IoT security goes to Washington - [Opinion]
IEEE Spectrum · 2019
IN 2016, attacks such as the Mirai botnet took down several popular websites, and in doing so, brought attention to the need for security for Internet of Things (IoT) devices. Since then, the U.S. Congress has made attempts to pass legislation around IoT security, including a lame attempt in 2017, when senators introduced a bill that would prevent the government from buying connected devices that had one of a small number of glaring security flaws. Once again, Congress is trying to pass legislation, but this time around, there's more to like in the bill. • The Internet of Things Cybersecurity Improvement Act of 2019 isn't trying to dictate specifically how to secure connected devices, as the 2017 bill did. Instead, it aims to build a framework that the government can use to establish a list of characteristics required for secure connected devices. Promisingly, the bill allocates the task of figuring out the requirements for a secure device to the technologically savvy National Institute of Standards and Technology (NIST). Then it's up to the Office of Management and Budget (OMB) to direct federal agencies how they should adopt the NIST guidelines. • Some security experts worry that this two-step approach will lead to lower security standards for agencies, because even if NIST produces strong standards, OMB could tell some or all agencies to ignore parts or even all of the standards. But that isn't necessarily a bad thing: The National Park Service probably doesn't require the same security guidelines that the Department of Defense requires.