[Congressional Record Volume 164, Number 94 (Thursday, June 7, 2018)]
[Senate]
[Pages S3382-S3383]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2567. Mr. WARNER (for himself and Mr. Gardner) submitted an
amendment intended to be proposed to amendment SA 2282 submitted by Mr.
Inhofe (for himself and Mr. McCain) and intended to be proposed to the
bill H.R. 5515, to authorize appropriations for fiscal year 2019 for
military activities of the Department of Defense, for military
construction, and for defense activities of the Department of Energy,
to prescribe military personnel strengths for such fiscal year, and for
other purposes; which was ordered to lie on the table; as follows:
At the end of title X, add the following:
Subtitle G--Internet of Things Cybersecurity Improvement Act
SEC. 1071. SHORT TITLE.
This subtitle may be cited as the ``Internet of Things
(IoT) Cybersecurity Improvement Act of 2018''.
SEC. 1073. DEFINITIONS.
In this subtitle:
(1) Covered agency.--The term ``covered agency'' means--
(A) the Department of Defense; and
(B) the National Security Agency.
(2) Covered device.--
(A) In general.--The term ``covered device''--
(i) means a physical object that--
(I) is capable of connecting to and is in regular
connection with the Internet; and
(II) has computer processing capabilities that can collect,
send, or receive data; and
(ii) does not include advanced or general-purpose computing
devices, including personal computing systems, smart mobile
communications devices, programmable logic controls, and
mainframe computing systems.
(B) Modification of definition.--The Secretary shall
establish a process by which--
(i) interested parties may petition for a device that is
not described in subparagraph (A)(ii) to be considered a
device that is not a covered device; and
(ii) the Secretary acts upon any petition submitted under
clause (i) in a timely manner.
(3) Firmware.--The term ``firmware'' means a computer
program and the data stored in hardware, typically in read-
only memory (ROM) or programmable read-only memory (PROM),
such that the program and data cannot be dynamically written
or modified during execution of the program.
(4) Fixed or hard-coded credential.--The term ``fixed or
hard-coded credential'' means a value, such as a password,
token, cryptographic key, or other data element used as part
of an authentication mechanism for granting remote access to
an information system or its information, that is--
(A) established by a product vendor or service provider;
and
(B) incapable of being modified or revoked by the user or
manufacturer lawfully operating the information system,
except via a firmware update.
(5) Hardware.--The term ``hardware'' means the physical
components of an information system.
(6) IoT.--The term ``IoT'' means the Internet of Things.
(7) NIST.--The term ``NIST'' means the National Institute
of Standards and Technology.
(8) Properly authenticated update.--The term ``properly
authenticated update'' means an update, remediation, or
technical fix to a hardware, firmware, or software component
issued by a product vendor or service provider used to
correct particular problems with the component, and that, in
the case of software or firmware, contains some method of
authenticity protection, such as a digital signature, so that
unauthorized updates can be automatically detected and
rejected.
(9) Secretary.--The term ``Secretary'' means the Secretary
of Defense.
(10) Security vulnerability.--The term ``security
vulnerability'' means any attribute of hardware, firmware,
software, process, or procedure or combination of 2 or more
of these factors that could enable or facilitate the defeat
or compromise of the confidentiality, integrity, or
availability of an information system or its information or
physical devices to which it is connected.
(11) Software.--The term ``software'' means a computer
program and associated data that may be dynamically written
or modified.
SEC. 1074. CONTRACTOR RESPONSIBILITIES WITH RESPECT TO
COVERED DEVICE CYBERSECURITY.
(a) Standard Security Clause Required in Covered Devices.--
(1) In general.--Not later than 180 days after the date of
enactment of this Act, the Secretary, in consultation with
the Administrator of General Services, the Secretary of
Commerce, the Secretary of Homeland Security, and any other
intelligence or national security agency that the Secretary
determines to be necessary, shall issue guidelines for each
covered agency to require the inclusion of a standard
security clause in any contract, except as provided in
paragraph (2), for the acquisition of covered devices.
(2) Content of standard security clause.--The standard
security clause required under paragraph (1)--
(A) shall establish baseline security requirements that
address aspects of device security, including--
(i) the ability of software or firmware components to
accept properly authenticated and trusted updates from the
vendor;
(ii) identity and access management, including prohibiting
the use of fixed or hard-coded credentials used for remote
administration, the delivery of updates, or communication;
(iii) participation in a Coordinated Vulnerability
Disclosure program in accordance with subsection (f);
(iv) such other aspects as the Secretary determines to be
appropriate; and
(B) shall, to the maximum extent practicable, reflect and
align with voluntary consensus standards in effect on the
date of enactment of this Act;
(C) shall require vendors to provide written attestation
that the device meets such requirements as established under
subparagraph (A);
(D) shall, to the maximum extent practicable, ensure that
the requirements described in subparagraph (A) are--
(i) tailored to address the characteristics of different
types of devices, including risk and intended function;
(ii) based on technology-neutral, outcome-based security
principles;
(iii) developed through a transparent process that
incorporates input from relevant stakeholders in industry and
academia;
(iv) aligned with internationally recognized technical
standards; and
(v) updated regularly based on developments in technology
and security methodologies;
(E) shall identify responsibilities for ensuring that a
covered device software or firmware component is updated or
replaced, consistent with other provisions in the contract
governing the term of support, in a manner that allows for
any future security vulnerability or defect in any part of
the software or firmware to be patched, based on risk, in
order to fix or remove a vulnerability or defect in the
software or firmware component in a properly authenticated
and secure manner; and
(F) shall require the contractor to provide the purchasing
agency with general information on the ability of the device
to be updated, such as--
(i) the manner in which the device receives security
updates;
(ii) the business terms, including any fees for ongoing
security support, under which security updates will be
provided for a covered device;
(iii) the anticipated timeline for ending security support
associated with the covered device;
(iv) formal notification when security support has ceased;
and
(v) other information as determined necessary by the
Secretary.
(3) Waiver.--The Secretary may establish a process for a
purchasing covered agency to waive the requirements described
in paragraph (2)(A) when a contractor submits a written
application for a waiver, if the process--
(A) provides for waivers to be granted only in limited
circumstances, including--
(i) if a vendor demonstrates that a device meets a desired
level of security through means other than those required
under paragraph (2)(A); or
(ii) if the purchasing covered agency reasonably believes
that procurement of a covered device with limited data
processing and software functionality would be unfeasible or
economically impractical; and
(B) provides that, if the head of the purchasing covered
agency approves a waiver, the head of the purchasing covered
agency shall provide the contractor a written statement that
the covered agency accepts risks resulting from use of the
device;
(4) Alignment with fisma.--In issuing the guidelines
required under paragraph (1), the Secretary, in consultation
with the Administrator of General Services, shall ensure that
such guidelines are, to the greatest extent practicable,
consistent with, not duplicative of, and in compliance with
any applicable established information security policies,
procedures, standards, and compliance requirements under
chapter 35 of title 44, United States Code.
(b) Alternate Conditions to Mitigate Cybersecurity Risks.--
(1) In general.--Not later than 180 days after the date of
the enactment of this Act, the Secretary, in coordination
with NIST, shall establish a set of conditions that--
(A) ensure that a covered device that does not comply with
the standard security clause under subsection (a) can be used
with a level of security that is equivalent to the level of
security described in subsection (a)(2); and
(B) shall be met in order for a covered agency to purchase
a covered device described in subparagraph (A).
(2) Requirements.--In defining a set of conditions that
must be met for non-compliant devices as required under
paragraph (1), the Secretary, in coordination with NIST and
relevant industry entities, may consider the use of
conditions including--
(A) network segmentation or micro-segmentation;
[[Page S3383]]
(B) the adoption of system level security controls,
including operating system containers and microservices;
(C) multi-factor authentication; and
(D) intelligent network solutions and edge systems, such as
gateways, that can isolate, disable, or remediate connected
devices.
(3) Specification of additional precautions.--To address
the long-term risk of non-compliant covered devices acquired
in accordance with an exception under this paragraph, the
Secretary, in coordination with NIST and private-sector
industry experts, may stipulate additional requirements for
management and use of non-compliant devices, including
deadlines for the removal, replacement, or disabling of non-
compliant devices (or their Internet-connectivity), as well
as minimal requirements for gateway products to ensure the
integrity and security of the non-compliant devices.
(4) Existing third-party security standard.--
(A) In general.--If an existing voluntary consensus
standard for the security of covered devices provides an
equivalent or greater level of security to that described in
subsection (a)(2)(A), the Secretary shall terminate the
requirements under subsection (a)(2)(A) and modify security
clauses to reflect conformity with that voluntary consensus
standard.
(B) Written certification.--A contractor providing the
covered device under this paragraph shall provide third-party
written certification that the device complies with the
security requirements of the industry certification method of
the third party.
(C) NIST.--The Director of NIST, in coordination with the
Secretary and other appropriate executive agencies, shall
determine--
(i) accreditation standards for third-party certifiers; and
(ii) whether the standards described in clause (i) provide
appropriate security and are aligned with the guidelines
issued under this subsection.
(5) Existing agency security evaluation standards.--
(A) In general.--If a covered agency employs a security
evaluation process or criteria for covered devices that the
agency believes provides an equivalent or greater level of
security to that described in subsection (a)(2)(A), a covered
agency may, upon the approval of the Secretary, continue to
use that process or standard in lieu of the requirements
under subsection (a)(2)(A).
(B) NIST.--The Director of NIST, in coordination with the
Secretary and other appropriate executive agencies, shall
determine whether the process or criteria described in
subparagraph (A) provides appropriate security and are
aligned with the guidelines issued under this subsection.
(c) Required Guidelines.--Not later than 180 days after the
date of enactment of this Act, the Secretary, in consultation
with the Administrator of General Services, shall issue
guidelines for each covered agency to limit, to the maximum
extent practicable, the use of lowest price technically
acceptable source selection criteria in the case of a
procurement that is predominately for the acquisition of a
covered device.
(d) Report to Congress.--Not later than 5 years after the
date of enactment of this Act, the Secretary shall submit to
Congress a report on the effectiveness of the guidelines
required to be issued under subsections (a) and (c), which
shall include any recommendations for legislation necessary
to improve cybersecurity in Federal Government acquisition of
Internet-connected devices.
(e) Waiver Authority.--Beginning on the date that is 5
years after the date of enactment of this Act, the Secretary
may waive, in whole or in part, the requirements of the
guidelines issued under this section, for a covered agency.
(f) Guidelines Regarding the Coordinated Disclosure of
Security Vulnerabilities and Defects.--
(1) In general.--Not later than 180 days after the date of
the enactment of this Act, the National Protection and
Programs Directorate, in consultation with cybersecurity
researchers and private-sector industry experts, shall issue
guidelines for each agency with respect to any covered device
in use by the United States Government regarding
cybersecurity coordinated disclosure requirements that shall
be required of contractors providing such covered devices to
the United States Government.
(2) Contents.--The guidelines required to be issued under
paragraph (1) shall include policies and procedures for the
processing and resolving of potential vulnerability
information relating to a covered device, which shall be, to
the maximum extent practicable, aligned with Standards 29147
and 30111 of the International Standards Organization, or any
successor standard, such as--
(A) procedures for a contractor providing a covered device
to the United States Government on how to--
(i) receive information about potential vulnerabilities in
the product or online service of the contractor; and
(ii) disseminate resolution information about
vulnerabilities in the product or online service of the
contractor; and
(B) guidance, including example content, on the information
items that should be produced through the implementation of
the vulnerability disclosure process of the contractor.
SEC. 1075. INVENTORY OF DEVICES.
(a) In General.--Not later than 180 days after the date of
enactment of this Act, the head of each covered agency shall
establish and maintain an inventory of covered devices used
by the agency procured under this subtitle.
(b) Guidelines.--Not later than 30 days after the date of
the enactment of this Act, the Secretary, in consultation
with the Secretary of Homeland Security, shall issue
guidelines for executive agencies to develop and manage the
inventories required under subsection (a), based on the
Continuous Diagnostics and Mitigation (CDM) program used by
the Department of Homeland Security.
(c) Device Databases.--
(1) In general.--Not later than 180 days after the date of
enactment of this Act, the Secretary shall establish and
maintain--
(A) a database of devices and the respective manufacturers
of such devices for which limitations of liability exist
under this subtitle; and
(B) a database of devices and the respective manufacturers
of such devices about which the Government has received
formal notification of security support ceasing, as required
under section 1074(a)(2)(G).
(2) Updates.--The Secretary shall update the databases
established under paragraph (1) not less frequently than once
every 30 days.
SEC. 1076. USE OF BEST PRACTICES IN IDENTIFICATION AND
TRACKING OF VULNERABILITIES FOR PURPOSES OF THE
NATIONAL VULNERABILITY DATABASE.
The Director of NIST shall ensure that NIST establishes,
maintains, and uses best practices in the identification and
tracking of vulnerabilities for purposes of the National
Vulnerability Database of NIST.
______