Security of Connected Devices (IoT security law)

IoT Security (SB 327)
active

Requires makers of internet-connected devices to build in reasonable security features suited to the device and the data it handles. A unique preprogrammed password per device, or forcing the user to set new credentials at first use, satisfies the rule for remote authentication, as does meeting a NIST-conforming labeling scheme.

Jurisdiction

California

Jurisdiction Type

state

Country

United States

Effective Date

1/1/2020

Enforcing Authority

California Attorney General, city attorneys, county counsel, and district attorneys (exclusive; 1798.91.06(e))

Fines Under This Regulation

0

Total Fine Amount (USD)

--