Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · STATUTE-COMPILATIONS · Internet of Things Cybersecurity Improvement Act of 2020 · Sec. 5

Sec. 5. GUIDELINES ON THE DISCLOSURE PROCESS FOR SECURITY VULNERABILITIES RELATING TO INFORMATION SYSTEMS, INCLUDING INTERNET OF THINGS DEVICES

436 words·~2 min read·/statute-compilations/comps-15863/sec-5

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

## SEC. 5 GUIDELINES ON THE DISCLOSURE PROCESS FOR SECURITY VULNERABILITIES RELATING TO INFORMATION SYSTEMS, INCLUDING INTERNET OF THINGS DEVICES **[**[15 U.S.C. 278g-3c](/us/usc/t15/s278g-3c)**]** ###
(a)In General Not later than 180 days after the date of the enactment of this Act, the Director of the Institute, in consultation with such cybersecurity researchers and private sector industry experts as the Director considers appropriate, and in consultation with the Secretary, shall develop and publish under section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g-3) guidelines— ####
(1)for the reporting, coordinating, publishing, and receiving of information about— #####
(A)a security vulnerability relating to information systems owned or controlled by an agency (including Internet of Things devices owned or controlled by an agency); and #####
(B)the resolution of such security vulnerability; and ####
(2)for a contractor providing to an agency an information system (including an Internet of Things device) and any subcontractor thereof at any tier providing such information system to such contractor, on— #####
(A)receiving information about a potential security vulnerability relating to the information system; and #####
(B)disseminating information about the resolution of a security vulnerability relating to the information system. ###
(b)Elements The guidelines published under subsection
(a)shall— ####
(1)to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely-used standard; ####
(2)incorporate guidelines on— #####
(A)receiving information about a potential security vulnerability relating to an information system owned or controlled by an agency (including an Internet of Things device); and #####
(B)disseminating information about the resolution of a security vulnerability relating to an information system owned or controlled by an agency (including an Internet of Things device); and ####
(3)be consistent with the policies and procedures produced under section 2009(m) of the Homeland Security Act of 2002 (6 U.S.C. 659(m)). ###
(c)Information Items The guidelines published under subsection
(a)shall include example content, on the information items that should be reported, coordinated, published, or received pursuant to this section by a contractor, or any subcontractor thereof at any tier, providing an information system (including Internet of Things device) to the Federal Government. ###
(d)Oversight The Director of OMB shall oversee the implementation of the guidelines published under subsection (a). ###
(e)Operational and Technical Assistance The Secretary, in consultation with the Director of OMB, shall administer the implementation of the guidelines published under subsection
(a)and provide operational and technical assistance in implementing such guidelines.
Connectionstraces to 3
Citation graph
cites case law
Sec. 5
GUIDELINES ON THE DISCLOSURE PROCESS FOR SECURITY VULNERABILITIES RELATING TO INFORMATION SYSTEMS, INCLUDING INTERNET OF THINGS DEVICES
Cites 3Cited by 0 across 0 sources
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.