecurity Improvement Act of 2020</b> </p> </p> <p>This bill requires the National Institute of Standards and Technology (NIST) and the Office of Management and Budget (OMB) to take specified steps to increase cybersecurity for Internet of Things (IoT) devices. IoT is the extension of internet connectivity into physical devices and everyday objects.</p> <p>Specifically, the bill requires NIST to develop and publish standards and guidelines for the federal government on the appropriate use and management by agencies of IoT devices owned or controlled by an agency and connected to information systems owned or controlled by an agency, including minimum information security requirements for managing cybersecurity risks associated with such devices.</p> <p>The bill requires the OMB to review agency information security policies and principles on the basis of the NIST standards and guidelines and issue such policies and principles as necessary to ensure the agency policies and principles are consistent with the NIST standards and guidelines. </p> <p>NIST shall review and revise, as appropriate, the standards and guidelines every five years. The OMB shall update any policy or principle to be consistent with NIST revisions. </p> <p>NIST shall develop and publish guidelines for agency, contractor, and subcontractor communications regarding security vulnerabilities.</p><p>The OMB shall develop and oversee the implementation of policies, principles, standards, or guidelines as necessary to address security vulnerabilities of information systems. </p><p>An agency is prohibited from procuring, obtaining, or using an IoT device if the agency determines during a review of a contract that the use of such device prevents compliance with the standards and guidelines, subject to a waiver where necessary for national security, for research purposes, or where such device is secured using alternative effective methods. </p><p>The Government Accountability Office shall report to Congress on broader IoT efforts.</p>]]></summary-text>
</summary>
<summary summary-id="id116hr1668v00" currentChamber="HOUSE" update-date="2020-12-11">
<action-date>2019-03-11</action-date>
<action-desc>Introduced in House</action-desc>
<summary-text><![CDATA[<p><b>Internet of Things Cybersecurity Improvement Act of 2019 or the IoT Cybersecurity Improvement Act of 2019</b></p> <p>This bill requires the National Institute of Standards and Technology (NIST) and the Office of Management and Budget (OMB) to take specified steps to increase cybersecurity for Internet of Things (IoT) devices. IoT is the extension of internet connectivity into physical devices and everyday objects.</p> <p>The bill establishes September 30, 2019, as the deadline for the completion of NIST's efforts regarding considerations for managing IoT cybersecurity risks, especially regarding examples of possible cybersecurity capabilities of IoT devices. By March 31, 2020, NIST must develop recommendations for the appropriate use and management of IoT devices owned or controlled by the government, including minimum information security requirements for managing cybersecurity risks.</p> <p>The OMB shall then issue guidelines for each agency that are consistent with such recommendations.</p> <p>NIST and the OMB shall publish guidance on policies and procedures for the reporting, coordinating, publishing, and receiving of information about a security vulnerability relating to an IoT device used by the government and the resolution of such security vulnerability.</p>]]></summary-text>
</summary>
</item>
<dublinCore xmlns:dc="http://purl.org/dc/elements/1.1/">
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
<dc:contributor>Congressional Research Service, Library of Congress</dc:contributor>
<dc:description>This file contains bill summaries for federal legislation. A bill summary describes the most significant provisions of a piece of legislation and details the effects the legislative text may have on current law and federal programs. Bill summaries are authored by the Congressional Research Service (CRS) of the Library of Congress. As stated in Public Law 91-510 (2 USC 166 (d)(6)), one of the duties of CRS is "to prepare summaries and digests of bills and resolutions of a public general nature introduced in the Senate or House of Representatives". For more information, refer to the User Guide that accompanies this file.</dc:description>
</dublinCore>
</BillSummaries>
