CYSE 406

Cyber Law

Below is a scenario of me being a legislative research aid.

To: Representative Tito Canduit, 26th District of VirginiaFrom: Josiah Marshall Marshall, Legislative Research AideDate: 11/22/2024Subject: Cybersecurity Research Memo – IoT Cybersecurity Improvement Act of 2020The Internet of Things (IoT) Cybersecurity Improvement Act of 2020 is a federal lawsigned by President Donald J. Trump. This law was signed on December 4th of 2020. This lawaims to help federal agencies improve their cybersecurity of internet connected devices. This lawmandates that minimum security standards for IoT devices purchased by the federal governmentfollow the National Institute of Standards and Technology. These standards focus on securedevelopments, identity management, configuration management, patching. Contractorssupplying IoT devices to federal agencies must ensure their products meet NIST’s guidelines.Regarding device assessment, assessments must be conducted to ensure compliance and addressnew cybersecurity risks. Lastly, federal agencies are required to establish processes foridentifying and resolving vulnerabilities in IoT devices they use.The problem’s that IoT devices such as sensors, smart cameras, and connected medicaldevices have been used more in recent years. In 2020 there were about 31 billion IoT devicesworldwide. These devices often have no security features and this makes them easy to attack. Anotable example of this is the 2016 Mirai botnet attack which harnessed unsecured IoT devicesto create a massive distributed denial-of-service (DDoS) attack that disrupted major websites.This not only presents security risks, but risks to the federal government. As I stated earlier,healthcare, the Department of Defense and other big federal agencies use IoT devices. An attackon these systems could jeopardize national security. Because of this, growing threats are aiding
in different countries because they know IoT devices can be useful to take advantage of nationalsecurity. However, this law responds to public concerns about cybersecurity and ransomwareincidents. This law aims to set precedent for improving security standards across the privatesector.The strength of this law is that it establishes at least the most minimal security measuresand reduces risk of attackers exploiting poorly secured IoT devices in federal systems. It alsopromotes security design in these IoT devices being made and encourages better approaches ingeneral. However, this law could improve by being IoT devices as a whole. This law only coversthe IoT devices used by federal agencies which is a small portion of the IoT devices. This lawneeds to educate the public about why IoT devices need to be secure and have punishments if notproperly secured.Some voter focused observations are the economic impact. The law would encouragebetter innovation by incentivizing companies to develop more secure products. This would be aplus for voters focused on economic growth and jobs in the technology industry. This would alsoset a benchmark for private companies and benefit consumers by raising the bar for IoT security.What I recommend for Representative Canduit to strengthen your position oncybersecurity is to consider supporting/proposing laws that extend IoT security standards inbusinesses to help consumers. Also you should also suggest partnerships with governments andindustry leaders to improve IoT security in general. The last thing that you should consider ispushing for laws to continue to advance technological advancements in general and fundingsecurity research to continue to watch for cybersecurity threats.

Sincerely,Josiah MarshallSources:https://www.congress.gov/bill/116th-congress/house-bill/1668https://www.csoonline.com/article/568801/2020-outlook-for-cybersecurity-legislation.htmlhttps://www.nist.gov/internet-things-iot