[Congressional Record Volume 164, Number 97 (Tuesday, June 12, 2018)]
[Senate]
[Pages S3849-S3851]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2825. Mr. GARDNER (for himself and Mr. Warner) submitted an
amendment intended to be proposed to amendment SA 2282 proposed by Mr.
Inhofe (for himself and Mr. McCain) to the bill H.R. 5515, to authorize
appropriations for fiscal year 2019 for military activities of the
Department of Defense, for military construction, and for defense
activities of the Department of Energy, to prescribe military personnel
strengths for such fiscal year, and for other purposes; which was
ordered to lie on the table; as follows:
At the end of title X, add the following:
Subtitle G--Internet of Things Cybersecurity Improvement Act
SEC. 1071. SHORT TITLE.
This subtitle may be cited as the ``Internet of Things
(IoT) Cybersecurity Improvement Act of 2018''.
SEC. 1072. DEFINITIONS; RULE OF CONSTRUCTION.
(a) Definitions.--In this subtitle:
(1) Covered device.--
(A) In general.--Subject to subparagraph (B), the term
``covered device''--
(i) means a physical object that--
(I) is capable of connecting to and is in regular
connection with the Internet or internal networks of the
Department that are connected to the Internet; and
(II) has computer processing capabilities that can collect,
send, or receive data; and
(ii) does not include advanced or general-purpose computing
devices, including personal computing systems, smart mobile
communications devices, programmable logic controls,
mainframe computing systems, and motor vehicles.
(B) Modification of definition.--
(i) In general.--The Secretary may modify the definition of
the term ``covered device'' in order to expand or narrow the
definition.
(ii) Interested parties.--The Secretary shall establish a
process by which--
(I) interested parties may petition the Integrating
Official described in section 1625 for a device that is not
described in subparagraph (A)(ii) to be considered a device
that is not a covered device; and
(II) the Secretary, acting through the Integrating
Official, acts upon any petition submitted under subclause
(I) in a timely manner.
(2) Department.--The term ``Department'' means the
Department of Defense.
(3) Firmware.--The term ``firmware'' means a computer
program and the data stored in hardware, typically in read-
only memory (ROM) or programmable read-only memory (PROM),
such that the program and data cannot be dynamically written
or modified during execution of the program.
(4) Fixed or hard-coded credential.--The term ``fixed or
hard-coded credential'' means a value, such as a password,
token, cryptographic key, or other data element used as part
of an authentication mechanism for granting remote access to
an information system or its information, that is--
(A) established by a product vendor or service provider;
(B) incapable of being modified or revoked by the user or
manufacturer lawfully operating the information system,
except via a firmware update; and
(C) not unique to each covered device.
(5) Hardware.--The term ``hardware'' means the physical
components of an information system.
(6) IoT.--The term ``IoT'' means the Internet of Things.
(7) NIST.--The term ``NIST'' means the National Institute
of Standards and Technology.
(8) Properly authenticated update.--The term ``properly
authenticated update''
[[Page S3850]]
means an update, remediation, or technical fix to a hardware,
firmware, or software component issued by a product vendor or
service provider used to correct particular problems with the
component, and that, in the case of software or firmware,
contains some method of authenticity protection, such as a
digital signature, so that unauthorized updates can be
automatically detected and rejected.
(9) Secretary.--The term ``Secretary'' means the Secretary
of Defense.
(10) Security vulnerability.--The term ``security
vulnerability'' means any attribute of hardware, firmware,
software, process, or procedure or combination of 2 or more
of these factors that could enable or facilitate the defeat
or compromise of the confidentiality, integrity, or
availability of an information system or its information or
physical devices to which it is connected.
(11) Software.--The term ``software'' means a computer
program and associated data that may be dynamically written
or modified.
(b) Rule of Construction.--Nothing in this subtitle shall
be construed to expand the authority or jurisdiction of NIST.
SEC. 1073. CONTRACTOR RESPONSIBILITIES WITH RESPECT TO
COVERED DEVICE CYBERSECURITY.
(a) Standard Security Clause Required in Covered Devices.--
(1) In general.--Not later than 180 days after the date of
enactment of this Act, the Secretary, in consultation with
NIST, shall issue guidelines for the Department to require
the inclusion of a standard security clause in any contract,
except as provided in paragraph (2), paragraph (3), and
subsection (b), for the acquisition of covered devices.
(2) Content of standard security clause.--The standard
security clause required under paragraph (1)--
(A) shall establish baseline security requirements that
address aspects of device security, including--
(i) the ability of software or firmware components to
accept properly authenticated and trusted updates from the
vendor;
(ii) identity and access management, including prohibiting
the use of fixed or hard-coded credentials used for remote
administration, the delivery of updates, or communication;
(iii) participation in a Coordinated Vulnerability
Disclosure program in accordance with subsection (f);
(iv) such other aspects as the Secretary determines to be
appropriate; and
(B) shall, to the maximum extent practicable, reflect and
align with voluntary consensus standards in effect on the
date of enactment of this Act;
(C) shall require vendors to provide written attestation
that the device meets such requirements as established under
subparagraph (A);
(D) shall, to the maximum extent practicable, ensure that
the requirements described in subparagraph (A) are--
(i) tailored to address the characteristics of different
types of devices, including risk and intended function;
(ii) based on technology-neutral, outcome-based security
principles;
(iii) developed through a transparent process that
incorporates input from relevant stakeholders in industry and
academia; and
(iv) updated regularly based on developments in technology
and security methodologies;
(E) shall identify responsibilities for ensuring that a
covered device software or firmware component is updated or
replaced, consistent with other provisions in the contract
governing the term of support, in a manner that allows for
any future security vulnerability or defect in any part of
the software or firmware to be patched, based on risk, in
order to fix or remove a vulnerability or defect in the
software or firmware component in a properly authenticated
and secure manner; and
(F) shall require the contractor to provide the Department
with general information on the ability of the device to be
updated, such as--
(i) the manner in which the device receives security
updates;
(ii) the business terms, including any fees for ongoing
security support, under which security updates will be
provided for a covered device;
(iii) the anticipated timeline for ending security support
associated with the covered device;
(iv) formal notification when security support has ceased;
and
(v) other information as determined necessary by the
Secretary.
(3) Waiver.--The Secretary may establish a process for the
Department to waive the requirements described in paragraph
(2)(A) when a component of the Department submits a written
application for a waiver, if the process--
(A) provides for waivers to be granted only in limited
circumstances, including--
(i) if a vendor demonstrates that a device meets a desired
level of security through means other than those required
under paragraph (2)(A); or
(ii) if the purchasing component of the Department
reasonably believes that procurement of a covered device with
limited data processing and software functionality would be
unfeasible or economically impractical; and
(B) provides that, if the Secretary approves a waiver, the
head of the purchasing component of the Department shall
provide the contractor a written statement that the
Department accepts risks resulting from use of the device.
(4) Alignment with fisma.--In issuing the guidelines
required under paragraph (1), the Secretary shall ensure that
such guidelines are, to the greatest extent practicable,
consistent with, not duplicative of, and in compliance with
any applicable established information security policies,
procedures, standards, and compliance requirements under
chapter 35 of title 44, United States Code.
(b) Alternate Conditions to Mitigate Cybersecurity Risks.--
(1) In general.--Not later than 180 days after the date of
the enactment of this Act, the Secretary, in consultation
with NIST, shall establish a set of conditions that--
(A) ensure that a covered device that does not comply with
the standard security clause under subsection (a) can be used
with a level of security that is equivalent to the level of
security described in subsection (a)(2); and
(B) shall be met in order for a Department to purchase a
covered device described in subparagraph (A).
(2) Requirements.--In defining a set of conditions that
must be met for non-compliant devices as required under
paragraph (1), the Secretary, in consultation with NIST, may
consider the use of conditions and information security
products such as those described in the relation to the
security integration framework established in section 1631,
including--
(A) network segmentation or micro-segmentation;
(B) the adoption of system level security controls,
including operating system containers and microservices;
(C) multi-factor authentication; and
(D) intelligent network solutions and edge systems, such as
gateways, that can isolate, disable, or remediate connected
devices.
(3) Specification of additional precautions.--To address
the long-term risk of non-compliant covered devices acquired
in accordance with an exception under this paragraph, the
Secretary, in consultation with NIST and taking into
consideration frameworks set forth by NIST, may stipulate
additional requirements for management and use of non-
compliant devices, including deadlines for the removal,
replacement, or disabling of non-compliant devices (or their
Internet-connectivity), as well as minimal requirements for
gateway products to ensure the integrity and security of the
non-compliant devices.
(4) Existing third-party security standard.--
(A) In general.--If an existing voluntary consensus
standard for the security of covered devices provides an
equivalent or greater level of security to that described in
subsection (a)(2)(A), the Secretary shall modify the required
security clauses to reflect conformity with that voluntary
consensus standard.
(B) Written certification.--A contractor providing the
covered device under this paragraph shall provide self-
attested written certification that the device complies with
the security requirements of the industry certification
method of the third party.
(C) Accreditation standards.--The Secretary shall determine
accreditation standards for third-party certification of
compliance with voluntary consensus standards described in
subparagraph (A).
(5) Existing security evaluation standards.--
(A) In general.--If a component of the Department employs
or proposes to employ a security evaluation process or
criteria for covered devices that the component believes
provides an equivalent or greater level of security to that
described in subsection (a)(2)(A), the component may, upon
the approval of the Secretary, employ or adopt that process
or criteria in lieu of the requirements under subsection
(a)(2)(A).
(B) Approval.--The Secretary shall determine whether the
process or criteria described in subparagraph (A) provides
appropriate security and is aligned with the guidelines
issued under this subsection.
(c) Required Guidelines.--Not later than 180 days after the
date of enactment of this Act, the Secretary shall issue
guidelines for the Department to limit, to the maximum extent
practicable, the use of lowest price technically acceptable
source selection criteria in the case of a procurement that
is predominately for the acquisition of a covered device.
(d) Report to Congress.--Not later than 5 years after the
date of enactment of this Act, the Secretary shall submit to
Congress a report on the effectiveness of the guidelines
required to be issued under subsections (a) and (c), which
shall include any recommendations for legislation necessary
to improve cybersecurity in the acquisition of Internet-
connected devices by the Department.
(e) Waiver Authority.--Beginning on the date that is 5
years after the date of enactment of this Act, the Secretary
may waive, in whole or in part, the requirements of the
guidelines issued under this section, for the Department.
(f) Guidelines Regarding the Coordinated Disclosure of
Security Vulnerabilities and Defects.--
(1) In general.--Not later than 180 days after the date of
the enactment of this Act,
[[Page S3851]]
the Secretary, in consultation with cybersecurity researchers
and private-sector industry experts, shall issue guidelines
for the Department with respect to any covered device in use
by the Department regarding cybersecurity coordinated
disclosure requirements that shall be required of contractors
providing such covered devices to the Department.
(2) Contents.--The guidelines required to be issued under
paragraph (1) shall include policies and procedures for the
processing and resolving of potential vulnerability
information relating to a covered device, which shall be, to
the maximum extent practicable, aligned with Standards 29147
and 30111 of the International Standards Organization, or any
successor standard, such as--
(A) procedures for a contractor providing a covered device
to the Department on how to--
(i) receive information about potential vulnerabilities in
the product or online service of the contractor; and
(ii) disseminate resolution information about
vulnerabilities in the product or online service of the
contractor; and
(B) guidance, including example content, on the information
items that should be produced through the implementation of
the vulnerability disclosure process of the contractor.
(3) Requirement.--Consistent with section 1626, the
Secretary shall develop mechanisms to provide assistance to
help small manufacturers of covered devices set up
coordinated vulnerability disclosure programs under this
subsection, including assistance in establishing processes
for intake, handling, and remediation of security
vulnerabilities.
SEC. 1074. INVENTORY OF DEVICES.
(a) In General.--Not later than 180 days after the date of
enactment of this Act, the Secretary shall establish and
maintain an inventory of covered devices used by the
Department procured under this subtitle.
(b) Guidelines.--Not later than 90 days after the date of
the enactment of this Act, the Secretary shall issue
guidelines for the Department to develop and manage the
inventories required under subsection (a).
(c) Device Databases.--
(1) In general.--Not later than 180 days after the date of
enactment of this Act, the Secretary shall establish and
maintain a database of devices and the respective
manufacturers of such devices about which the Government has
received formal notification of security support ceasing, as
required under section 1073(a)(2)(F).
(2) Requirement.--The Secretary shall take actions to
ensure that the database required under paragraph (1) is
consistent with section 1629 to increase visibility to
endpoints, such as covered devices.
(3) Updates.--The Secretary shall update the databases
established under paragraph (1) not less frequently than once
every 30 days.
______