Files
Fabio 76b8ec33a7 Legal corpus: the complete U.S. Code (59,740 sections, all 53 titles)
Ingested titles 12–51 and 54 from OLRC USLM XML @119-100 (the whole Code
now, uniform edition; Title 53 is reserved/empty). LegalText 11,221 ->
59,740; repo total 105,704 records. Deterministic (byte-identical rerun,
verified on Title 42's 8,356 sections); make check green. make
legal-us-code default now covers every title.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 10:51:44 -04:00

4.3 KiB
Raw Permalink Blame History

type, title, description, jurisdiction, corpus, kind, title_number, title_name, chapter_number, chapter_name, section, citation, status, release_point, release_date, source, source_url, source_identifier, source_file, source_hash, raw_snapshot_hash, text_hash, retrieved_at, confidence, tags
type title description jurisdiction corpus kind title_number title_name chapter_number chapter_name section citation status release_point release_date source source_url source_identifier source_file source_hash raw_snapshot_hash text_hash retrieved_at confidence tags
LegalText 15 U.S.C. § 278g3c Guidelines on the disclosure process for security vulnerabilities relating to information systems, including Internet of Things devices us united_states_code code_section 15 COMMERCE AND TRADE 7 NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY 278g3c 15 U.S.C. § 278g3c current 119-100 2026-06-26 official https://uscode.house.gov/download/releasepoints/us/pl/119/100/xml_usc15@119-100.zip /us/usc/t15/s278g3c data/legal/raw/us/code/title-15/usc15.xml 7d772d31ddacb8b658358f48f11d15aaa9110a01556205c01219951468864e06 6982338d990ef19d6b52bff6825089bdd6d0ee1233d9382673faf533decd5059 48e4d9e5f56990a2b6bc2f146b645cd352435b7a1918b05b1ec1cdf6a312a5b6 2026-07-04 official
legal
us-code

15 U.S.C. § 278g3c - Guidelines on the disclosure process for security vulnerabilities relating to information systems, including Internet of Things devices

Text

(a) In general Not later than 180 days after December 4, 2020, the Director of the Institute, in consultation with such cybersecurity researchers and private sector industry experts as the Director considers appropriate, and in consultation with the Secretary, shall develop and publish under section 278g3 of this title guidelines—

(1) for the reporting, coordinating, publishing, and receiving of information about—

(A) a security vulnerability relating to information systems owned or controlled by an agency (including Internet of Things devices owned or controlled by an agency); and

(B) the resolution of such security vulnerability; and

(2) for a contractor providing to an agency an information system (including an Internet of Things device) and any subcontractor thereof at any tier providing such information system to such contractor, on—

(A) receiving information about a potential security vulnerability relating to the information system; and

(B) disseminating information about the resolution of a security vulnerability relating to the information system.

(b) Elements The guidelines published under subsection (a) shall—

(1) to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely-used standard;

(2) incorporate guidelines on—

(A) receiving information about a potential security vulnerability relating to an information system owned or controlled by an agency (including an Internet of Things device); and

(B) disseminating information about the resolution of a security vulnerability relating to an information system owned or controlled by an agency (including an Internet of Things device); and

(3) be consistent with the policies and procedures produced under section 659(m) of title 6.

(c) Information items The guidelines published under subsection (a) shall include example content, on the information items that should be reported, coordinated, published, or received pursuant to this section by a contractor, or any subcontractor thereof at any tier, providing an information system (including Internet of Things device) to the Federal Government.

(d) Oversight The Director of OMB shall oversee the implementation of the guidelines published under subsection (a).

(e) Operational and technical assistance The Secretary, in consultation with the Director of OMB, shall administer the implementation of the guidelines published under subsection (a) and provide operational and technical assistance in implementing such guidelines.

(Pub. L. 116207, § 5, Dec. 4, 2020, 134 Stat. 1004.)

Notes

Editorial Notes

Codification Section was enacted as part of the Internet of Things Cybersecurity Improvement Act of 2020, also known as the IoT Cybersecurity Improvement Act of 2020, and not as part of the National Institute of Standards and Technology Act which comprises this chapter.

Statutory Notes and Related Subsidiaries

Definitions For definitions of terms used in this section, see section 278g3a of this title.