[Congressional Record Volume 164, Number 97 (Tuesday, June 12, 2018)]
[Senate]
[Pages S3849-S3851]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2825. Mr. GARDNER (for himself and Mr. Warner) submitted an 
amendment intended to be proposed to amendment SA 2282 proposed by Mr. 
Inhofe (for himself and Mr. McCain) to the bill H.R. 5515, to authorize 
appropriations for fiscal year 2019 for military activities of the 
Department of Defense, for military construction, and for defense 
activities of the Department of Energy, to prescribe military personnel 
strengths for such fiscal year, and for other purposes; which was 
ordered to lie on the table; as follows:

       At the end of title X, add the following:

      Subtitle G--Internet of Things Cybersecurity Improvement Act

     SEC. 1071. SHORT TITLE.

       This subtitle may be cited as the ``Internet of Things 
     (IoT) Cybersecurity Improvement Act of 2018''.

     SEC. 1072. DEFINITIONS; RULE OF CONSTRUCTION.

       (a) Definitions.--In this subtitle:
       (1) Covered device.--
       (A) In general.--Subject to subparagraph (B), the term 
     ``covered device''--
       (i) means a physical object that--

       (I) is capable of connecting to and is in regular 
     connection with the Internet or internal networks of the 
     Department that are connected to the Internet; and
       (II) has computer processing capabilities that can collect, 
     send, or receive data; and

       (ii) does not include advanced or general-purpose computing 
     devices, including personal computing systems, smart mobile 
     communications devices, programmable logic controls, 
     mainframe computing systems, and motor vehicles.
       (B) Modification of definition.--
       (i) In general.--The Secretary may modify the definition of 
     the term ``covered device'' in order to expand or narrow the 
     definition.
       (ii) Interested parties.--The Secretary shall establish a 
     process by which--

       (I) interested parties may petition the Integrating 
     Official described in section 1625 for a device that is not 
     described in subparagraph (A)(ii) to be considered a device 
     that is not a covered device; and
       (II) the Secretary, acting through the Integrating 
     Official, acts upon any petition submitted under subclause 
     (I) in a timely manner.

       (2) Department.--The term ``Department'' means the 
     Department of Defense.
       (3) Firmware.--The term ``firmware'' means a computer 
     program and the data stored in hardware, typically in read-
     only memory (ROM) or programmable read-only memory (PROM), 
     such that the program and data cannot be dynamically written 
     or modified during execution of the program.
       (4) Fixed or hard-coded credential.--The term ``fixed or 
     hard-coded credential'' means a value, such as a password, 
     token, cryptographic key, or other data element used as part 
     of an authentication mechanism for granting remote access to 
     an information system or its information, that is--
       (A) established by a product vendor or service provider;
       (B) incapable of being modified or revoked by the user or 
     manufacturer lawfully operating the information system, 
     except via a firmware update; and
       (C) not unique to each covered device.
       (5) Hardware.--The term ``hardware'' means the physical 
     components of an information system.
       (6) IoT.--The term ``IoT'' means the Internet of Things.
       (7) NIST.--The term ``NIST'' means the National Institute 
     of Standards and Technology.
       (8) Properly authenticated update.--The term ``properly 
     authenticated update''

[[Page S3850]]

     means an update, remediation, or technical fix to a hardware, 
     firmware, or software component issued by a product vendor or 
     service provider used to correct particular problems with the 
     component, and that, in the case of software or firmware, 
     contains some method of authenticity protection, such as a 
     digital signature, so that unauthorized updates can be 
     automatically detected and rejected.
       (9) Secretary.--The term ``Secretary'' means the Secretary 
     of Defense.
       (10) Security vulnerability.--The term ``security 
     vulnerability'' means any attribute of hardware, firmware, 
     software, process, or procedure or combination of 2 or more 
     of these factors that could enable or facilitate the defeat 
     or compromise of the confidentiality, integrity, or 
     availability of an information system or its information or 
     physical devices to which it is connected.
       (11) Software.--The term ``software'' means a computer 
     program and associated data that may be dynamically written 
     or modified.
       (b) Rule of Construction.--Nothing in this subtitle shall 
     be construed to expand the authority or jurisdiction of NIST.

     SEC. 1073. CONTRACTOR RESPONSIBILITIES WITH RESPECT TO 
                   COVERED DEVICE CYBERSECURITY.

       (a) Standard Security Clause Required in Covered Devices.--
       (1) In general.--Not later than 180 days after the date of 
     enactment of this Act, the Secretary, in consultation with 
     NIST, shall issue guidelines for the Department to require 
     the inclusion of a standard security clause in any contract, 
     except as provided in paragraph (2), paragraph (3), and 
     subsection (b), for the acquisition of covered devices.
       (2) Content of standard security clause.--The standard 
     security clause required under paragraph (1)--
       (A) shall establish baseline security requirements that 
     address aspects of device security, including--
       (i) the ability of software or firmware components to 
     accept properly authenticated and trusted updates from the 
     vendor;
       (ii) identity and access management, including prohibiting 
     the use of fixed or hard-coded credentials used for remote 
     administration, the delivery of updates, or communication;
       (iii) participation in a Coordinated Vulnerability 
     Disclosure program in accordance with subsection (f);
       (iv) such other aspects as the Secretary determines to be 
     appropriate; and
       (B) shall, to the maximum extent practicable, reflect and 
     align with voluntary consensus standards in effect on the 
     date of enactment of this Act;
       (C) shall require vendors to provide written attestation 
     that the device meets such requirements as established under 
     subparagraph (A);
       (D) shall, to the maximum extent practicable, ensure that 
     the requirements described in subparagraph (A) are--
       (i) tailored to address the characteristics of different 
     types of devices, including risk and intended function;
       (ii) based on technology-neutral, outcome-based security 
     principles;
       (iii) developed through a transparent process that 
     incorporates input from relevant stakeholders in industry and 
     academia; and
       (iv) updated regularly based on developments in technology 
     and security methodologies;
       (E) shall identify responsibilities for ensuring that a 
     covered device software or firmware component is updated or 
     replaced, consistent with other provisions in the contract 
     governing the term of support, in a manner that allows for 
     any future security vulnerability or defect in any part of 
     the software or firmware to be patched, based on risk, in 
     order to fix or remove a vulnerability or defect in the 
     software or firmware component in a properly authenticated 
     and secure manner; and
       (F) shall require the contractor to provide the Department 
     with general information on the ability of the device to be 
     updated, such as--
       (i) the manner in which the device receives security 
     updates;
       (ii) the business terms, including any fees for ongoing 
     security support, under which security updates will be 
     provided for a covered device;
       (iii) the anticipated timeline for ending security support 
     associated with the covered device;
       (iv) formal notification when security support has ceased; 
     and
       (v) other information as determined necessary by the 
     Secretary.
       (3) Waiver.--The Secretary may establish a process for the 
     Department to waive the requirements described in paragraph 
     (2)(A) when a component of the Department submits a written 
     application for a waiver, if the process--
       (A) provides for waivers to be granted only in limited 
     circumstances, including--
       (i) if a vendor demonstrates that a device meets a desired 
     level of security through means other than those required 
     under paragraph (2)(A); or
       (ii) if the purchasing component of the Department 
     reasonably believes that procurement of a covered device with 
     limited data processing and software functionality would be 
     unfeasible or economically impractical; and
       (B) provides that, if the Secretary approves a waiver, the 
     head of the purchasing component of the Department shall 
     provide the contractor a written statement that the 
     Department accepts risks resulting from use of the device.
       (4) Alignment with fisma.--In issuing the guidelines 
     required under paragraph (1), the Secretary shall ensure that 
     such guidelines are, to the greatest extent practicable, 
     consistent with, not duplicative of, and in compliance with 
     any applicable established information security policies, 
     procedures, standards, and compliance requirements under 
     chapter 35 of title 44, United States Code.
       (b) Alternate Conditions to Mitigate Cybersecurity Risks.--
       (1) In general.--Not later than 180 days after the date of 
     the enactment of this Act, the Secretary, in consultation 
     with NIST, shall establish a set of conditions that--
       (A) ensure that a covered device that does not comply with 
     the standard security clause under subsection (a) can be used 
     with a level of security that is equivalent to the level of 
     security described in subsection (a)(2); and
       (B) shall be met in order for a Department to purchase a 
     covered device described in subparagraph (A).
       (2) Requirements.--In defining a set of conditions that 
     must be met for non-compliant devices as required under 
     paragraph (1), the Secretary, in consultation with NIST, may 
     consider the use of conditions and information security 
     products such as those described in the relation to the 
     security integration framework established in section 1631, 
     including--
       (A) network segmentation or micro-segmentation;
       (B) the adoption of system level security controls, 
     including operating system containers and microservices;
       (C) multi-factor authentication; and
       (D) intelligent network solutions and edge systems, such as 
     gateways, that can isolate, disable, or remediate connected 
     devices.
       (3) Specification of additional precautions.--To address 
     the long-term risk of non-compliant covered devices acquired 
     in accordance with an exception under this paragraph, the 
     Secretary, in consultation with NIST and taking into 
     consideration frameworks set forth by NIST, may stipulate 
     additional requirements for management and use of non-
     compliant devices, including deadlines for the removal, 
     replacement, or disabling of non-compliant devices (or their 
     Internet-connectivity), as well as minimal requirements for 
     gateway products to ensure the integrity and security of the 
     non-compliant devices.
       (4) Existing third-party security standard.--
       (A) In general.--If an existing voluntary consensus 
     standard for the security of covered devices provides an 
     equivalent or greater level of security to that described in 
     subsection (a)(2)(A), the Secretary shall modify the required 
     security clauses to reflect conformity with that voluntary 
     consensus standard.
       (B) Written certification.--A contractor providing the 
     covered device under this paragraph shall provide self-
     attested written certification that the device complies with 
     the security requirements of the industry certification 
     method of the third party.
       (C) Accreditation standards.--The Secretary shall determine 
     accreditation standards for third-party certification of 
     compliance with voluntary consensus standards described in 
     subparagraph (A).
       (5) Existing security evaluation standards.--
       (A) In general.--If a component of the Department employs 
     or proposes to employ a security evaluation process or 
     criteria for covered devices that the component believes 
     provides an equivalent or greater level of security to that 
     described in subsection (a)(2)(A), the component may, upon 
     the approval of the Secretary, employ or adopt that process 
     or criteria in lieu of the requirements under subsection 
     (a)(2)(A).
       (B) Approval.--The Secretary shall determine whether the 
     process or criteria described in subparagraph (A) provides 
     appropriate security and is aligned with the guidelines 
     issued under this subsection.
       (c) Required Guidelines.--Not later than 180 days after the 
     date of enactment of this Act, the Secretary shall issue 
     guidelines for the Department to limit, to the maximum extent 
     practicable, the use of lowest price technically acceptable 
     source selection criteria in the case of a procurement that 
     is predominately for the acquisition of a covered device.
       (d) Report to Congress.--Not later than 5 years after the 
     date of enactment of this Act, the Secretary shall submit to 
     Congress a report on the effectiveness of the guidelines 
     required to be issued under subsections (a) and (c), which 
     shall include any recommendations for legislation necessary 
     to improve cybersecurity in the acquisition of Internet-
     connected devices by the Department.
       (e) Waiver Authority.--Beginning on the date that is 5 
     years after the date of enactment of this Act, the Secretary 
     may waive, in whole or in part, the requirements of the 
     guidelines issued under this section, for the Department.
       (f) Guidelines Regarding the Coordinated Disclosure of 
     Security Vulnerabilities and Defects.--
       (1) In general.--Not later than 180 days after the date of 
     the enactment of this Act,

[[Page S3851]]

     the Secretary, in consultation with cybersecurity researchers 
     and private-sector industry experts, shall issue guidelines 
     for the Department with respect to any covered device in use 
     by the Department regarding cybersecurity coordinated 
     disclosure requirements that shall be required of contractors 
     providing such covered devices to the Department.
       (2) Contents.--The guidelines required to be issued under 
     paragraph (1) shall include policies and procedures for the 
     processing and resolving of potential vulnerability 
     information relating to a covered device, which shall be, to 
     the maximum extent practicable, aligned with Standards 29147 
     and 30111 of the International Standards Organization, or any 
     successor standard, such as--
       (A) procedures for a contractor providing a covered device 
     to the Department on how to--
       (i) receive information about potential vulnerabilities in 
     the product or online service of the contractor; and
       (ii) disseminate resolution information about 
     vulnerabilities in the product or online service of the 
     contractor; and
       (B) guidance, including example content, on the information 
     items that should be produced through the implementation of 
     the vulnerability disclosure process of the contractor.
       (3) Requirement.--Consistent with section 1626, the 
     Secretary shall develop mechanisms to provide assistance to 
     help small manufacturers of covered devices set up 
     coordinated vulnerability disclosure programs under this 
     subsection, including assistance in establishing processes 
     for intake, handling, and remediation of security 
     vulnerabilities.

     SEC. 1074. INVENTORY OF DEVICES.

       (a) In General.--Not later than 180 days after the date of 
     enactment of this Act, the Secretary shall establish and 
     maintain an inventory of covered devices used by the 
     Department procured under this subtitle.
       (b) Guidelines.--Not later than 90 days after the date of 
     the enactment of this Act, the Secretary shall issue 
     guidelines for the Department to develop and manage the 
     inventories required under subsection (a).
       (c) Device Databases.--
       (1) In general.--Not later than 180 days after the date of 
     enactment of this Act, the Secretary shall establish and 
     maintain a database of devices and the respective 
     manufacturers of such devices about which the Government has 
     received formal notification of security support ceasing, as 
     required under section 1073(a)(2)(F).
       (2) Requirement.--The Secretary shall take actions to 
     ensure that the database required under paragraph (1) is 
     consistent with section 1629 to increase visibility to 
     endpoints, such as covered devices.
       (3) Updates.--The Secretary shall update the databases 
     established under paragraph (1) not less frequently than once 
     every 30 days.
                                 ______