[Congressional Record Volume 164, Number 94 (Thursday, June 7, 2018)]
[Senate]
[Pages S3382-S3383]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2567. Mr. WARNER (for himself and Mr. Gardner) submitted an 
amendment intended to be proposed to amendment SA 2282 submitted by Mr. 
Inhofe (for himself and Mr. McCain) and intended to be proposed to the 
bill H.R. 5515, to authorize appropriations for fiscal year 2019 for 
military activities of the Department of Defense, for military 
construction, and for defense activities of the Department of Energy, 
to prescribe military personnel strengths for such fiscal year, and for 
other purposes; which was ordered to lie on the table; as follows:

       At the end of title X, add the following:

      Subtitle G--Internet of Things Cybersecurity Improvement Act

     SEC. 1071. SHORT TITLE.

       This subtitle may be cited as the ``Internet of Things 
     (IoT) Cybersecurity Improvement Act of 2018''.

     SEC. 1073. DEFINITIONS.

       In this subtitle:
       (1) Covered agency.--The term ``covered agency'' means--
       (A) the Department of Defense; and
       (B) the National Security Agency.
       (2) Covered device.--
       (A) In general.--The term ``covered device''--
       (i) means a physical object that--

       (I) is capable of connecting to and is in regular 
     connection with the Internet; and
       (II) has computer processing capabilities that can collect, 
     send, or receive data; and

       (ii) does not include advanced or general-purpose computing 
     devices, including personal computing systems, smart mobile 
     communications devices, programmable logic controls, and 
     mainframe computing systems.
       (B) Modification of definition.--The Secretary shall 
     establish a process by which--
       (i) interested parties may petition for a device that is 
     not described in subparagraph (A)(ii) to be considered a 
     device that is not a covered device; and
       (ii) the Secretary acts upon any petition submitted under 
     clause (i) in a timely manner.
       (3) Firmware.--The term ``firmware'' means a computer 
     program and the data stored in hardware, typically in read-
     only memory (ROM) or programmable read-only memory (PROM), 
     such that the program and data cannot be dynamically written 
     or modified during execution of the program.
       (4) Fixed or hard-coded credential.--The term ``fixed or 
     hard-coded credential'' means a value, such as a password, 
     token, cryptographic key, or other data element used as part 
     of an authentication mechanism for granting remote access to 
     an information system or its information, that is--
       (A) established by a product vendor or service provider; 
     and
       (B) incapable of being modified or revoked by the user or 
     manufacturer lawfully operating the information system, 
     except via a firmware update.
       (5) Hardware.--The term ``hardware'' means the physical 
     components of an information system.
       (6) IoT.--The term ``IoT'' means the Internet of Things.
       (7) NIST.--The term ``NIST'' means the National Institute 
     of Standards and Technology.
       (8) Properly authenticated update.--The term ``properly 
     authenticated update'' means an update, remediation, or 
     technical fix to a hardware, firmware, or software component 
     issued by a product vendor or service provider used to 
     correct particular problems with the component, and that, in 
     the case of software or firmware, contains some method of 
     authenticity protection, such as a digital signature, so that 
     unauthorized updates can be automatically detected and 
     rejected.
       (9) Secretary.--The term ``Secretary'' means the Secretary 
     of Defense.
       (10) Security vulnerability.--The term ``security 
     vulnerability'' means any attribute of hardware, firmware, 
     software, process, or procedure or combination of 2 or more 
     of these factors that could enable or facilitate the defeat 
     or compromise of the confidentiality, integrity, or 
     availability of an information system or its information or 
     physical devices to which it is connected.
       (11) Software.--The term ``software'' means a computer 
     program and associated data that may be dynamically written 
     or modified.

     SEC. 1074. CONTRACTOR RESPONSIBILITIES WITH RESPECT TO 
                   COVERED DEVICE CYBERSECURITY.

       (a) Standard Security Clause Required in Covered Devices.--
       (1) In general.--Not later than 180 days after the date of 
     enactment of this Act, the Secretary, in consultation with 
     the Administrator of General Services, the Secretary of 
     Commerce, the Secretary of Homeland Security, and any other 
     intelligence or national security agency that the Secretary 
     determines to be necessary, shall issue guidelines for each 
     covered agency to require the inclusion of a standard 
     security clause in any contract, except as provided in 
     paragraph (2), for the acquisition of covered devices.
       (2) Content of standard security clause.--The standard 
     security clause required under paragraph (1)--
       (A) shall establish baseline security requirements that 
     address aspects of device security, including--
       (i) the ability of software or firmware components to 
     accept properly authenticated and trusted updates from the 
     vendor;
       (ii) identity and access management, including prohibiting 
     the use of fixed or hard-coded credentials used for remote 
     administration, the delivery of updates, or communication;
       (iii) participation in a Coordinated Vulnerability 
     Disclosure program in accordance with subsection (f);
       (iv) such other aspects as the Secretary determines to be 
     appropriate; and
       (B) shall, to the maximum extent practicable, reflect and 
     align with voluntary consensus standards in effect on the 
     date of enactment of this Act;
       (C) shall require vendors to provide written attestation 
     that the device meets such requirements as established under 
     subparagraph (A);
       (D) shall, to the maximum extent practicable, ensure that 
     the requirements described in subparagraph (A) are--
       (i) tailored to address the characteristics of different 
     types of devices, including risk and intended function;
       (ii) based on technology-neutral, outcome-based security 
     principles;
       (iii) developed through a transparent process that 
     incorporates input from relevant stakeholders in industry and 
     academia;
       (iv) aligned with internationally recognized technical 
     standards; and
       (v) updated regularly based on developments in technology 
     and security methodologies;
       (E) shall identify responsibilities for ensuring that a 
     covered device software or firmware component is updated or 
     replaced, consistent with other provisions in the contract 
     governing the term of support, in a manner that allows for 
     any future security vulnerability or defect in any part of 
     the software or firmware to be patched, based on risk, in 
     order to fix or remove a vulnerability or defect in the 
     software or firmware component in a properly authenticated 
     and secure manner; and
       (F) shall require the contractor to provide the purchasing 
     agency with general information on the ability of the device 
     to be updated, such as--
       (i) the manner in which the device receives security 
     updates;
       (ii) the business terms, including any fees for ongoing 
     security support, under which security updates will be 
     provided for a covered device;
       (iii) the anticipated timeline for ending security support 
     associated with the covered device;
       (iv) formal notification when security support has ceased; 
     and
       (v) other information as determined necessary by the 
     Secretary.
       (3) Waiver.--The Secretary may establish a process for a 
     purchasing covered agency to waive the requirements described 
     in paragraph (2)(A) when a contractor submits a written 
     application for a waiver, if the process--
       (A) provides for waivers to be granted only in limited 
     circumstances, including--
       (i) if a vendor demonstrates that a device meets a desired 
     level of security through means other than those required 
     under paragraph (2)(A); or
       (ii) if the purchasing covered agency reasonably believes 
     that procurement of a covered device with limited data 
     processing and software functionality would be unfeasible or 
     economically impractical; and
       (B) provides that, if the head of the purchasing covered 
     agency approves a waiver, the head of the purchasing covered 
     agency shall provide the contractor a written statement that 
     the covered agency accepts risks resulting from use of the 
     device;
       (4) Alignment with fisma.--In issuing the guidelines 
     required under paragraph (1), the Secretary, in consultation 
     with the Administrator of General Services, shall ensure that 
     such guidelines are, to the greatest extent practicable, 
     consistent with, not duplicative of, and in compliance with 
     any applicable established information security policies, 
     procedures, standards, and compliance requirements under 
     chapter 35 of title 44, United States Code.
       (b) Alternate Conditions to Mitigate Cybersecurity Risks.--
       (1) In general.--Not later than 180 days after the date of 
     the enactment of this Act, the Secretary, in coordination 
     with NIST, shall establish a set of conditions that--
       (A) ensure that a covered device that does not comply with 
     the standard security clause under subsection (a) can be used 
     with a level of security that is equivalent to the level of 
     security described in subsection (a)(2); and
       (B) shall be met in order for a covered agency to purchase 
     a covered device described in subparagraph (A).
       (2) Requirements.--In defining a set of conditions that 
     must be met for non-compliant devices as required under 
     paragraph (1), the Secretary, in coordination with NIST and 
     relevant industry entities, may consider the use of 
     conditions including--
       (A) network segmentation or micro-segmentation;

[[Page S3383]]

       (B) the adoption of system level security controls, 
     including operating system containers and microservices;
       (C) multi-factor authentication; and
       (D) intelligent network solutions and edge systems, such as 
     gateways, that can isolate, disable, or remediate connected 
     devices.
       (3) Specification of additional precautions.--To address 
     the long-term risk of non-compliant covered devices acquired 
     in accordance with an exception under this paragraph, the 
     Secretary, in coordination with NIST and private-sector 
     industry experts, may stipulate additional requirements for 
     management and use of non-compliant devices, including 
     deadlines for the removal, replacement, or disabling of non-
     compliant devices (or their Internet-connectivity), as well 
     as minimal requirements for gateway products to ensure the 
     integrity and security of the non-compliant devices.
       (4) Existing third-party security standard.--
       (A) In general.--If an existing voluntary consensus 
     standard for the security of covered devices provides an 
     equivalent or greater level of security to that described in 
     subsection (a)(2)(A), the Secretary shall terminate the 
     requirements under subsection (a)(2)(A) and modify security 
     clauses to reflect conformity with that voluntary consensus 
     standard.
       (B) Written certification.--A contractor providing the 
     covered device under this paragraph shall provide third-party 
     written certification that the device complies with the 
     security requirements of the industry certification method of 
     the third party.
       (C) NIST.--The Director of NIST, in coordination with the 
     Secretary and other appropriate executive agencies, shall 
     determine--
       (i) accreditation standards for third-party certifiers; and
       (ii) whether the standards described in clause (i) provide 
     appropriate security and are aligned with the guidelines 
     issued under this subsection.
       (5) Existing agency security evaluation standards.--
       (A) In general.--If a covered agency employs a security 
     evaluation process or criteria for covered devices that the 
     agency believes provides an equivalent or greater level of 
     security to that described in subsection (a)(2)(A), a covered 
     agency may, upon the approval of the Secretary, continue to 
     use that process or standard in lieu of the requirements 
     under subsection (a)(2)(A).
       (B) NIST.--The Director of NIST, in coordination with the 
     Secretary and other appropriate executive agencies, shall 
     determine whether the process or criteria described in 
     subparagraph (A) provides appropriate security and are 
     aligned with the guidelines issued under this subsection.
       (c) Required Guidelines.--Not later than 180 days after the 
     date of enactment of this Act, the Secretary, in consultation 
     with the Administrator of General Services, shall issue 
     guidelines for each covered agency to limit, to the maximum 
     extent practicable, the use of lowest price technically 
     acceptable source selection criteria in the case of a 
     procurement that is predominately for the acquisition of a 
     covered device.
       (d) Report to Congress.--Not later than 5 years after the 
     date of enactment of this Act, the Secretary shall submit to 
     Congress a report on the effectiveness of the guidelines 
     required to be issued under subsections (a) and (c), which 
     shall include any recommendations for legislation necessary 
     to improve cybersecurity in Federal Government acquisition of 
     Internet-connected devices.
       (e) Waiver Authority.--Beginning on the date that is 5 
     years after the date of enactment of this Act, the Secretary 
     may waive, in whole or in part, the requirements of the 
     guidelines issued under this section, for a covered agency.
       (f) Guidelines Regarding the Coordinated Disclosure of 
     Security Vulnerabilities and Defects.--
       (1) In general.--Not later than 180 days after the date of 
     the enactment of this Act, the National Protection and 
     Programs Directorate, in consultation with cybersecurity 
     researchers and private-sector industry experts, shall issue 
     guidelines for each agency with respect to any covered device 
     in use by the United States Government regarding 
     cybersecurity coordinated disclosure requirements that shall 
     be required of contractors providing such covered devices to 
     the United States Government.
       (2) Contents.--The guidelines required to be issued under 
     paragraph (1) shall include policies and procedures for the 
     processing and resolving of potential vulnerability 
     information relating to a covered device, which shall be, to 
     the maximum extent practicable, aligned with Standards 29147 
     and 30111 of the International Standards Organization, or any 
     successor standard, such as--
       (A) procedures for a contractor providing a covered device 
     to the United States Government on how to--
       (i) receive information about potential vulnerabilities in 
     the product or online service of the contractor; and
       (ii) disseminate resolution information about 
     vulnerabilities in the product or online service of the 
     contractor; and
       (B) guidance, including example content, on the information 
     items that should be produced through the implementation of 
     the vulnerability disclosure process of the contractor.

     SEC. 1075. INVENTORY OF DEVICES.

       (a) In General.--Not later than 180 days after the date of 
     enactment of this Act, the head of each covered agency shall 
     establish and maintain an inventory of covered devices used 
     by the agency procured under this subtitle.
       (b) Guidelines.--Not later than 30 days after the date of 
     the enactment of this Act, the Secretary, in consultation 
     with the Secretary of Homeland Security, shall issue 
     guidelines for executive agencies to develop and manage the 
     inventories required under subsection (a), based on the 
     Continuous Diagnostics and Mitigation (CDM) program used by 
     the Department of Homeland Security.
       (c) Device Databases.--
       (1) In general.--Not later than 180 days after the date of 
     enactment of this Act, the Secretary shall establish and 
     maintain--
       (A) a database of devices and the respective manufacturers 
     of such devices for which limitations of liability exist 
     under this subtitle; and
       (B) a database of devices and the respective manufacturers 
     of such devices about which the Government has received 
     formal notification of security support ceasing, as required 
     under section 1074(a)(2)(G).
       (2) Updates.--The Secretary shall update the databases 
     established under paragraph (1) not less frequently than once 
     every 30 days.

     SEC. 1076. USE OF BEST PRACTICES IN IDENTIFICATION AND 
                   TRACKING OF VULNERABILITIES FOR PURPOSES OF THE 
                   NATIONAL VULNERABILITY DATABASE.

       The Director of NIST shall ensure that NIST establishes, 
     maintains, and uses best practices in the identification and 
     tracking of vulnerabilities for purposes of the National 
     Vulnerability Database of NIST.
                                 ______