Security News > 2020 > December > IoT Cybersecurity Improvement Act Signed Into Law

IoT Cybersecurity Improvement Act Signed Into Law
2020-12-08 13:27

The IoT Cybersecurity Improvement Act of 2020 requires the National Institute of Standards and Technology to develop and publish standards and guidelines on addressing issues related to the development, management, configuring, and patching of IoT devices.

The law demands the Office of Management and Budget to issue recommendations based on the NIST guidelines for federal agencies, which are required to ensure that all IoT devices within their environments fully comply with these standards and guidelines.

The legislation also dictates that NIST develops and publishes guidelines for the reporting and disclosure of security vulnerabilities, including those in IoT devices used within federal agencies.

Brad Ree, CTO of the ioXt Alliance, which describes itself as the global standard for IoT security, said the first national IoT security law in the U.S. is a "Huge milestone for the industry."

"As the world becomes more connected, it is great to see American leadership in the public and private sectors coming together to improve connected device security by setting the minimum security requirements for government purchased devices. Though this bill is targeted at government purchases, I fully expect network operators, consumer ecosystems, and retailers to follow with similar requirements for consumer products," Ree told SecurityWeek.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/0K978m4V8fQ/iot-cybersecurity-improvement-act-signed-law