Files
republic-os/legal/us/code/title-15/chapter-7/section-278g-3b.md
T
Fabio 76b8ec33a7 Legal corpus: the complete U.S. Code (59,740 sections, all 53 titles)
Ingested titles 12–51 and 54 from OLRC USLM XML @119-100 (the whole Code
now, uniform edition; Title 53 is reserved/empty). LegalText 11,221 ->
59,740; repo total 105,704 records. Deterministic (byte-identical rerun,
verified on Title 42's 8,356 sections); make check green. make
legal-us-code default now covers every title.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 10:51:44 -04:00

5.8 KiB
Raw Blame History

type, title, description, jurisdiction, corpus, kind, title_number, title_name, chapter_number, chapter_name, section, citation, status, release_point, release_date, source, source_url, source_identifier, source_file, source_hash, raw_snapshot_hash, text_hash, retrieved_at, confidence, tags
type title description jurisdiction corpus kind title_number title_name chapter_number chapter_name section citation status release_point release_date source source_url source_identifier source_file source_hash raw_snapshot_hash text_hash retrieved_at confidence tags
LegalText 15 U.S.C. § 278g3b Security standards and guidelines for agencies on use and management of Internet of Things devices us united_states_code code_section 15 COMMERCE AND TRADE 7 NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY 278g3b 15 U.S.C. § 278g3b current 119-100 2026-06-26 official https://uscode.house.gov/download/releasepoints/us/pl/119/100/xml_usc15@119-100.zip /us/usc/t15/s278g3b data/legal/raw/us/code/title-15/usc15.xml 4ce8e588a3308951b845083bca2e9266962b962ac086fd6b343bd29f8ef44646 6982338d990ef19d6b52bff6825089bdd6d0ee1233d9382673faf533decd5059 f6f564ec7a79d95613cceea88b67029356f4a73a54740ea0b0e69da8d6d00a35 2026-07-04 official
legal
us-code

15 U.S.C. § 278g3b - Security standards and guidelines for agencies on use and management of Internet of Things devices

Text

(a) National Institute of Standards and Technology development of standards and guidelines for use of Internet of Things devices by agencies (1) In general Not later than 90 days after December 4, 2020, the Director of the Institute shall develop and publish under section 278g3 of this title standards and guidelines for the Federal Government on the appropriate use and management by agencies of Internet of Things devices owned or controlled by an agency and connected to information systems owned or controlled by an agency, including minimum information security requirements for managing cybersecurity risks associated with such devices.

(2) Consistency with ongoing efforts The Director of the Institute shall ensure that the standards and guidelines developed under paragraph (1) are consistent with the efforts of the National Institute of Standards and Technology in effect on December 4, 2020—

(A) regarding—

(i) examples of possible security vulnerabilities of Internet of Things devices; and

(ii) considerations for managing the security vulnerabilities of Internet of Things devices; and

(B) with respect to the following considerations for Internet of Things devices:

(i) Secure Development.

(ii) Identity management.

(iii) Patching.

(iv) Configuration management.

(3) Considering relevant standards In developing the standards and guidelines under paragraph (1), the Director of the Institute shall consider relevant standards, guidelines, and best practices developed by the private sector, agencies, and public-private partnerships.

(b) Review of agency information security policies and principles (1) Requirement Not later than 180 days after the date on which the Director of the Institute completes the development of the standards and guidelines required under subsection (a), the Director of OMB shall review agency information security policies and principles on the basis of the standards and guidelines published under subsection (a) pertaining to Internet of Things devices owned or controlled by agencies (excluding agency information security policies and principles pertaining to Internet of Things of devices owned or controlled by agencies that are or comprise a national security system) for consistency with the standards and guidelines submitted under subsection (a) and issue such policies and principles as may be necessary to ensure those policies and principles are consistent with such standards and guidelines.

(2) Review In reviewing agency information security policies and principles under paragraph (1) and issuing policies and principles under such paragraph, as may be necessary, the Director of OMB shall—

(A) consult with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security; and

(B) ensure such policies and principles are consistent with the information security requirements under subchapter II of chapter 35 of title 44.

(3) National security systems Any policy or principle issued by the Director of OMB under paragraph (1) shall not apply to national security systems.

(c) Quinquennial review and revision (1) Review and revision of NIST standards and guidelines Not later than 5 years after the date on which the Director of the Institute publishes the standards and guidelines under subsection (a), and not less frequently than once every 5 years thereafter, the Director of the Institute, shall—

(A) review such standards and guidelines; and

(B) revise such standards and guidelines as appropriate.

(2) Updated OMB policies and principles for agencies Not later than 180 days after the Director of the Institute makes a revision pursuant to paragraph (1), the Director of OMB, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall update any policy or principle issued under subsection (b)(1) as necessary to ensure those policies and principles are consistent with the review and any revision under paragraph (1) under this subsection and paragraphs (2) and (3) of subsection (b).

(d) Revision of Federal Acquisition Regulation The Federal Acquisition Regulation shall be revised as necessary to implement any standards and guidelines promulgated in this section.

(Pub. L. 116207, § 4, Dec. 4, 2020, 134 Stat. 1002.)

Notes

Editorial Notes

Codification Section was enacted as part of the Internet of Things Cybersecurity Improvement Act of 2020, also known as the IoT Cybersecurity Improvement Act of 2020, and not as part of the National Institute of Standards and Technology Act which comprises this chapter.

Statutory Notes and Related Subsidiaries

Definitions For definitions of terms used in this section, see section 278g3a of this title.