Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

Bill Seeks To Establish Cybersecurity Guidelines for IoT Devices

Author: Scarinci Hollenbeck, LLC

Date: August 23, 2017

Key Contacts

Back

Bi-Partisan Bill Seeks to Establish Cybersecurity Guidelines for IoT Devices 

The U.S. Senate is currently considering the Internet of Things (IoT) Cybersecurity Improvement Act of 2017, which would establish baseline cybersecurity standards for federal procurement of IoT devices. The bill would also allow security researchers to look for critical vulnerabilities in devices purchased by the government without fear of prosecution. 

Bill Seeks To Establish Cybersecurity Guidelines for IoT Devices
Photo courtesy of Stocksnap.io

The IoT bill has attracted co-sponsors from both sides of the aisle, including U.S. Sens. Mark R. Warner (D-VA) and Cory Gardner (R-CO), co-chairs of the Senate Cybersecurity Caucus, along with Sens. Ron Wyden (D-OR) and Steve Daines (R-MT). The lawmakers drafted the legislation in consultation with technology and security experts from institutions such as the Berklett Cybersecurity Project of the Berkman Klein Center for Internet & Society at Harvard University.

Proliferation of IoT Devices Increases Cyber Risks

The term “Internet of Things” (IoT) refers to the ability of everyday objects, from home security systems to pacemakers, to send and receive data via an Internet connection. Research firm Gartner, Inc. predicts that 8.4 billion connected things will be in use worldwide in 2017, up 31 percent from 2016. The number of IoT devices is expected to reach 20.4 billion by 2020.

As adoption of the technology grows, so do the potential data privacy and cybersecurity risks, including unauthorized access, misuse of personal information, and personal safety concerns. According to Sen. Warner, the worldwide internet outages caused last year by devices infected with the Mirai malware highlighted the need for more robust discussions about securing IoT devices. 

“While I’m tremendously excited about the innovation and productivity that Internet-of-Things devices will unleash, I have long been concerned that too many Internet-connected devices are being sold without appropriate safeguards and protections in place,” said Sen. Warner

Provisions of Internet of Things (IoT) Cybersecurity Improvement Act of 2017

The Internet of Things (IoT) Cybersecurity Improvement Act of 2017 broadly defines “Internet-Connected Device” to include any “physical object that—(A) is capable of connecting to and is in regular connection with the Internet; and (B) has computer processing capabilities that can collect, send, or receive data.” Among other provisions, the legislation would:

  • Require vendors of Internet-connected devices purchased by the federal government to ensure their devices are patchable, rely on industry standard protocols, do not use hard-coded passwords, and do not contain any known security vulnerabilities.
  • Direct the Office of Management and Budget (OMB) to develop alternative network-level security requirements for devices with limited data processing and software functionality.
  • Direct the Department of Homeland Security’s National Protection and Programs Directorate to issue guidelines regarding cybersecurity coordinated vulnerability disclosure policies to be required by contractors providing connected devices to the U.S. Government.
  • Exempt cybersecurity researchers engaging in good-faith research (often called “grey hats”) from liability under the Computer Fraud and Abuse Act and the Digital Millennium Copyright Act when engaged in research pursuant to adopted coordinated vulnerability disclosure guidelines.
  • Require each executive agency to inventory all Internet-connected devices in use by the agency.

Notably, the requirements would only apply to IoT devices sold to the federal government. However, should the measure advance, additional legislation for consumer-facing devices would likely be forthcoming.

Do you have any feedback, thoughts, reactions or comments concerning this topic? Feel free to leave a comment below for Fernando M. Pinguelo. If you have any questions about this post, please contact me or the Scarinci Hollenbeck attorney with whom you work.

    No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

    Scarinci Hollenbeck, LLC, LLC

    Related Posts

    See all
    A Simple Guide to Industry Roll-Up Acquisitions post image

    A Simple Guide to Industry Roll-Up Acquisitions

    When done successfully, industry roll-up acquisitions can dramatically grow and strengthen your business. In this post, we break down what an industry roll-up is, why companies pursue it, and what makes it an effective (and sometimes risky) business strategy. What Is an Industry Roll-Up Acquisition? In an industry roll-up acquisition of companies, a buyer acquires multiple companies […]

    Author: Dan Brecher

    Link to post with title - "A Simple Guide to Industry Roll-Up Acquisitions"
    Genesis Mission: How the U.S. Government’s New AI Platform Will Reshape Corporate Innovation, Risk, and Competition post image

    Genesis Mission: How the U.S. Government’s New AI Platform Will Reshape Corporate Innovation, Risk, and Competition

    The federal government has launched one of the most ambitious scientific initiatives in decades, and it will redefine how companies develop technology, manage risk, and compete. The Genesis Mission, created by Executive Order and driven by the Department of Energy (“DOE”), is intended to accelerate scientific discovery through a national AI platform that links supercomputers, […]

    Author: Michael J. Sheppeard

    Link to post with title - "Genesis Mission: How the U.S. Government’s New AI Platform Will Reshape Corporate Innovation, Risk, and Competition"
    Stablecoins and the GENIUS Act: How New Global Rules Are Reshaping Compliance post image

    Stablecoins and the GENIUS Act: How New Global Rules Are Reshaping Compliance

    Stablecoins Leave the Grey Zone Stablecoins were supposed to be the “boring” part of crypto: digital dollars that just work. Yet for years they have lived in a regulatory no-man’s-land, classified one day as securities, the next as commodities, and sometimes as something regulators had not even named yet. That uncertainty is finally starting to […]

    Author: Bryce S. Robins

    Link to post with title - "Stablecoins and the GENIUS Act: How New Global Rules Are Reshaping Compliance"
    Don’t Overlook the Importance of Business License Management post image

    Don’t Overlook the Importance of Business License Management

    If you operate a business without the proper license, you risk fines, insurance issues, reputational harm, and even business closure. Even innocent mistakes, like forgetting to renew a license, can have significant consequences, such as losing your lawsuit for payment of services that are unlicensed, which makes it imperative to have business license management procedures […]

    Author: Dan Brecher

    Link to post with title - "Don’t Overlook the Importance of Business License Management"
    Failing to Comply With NJ Rent Control Exemption May Prove Costly post image

    Failing to Comply With NJ Rent Control Exemption May Prove Costly

    What Developers Need to Know About New Jersey’s Rent Control Exemption Law to Ensure Entitlement to Exemption for Newly Constructed Multi-family Housing.  A property owner in Jersey City is facing a $400 million federal class action lawsuit alleging that the landlord did not follow the procedural steps required to be eligible for exemption from local […]

    Author: Patrick T. Conlon

    Link to post with title - "Failing to Comply With NJ Rent Control Exemption May Prove Costly"
    Crypto Securities Law: When Tokens Become Investment Contracts post image

    Crypto Securities Law: When Tokens Become Investment Contracts

    The application of traditional federal securities laws to crypto assets continues to evolve. In some cases, the Securities and Exchange Commission (SEC) considers tokens and other digital assets to be securities. This makes them subject to federal securities law, including the Securities Act of 1933 and the Securities Exchange Act of 1934. This classification has […]

    Author: Bryce S. Robins

    Link to post with title - "Crypto Securities Law: When Tokens Become Investment Contracts"

    No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

    Sign up to get the latest from our attorneys!

    Explore What Matters Most to You.

    Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

    Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

    Let`s get in touch!

    * The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.

    Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!