Title 15 › Chapter CHAPTER 7— - NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY › § 278g–3b
The Director of the Institute must, within 90 days after December 4, 2020, create and publish standards and guidelines for federal agencies on using and managing Internet of Things devices the agency owns or controls that are connected to agency information systems. The rules must include minimum information security steps to manage cybersecurity risks, follow NIST work that was in effect on December 4, 2020 (including examples of device vulnerabilities and how to handle them), and address secure development, identity management, patching, and configuration management. The Director must also consider private-sector and agency best practices. Within 180 days after those standards are finished, the Director of OMB must review agencies’ information security policies (not including national security systems) and issue any changes needed to match the new standards. OMB must consult the Director of the Cybersecurity and Infrastructure Security Agency and make sure policies meet the requirements under subchapter II of chapter 35 of title 44. The Institute must review and update the standards at least every 5 years, and OMB must update its policies within 180 days after any changes. The Federal Acquisition Regulation must be revised as needed to implement the standards.
Full Legal Text
Commerce and Trade — Source: USLM XML via OLRC
Legislative History
Reference
Citation
15 U.S.C. § 278g–3b
Title 15 — Commerce and Trade
Last Updated
Apr 6, 2026
Release point: 119-73