OAKMOREL Forensic Intelligence // [email protected]
15 U.S.C. § 278g3e 15 u.s.c. · national institute of standards and tech · title 15
15 U.S.C. § 278g3e
Contractor compliance with coordinated disclosure of security vulnerabilities relating to agency Internet of Things devices
Title 15 USC
● ACTIVE
Ch. 7
Jurisdiction Federal — United States
Chapter NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY
Primary Source uscode.house.gov ↗
Federation ID OM-USC15-SEC-1E2C90
STATUTORY TEXT primary source · verbatim · uscode.house.gov

U.S.C. Title 15 - COMMERCE AND TRADE 15 U.S.C. United States Code, 2023 Edition Title 15 - COMMERCE AND TRADE CHAPTER 7 - NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY Sec. 278g-3e - Contractor compliance with coordinated disclosure of security vulnerabilities relating to agency Internet of Things devices From the U.S. Government Publishing Office, www.gpo.gov

§278g–3e. Contractor compliance with coordinated disclosure of security vulnerabilities relating to agency Internet of Things devices

(a) Prohibition on procurement and use (1) In general The head of an agency is prohibited from procuring or obtaining, renewing a contract to procure or obtain, or using an Internet of Things device, if the Chief Information Officer of that agency determines during a review required by section 11319(b)(1)(C) of title 40 of a contract for such device that the use of such device prevents compliance with the standards and guidelines developed under section 278g–3b of this title or the guidelines published under section 278g–3c of this title with respect to such device. (2) Simplified acquisition threshold Notwithstanding section 1905 of title 41, the requirements under paragraph (1) shall apply to a contract or subcontract in amounts not greater than the simplified acquisition threshold. (b) Waiver (1) Authority The head of an agency may waive the prohibition under subsection (a)(1) with respect to an Internet of Things device if the Chief Information Officer of that agency determines that— (A) the waiver is necessary in the interest of national security; (B) procuring, obtaining, or using such device is necessary for research purposes; or (C) such device is secured using alternative and effective methods appropriate to the function of such device. (2) Agency process The Director of OMB shall establish a standardized process for the Chief Information Officer of each agency to follow in determining whether the waiver under paragraph (1) may be granted. (c) Reports to Congress (1) Report Every 2 years during the 6-year period beginning on December 4, 2020, the Comptroller General of the United States shall submit to the Committee on Oversight and Reform of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs of the Senate a report— (A) on the effectiveness of the process established under subsection (b)(2); (B) that contains recommended best practices for the procurement of Internet of Things devices; and (C) that lists— (i) the number and type of each Internet of Things device for which a waiver under subsection (b)(1) was granted during the 2-year period prior to the submission of the report; and (ii) the legal authority under which each such waiver was granted, such as whether the waiver was granted pursuant to subparagraph (A), (B), or (C) of such subsection. (2) Classification of report Each report submitted under this subsection shall be submitted in unclassified form, but may include a classified annex that contains the information described under paragraph (1)(C). (d) Effective date The prohibition under subsection (a)(1) shall take effect 2 years after December 4, 2020.

(Pub. L. 116–207, §7, Dec. 4, 2020, 134 Stat. 1005.)

Editorial Notes

Codification Section was enacted as part of the Internet of Things Cybersecurity Improvement Act of 2020, also known as the IoT Cybersecurity Improvement Act of 2020, and not as part of the National Institute of Standards and Technology Act which comprises this chapter.

Statutory Notes and Related Subsidiaries

Change of Name Committee on Oversight and Reform of House of Representatives changed to Committee on Oversight and Accountability of House of Representatives by House Resolution No. 5, One Hundred Eighteenth Congress, Jan. 9, 2023.

Definitions For definitions of terms used in this section, see section 278g–3a of this title.

Source: uscode.house.gov — public domain Official Source ↗
ROOT-LD ENTITY DATA machine-readable · federation graph · v1.0
Federation ID
OM-USC15-SEC-1E2C90
Entity Class
STATUTE / FEDERAL-CODE-SECTION
Domain Signature
oakmorel.com
Spec Version
Root-LD v1.0
Source
PRIMARY-SOURCE
Content Hash
2dfd8ef42a6ec6ea...
Source Verified
✓ TRUE
Semantic Edges
PENDING — corpus passes queued
The statutory text of 15 U.S.C. § 278g3e is reproduced from the official United States Code as published by the Office of the Law Revision Counsel of the U.S. House of Representatives (uscode.house.gov).
OakMorel Law
15 U.S.C.
Citation
15 U.S.C. § 278g3e
Status
● ACTIVE
Chapter
7 — NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY
Title
Commerce and Trade
Jurisdiction
Federal
Federation ID
OM-USC15-SEC-1E2C90
Root-LD Spec
v1.0
► Forensic Services
Procurement fraud, platform integrity, litigation support. First conversation free.
► CONTACT OAKMOREL →
↑↓ Scroll ENTER Select ESC Exit
Commerce and Trade — 15 U.S.C. § 278g3e