FEDERAL · 15 U.S.C. · Chapter 7

Guidelines on the disclosure process for security vulnerabilities relating to information systems, including Internet of Things devices

Current through Pub. L. 119-102
Title 15Commerce and Trade·Ch. 7 — NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY
(a)In general Not later than 180 days after December 4, 2020, the Director of the Institute, in consultation with such cybersecurity researchers and private sector industry experts as the Director considers appropriate, and in consultation with the Secretary, shall develop and publish under section 278g–3 of this title guidelines—
(1)for the reporting, coordinating, publishing, and receiving of information about—
(A)a security vulnerability relating to information systems owned or controlled by an agency (including Internet of Things devices owned or controlled by an agency); and
(B)the resolution of such security vulnerability; and
(2)for a contractor providing to an agency an information system (including an Internet of Things device) and any subcontractor thereof at any tier provid

Free access — add to your briefcase to read the full text and ask questions with AI

15 U.S.C. § 278g–3c (Guidelines on the disclosure process for security vulnerabilities relating to information systems, including Internet of Things devices) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

§ 278g
15 U.S.C. § 278g
§ 659
15 U.S.C. § 659

Source Credit

History

(Pub. L. 116–207, §5, Dec. 4, 2020, 134 Stat. 1004.)

Editorial Notes

Editorial Notes

Codification
Section was enacted as part of the Internet of Things Cybersecurity Improvement Act of 2020, also known as the IoT Cybersecurity Improvement Act of 2020, and not as part of the National Institute of Standards and Technology Act which comprises this chapter.

Statutory Notes and Related Subsidiaries

Definitions
For definitions of terms used in this section, see section 278g–3a of this title.