California 2021-2022 Regular Session

California Assembly Bill AB2392 Compare Versions

OldNewDifferences
1-Assembly Bill No. 2392 CHAPTER 785 An act to amend Sections 1798.91.04 and 1798.91.05 of, and to repeal Title 1.81.26 (commencing with Section 1798.91.04) of Part 4 of Division 3 of, the Civil Code, relating to information privacy. [ Approved by Governor September 29, 2022. Filed with Secretary of State September 29, 2022. ] LEGISLATIVE COUNSEL'S DIGESTAB 2392, Irwin. Information privacy: connected devices: labeling.Existing law requires a manufacturer of a connected device to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and information contained in the device from unauthorized access, destruction, use, modification, or disclosure.This bill would provide that a manufacturer of a connected device may elect to satisfy the above-described provisions by ensuring the connected device meets or exceeds the baseline product criteria of a labeling scheme that conforms to specified guidance published by the National Institute of Standards and Technology (NIST) for consumer Internet of Things (IoT) products, satisfies a conformity assessment as described by a NIST conforming labeling scheme, as specified, and bears the binary label as described by a NIST conforming labeling scheme.This bill would also make nonsubstantive changes that remove provisions redundant to the above-described existing provisions.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. The Legislature finds and declares all of the following:(a) On May 12, 2021, President Joseph Biden issued the Executive Order on Improving the Nations Cybersecurity (E.O. 14028) directing the National Institute of Standards and Technology (NIST) to develop cybersecurity criteria and labeling approaches for consumer software and Internet of Things (IoT) products and then to initiate pilots based on those criteria.(b) On February 4, 2022, NIST published Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products to fulfill the requirements of the Executive Order.(c) NISTs recommended criteria aim to identify key elements of labeling in terms of minimum recommendations and desirable attributes for use by a labeling scheme owner.(d) NIST decided against establishing its own labeling program in favor of allowing various schemes owned by various public or private sector organizations.SEC. 2. Section 1798.91.04 of the Civil Code, as added by Section 1 of Chapter 860 of the Statutes of 2018, is amended to read:1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time.(c) A manufacturer of a connected device may elect to satisfy the requirements of subdivision (a) by ensuring the connected device does all of the following:(1) Meets or exceeds the baseline product criteria of a NIST conforming labeling scheme.(2) Satisfies a conformity assessment as described by a NIST conforming labeling scheme that includes a third-party test, inspection, or certification.(3) Bears the binary label as described by a NIST conforming labeling scheme.SEC. 3. Section 1798.91.05 of the Civil Code, as added by Section 1 of Chapter 860 of the Statutes of 2018, is amended to read:1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the internet, directly or indirectly, and that is assigned an internet protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) NIST conforming labeling scheme means a labeling scheme conforming to the Cybersecurity White Paper titled Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products published by the National Institute of Standards and Technology (NIST) on February 4, 2022, including any revisions or successor publications.(e) Security feature means a feature of a device designed to provide security for that device.(f) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer.SEC. 4. Title 1.81.26 (commencing with Section 1798.91.04) of Part 4 of Division 3 of the Civil Code, as added by Section 1 of Chapter 886 of the Statutes of 2018, is repealed.
1+Enrolled August 30, 2022 Passed IN Senate August 24, 2022 Passed IN Assembly August 29, 2022 Amended IN Senate June 23, 2022 Amended IN Assembly March 28, 2022 CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION Assembly Bill No. 2392Introduced by Assembly Member IrwinFebruary 17, 2022 An act to amend Sections 1798.91.04 and 1798.91.05 of, and to repeal Title 1.81.26 (commencing with Section 1798.91.04) of Part 4 of Division 3 of, the Civil Code, relating to information privacy. LEGISLATIVE COUNSEL'S DIGESTAB 2392, Irwin. Information privacy: connected devices: labeling.Existing law requires a manufacturer of a connected device to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and information contained in the device from unauthorized access, destruction, use, modification, or disclosure.This bill would provide that a manufacturer of a connected device may elect to satisfy the above-described provisions by ensuring the connected device meets or exceeds the baseline product criteria of a labeling scheme that conforms to specified guidance published by the National Institute of Standards and Technology (NIST) for consumer Internet of Things (IoT) products, satisfies a conformity assessment as described by a NIST conforming labeling scheme, as specified, and bears the binary label as described by a NIST conforming labeling scheme.This bill would also make nonsubstantive changes that remove provisions redundant to the above-described existing provisions.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. The Legislature finds and declares all of the following:(a) On May 12, 2021, President Joseph Biden issued the Executive Order on Improving the Nations Cybersecurity (E.O. 14028) directing the National Institute of Standards and Technology (NIST) to develop cybersecurity criteria and labeling approaches for consumer software and Internet of Things (IoT) products and then to initiate pilots based on those criteria.(b) On February 4, 2022, NIST published Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products to fulfill the requirements of the Executive Order.(c) NISTs recommended criteria aim to identify key elements of labeling in terms of minimum recommendations and desirable attributes for use by a labeling scheme owner.(d) NIST decided against establishing its own labeling program in favor of allowing various schemes owned by various public or private sector organizations.SEC. 2. Section 1798.91.04 of the Civil Code, as added by Section 1 of Chapter 860 of the Statutes of 2018, is amended to read:1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time.(c) A manufacturer of a connected device may elect to satisfy the requirements of subdivision (a) by ensuring the connected device does all of the following:(1) Meets or exceeds the baseline product criteria of a NIST conforming labeling scheme.(2) Satisfies a conformity assessment as described by a NIST conforming labeling scheme that includes a third-party test, inspection, or certification.(3) Bears the binary label as described by a NIST conforming labeling scheme.SEC. 3. Section 1798.91.05 of the Civil Code, as added by Section 1 of Chapter 860 of the Statutes of 2018, is amended to read:1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the internet, directly or indirectly, and that is assigned an internet protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) NIST conforming labeling scheme means a labeling scheme conforming to the Cybersecurity White Paper titled Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products published by the National Institute of Standards and Technology (NIST) on February 4, 2022, including any revisions or successor publications.(e) Security feature means a feature of a device designed to provide security for that device.(f) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer.SEC. 4. Title 1.81.26 (commencing with Section 1798.91.04) of Part 4 of Division 3 of the Civil Code, as added by Section 1 of Chapter 886 of the Statutes of 2018, is repealed.
22
3- Assembly Bill No. 2392 CHAPTER 785 An act to amend Sections 1798.91.04 and 1798.91.05 of, and to repeal Title 1.81.26 (commencing with Section 1798.91.04) of Part 4 of Division 3 of, the Civil Code, relating to information privacy. [ Approved by Governor September 29, 2022. Filed with Secretary of State September 29, 2022. ] LEGISLATIVE COUNSEL'S DIGESTAB 2392, Irwin. Information privacy: connected devices: labeling.Existing law requires a manufacturer of a connected device to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and information contained in the device from unauthorized access, destruction, use, modification, or disclosure.This bill would provide that a manufacturer of a connected device may elect to satisfy the above-described provisions by ensuring the connected device meets or exceeds the baseline product criteria of a labeling scheme that conforms to specified guidance published by the National Institute of Standards and Technology (NIST) for consumer Internet of Things (IoT) products, satisfies a conformity assessment as described by a NIST conforming labeling scheme, as specified, and bears the binary label as described by a NIST conforming labeling scheme.This bill would also make nonsubstantive changes that remove provisions redundant to the above-described existing provisions.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
3+ Enrolled August 30, 2022 Passed IN Senate August 24, 2022 Passed IN Assembly August 29, 2022 Amended IN Senate June 23, 2022 Amended IN Assembly March 28, 2022 CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION Assembly Bill No. 2392Introduced by Assembly Member IrwinFebruary 17, 2022 An act to amend Sections 1798.91.04 and 1798.91.05 of, and to repeal Title 1.81.26 (commencing with Section 1798.91.04) of Part 4 of Division 3 of, the Civil Code, relating to information privacy. LEGISLATIVE COUNSEL'S DIGESTAB 2392, Irwin. Information privacy: connected devices: labeling.Existing law requires a manufacturer of a connected device to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and information contained in the device from unauthorized access, destruction, use, modification, or disclosure.This bill would provide that a manufacturer of a connected device may elect to satisfy the above-described provisions by ensuring the connected device meets or exceeds the baseline product criteria of a labeling scheme that conforms to specified guidance published by the National Institute of Standards and Technology (NIST) for consumer Internet of Things (IoT) products, satisfies a conformity assessment as described by a NIST conforming labeling scheme, as specified, and bears the binary label as described by a NIST conforming labeling scheme.This bill would also make nonsubstantive changes that remove provisions redundant to the above-described existing provisions.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
44
5- Assembly Bill No. 2392 CHAPTER 785
5+ Enrolled August 30, 2022 Passed IN Senate August 24, 2022 Passed IN Assembly August 29, 2022 Amended IN Senate June 23, 2022 Amended IN Assembly March 28, 2022
66
7- Assembly Bill No. 2392
7+Enrolled August 30, 2022
8+Passed IN Senate August 24, 2022
9+Passed IN Assembly August 29, 2022
10+Amended IN Senate June 23, 2022
11+Amended IN Assembly March 28, 2022
812
9- CHAPTER 785
13+ CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION
14+
15+ Assembly Bill
16+
17+No. 2392
18+
19+Introduced by Assembly Member IrwinFebruary 17, 2022
20+
21+Introduced by Assembly Member Irwin
22+February 17, 2022
1023
1124 An act to amend Sections 1798.91.04 and 1798.91.05 of, and to repeal Title 1.81.26 (commencing with Section 1798.91.04) of Part 4 of Division 3 of, the Civil Code, relating to information privacy.
12-
13- [ Approved by Governor September 29, 2022. Filed with Secretary of State September 29, 2022. ]
1425
1526 LEGISLATIVE COUNSEL'S DIGEST
1627
1728 ## LEGISLATIVE COUNSEL'S DIGEST
1829
1930 AB 2392, Irwin. Information privacy: connected devices: labeling.
2031
2132 Existing law requires a manufacturer of a connected device to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and information contained in the device from unauthorized access, destruction, use, modification, or disclosure.This bill would provide that a manufacturer of a connected device may elect to satisfy the above-described provisions by ensuring the connected device meets or exceeds the baseline product criteria of a labeling scheme that conforms to specified guidance published by the National Institute of Standards and Technology (NIST) for consumer Internet of Things (IoT) products, satisfies a conformity assessment as described by a NIST conforming labeling scheme, as specified, and bears the binary label as described by a NIST conforming labeling scheme.This bill would also make nonsubstantive changes that remove provisions redundant to the above-described existing provisions.
2233
2334 Existing law requires a manufacturer of a connected device to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and information contained in the device from unauthorized access, destruction, use, modification, or disclosure.
2435
2536 This bill would provide that a manufacturer of a connected device may elect to satisfy the above-described provisions by ensuring the connected device meets or exceeds the baseline product criteria of a labeling scheme that conforms to specified guidance published by the National Institute of Standards and Technology (NIST) for consumer Internet of Things (IoT) products, satisfies a conformity assessment as described by a NIST conforming labeling scheme, as specified, and bears the binary label as described by a NIST conforming labeling scheme.
2637
2738 This bill would also make nonsubstantive changes that remove provisions redundant to the above-described existing provisions.
2839
2940 ## Digest Key
3041
3142 ## Bill Text
3243
3344 The people of the State of California do enact as follows:SECTION 1. The Legislature finds and declares all of the following:(a) On May 12, 2021, President Joseph Biden issued the Executive Order on Improving the Nations Cybersecurity (E.O. 14028) directing the National Institute of Standards and Technology (NIST) to develop cybersecurity criteria and labeling approaches for consumer software and Internet of Things (IoT) products and then to initiate pilots based on those criteria.(b) On February 4, 2022, NIST published Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products to fulfill the requirements of the Executive Order.(c) NISTs recommended criteria aim to identify key elements of labeling in terms of minimum recommendations and desirable attributes for use by a labeling scheme owner.(d) NIST decided against establishing its own labeling program in favor of allowing various schemes owned by various public or private sector organizations.SEC. 2. Section 1798.91.04 of the Civil Code, as added by Section 1 of Chapter 860 of the Statutes of 2018, is amended to read:1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time.(c) A manufacturer of a connected device may elect to satisfy the requirements of subdivision (a) by ensuring the connected device does all of the following:(1) Meets or exceeds the baseline product criteria of a NIST conforming labeling scheme.(2) Satisfies a conformity assessment as described by a NIST conforming labeling scheme that includes a third-party test, inspection, or certification.(3) Bears the binary label as described by a NIST conforming labeling scheme.SEC. 3. Section 1798.91.05 of the Civil Code, as added by Section 1 of Chapter 860 of the Statutes of 2018, is amended to read:1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the internet, directly or indirectly, and that is assigned an internet protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) NIST conforming labeling scheme means a labeling scheme conforming to the Cybersecurity White Paper titled Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products published by the National Institute of Standards and Technology (NIST) on February 4, 2022, including any revisions or successor publications.(e) Security feature means a feature of a device designed to provide security for that device.(f) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer.SEC. 4. Title 1.81.26 (commencing with Section 1798.91.04) of Part 4 of Division 3 of the Civil Code, as added by Section 1 of Chapter 886 of the Statutes of 2018, is repealed.
3445
3546 The people of the State of California do enact as follows:
3647
3748 ## The people of the State of California do enact as follows:
3849
3950 SECTION 1. The Legislature finds and declares all of the following:(a) On May 12, 2021, President Joseph Biden issued the Executive Order on Improving the Nations Cybersecurity (E.O. 14028) directing the National Institute of Standards and Technology (NIST) to develop cybersecurity criteria and labeling approaches for consumer software and Internet of Things (IoT) products and then to initiate pilots based on those criteria.(b) On February 4, 2022, NIST published Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products to fulfill the requirements of the Executive Order.(c) NISTs recommended criteria aim to identify key elements of labeling in terms of minimum recommendations and desirable attributes for use by a labeling scheme owner.(d) NIST decided against establishing its own labeling program in favor of allowing various schemes owned by various public or private sector organizations.
4051
4152 SECTION 1. The Legislature finds and declares all of the following:(a) On May 12, 2021, President Joseph Biden issued the Executive Order on Improving the Nations Cybersecurity (E.O. 14028) directing the National Institute of Standards and Technology (NIST) to develop cybersecurity criteria and labeling approaches for consumer software and Internet of Things (IoT) products and then to initiate pilots based on those criteria.(b) On February 4, 2022, NIST published Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products to fulfill the requirements of the Executive Order.(c) NISTs recommended criteria aim to identify key elements of labeling in terms of minimum recommendations and desirable attributes for use by a labeling scheme owner.(d) NIST decided against establishing its own labeling program in favor of allowing various schemes owned by various public or private sector organizations.
4253
4354 SECTION 1. The Legislature finds and declares all of the following:
4455
4556 ### SECTION 1.
4657
4758 (a) On May 12, 2021, President Joseph Biden issued the Executive Order on Improving the Nations Cybersecurity (E.O. 14028) directing the National Institute of Standards and Technology (NIST) to develop cybersecurity criteria and labeling approaches for consumer software and Internet of Things (IoT) products and then to initiate pilots based on those criteria.
4859
4960 (b) On February 4, 2022, NIST published Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products to fulfill the requirements of the Executive Order.
5061
5162 (c) NISTs recommended criteria aim to identify key elements of labeling in terms of minimum recommendations and desirable attributes for use by a labeling scheme owner.
5263
5364 (d) NIST decided against establishing its own labeling program in favor of allowing various schemes owned by various public or private sector organizations.
5465
5566 SEC. 2. Section 1798.91.04 of the Civil Code, as added by Section 1 of Chapter 860 of the Statutes of 2018, is amended to read:1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time.(c) A manufacturer of a connected device may elect to satisfy the requirements of subdivision (a) by ensuring the connected device does all of the following:(1) Meets or exceeds the baseline product criteria of a NIST conforming labeling scheme.(2) Satisfies a conformity assessment as described by a NIST conforming labeling scheme that includes a third-party test, inspection, or certification.(3) Bears the binary label as described by a NIST conforming labeling scheme.
5667
5768 SEC. 2. Section 1798.91.04 of the Civil Code, as added by Section 1 of Chapter 860 of the Statutes of 2018, is amended to read:
5869
5970 ### SEC. 2.
6071
6172 1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time.(c) A manufacturer of a connected device may elect to satisfy the requirements of subdivision (a) by ensuring the connected device does all of the following:(1) Meets or exceeds the baseline product criteria of a NIST conforming labeling scheme.(2) Satisfies a conformity assessment as described by a NIST conforming labeling scheme that includes a third-party test, inspection, or certification.(3) Bears the binary label as described by a NIST conforming labeling scheme.
6273
6374 1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time.(c) A manufacturer of a connected device may elect to satisfy the requirements of subdivision (a) by ensuring the connected device does all of the following:(1) Meets or exceeds the baseline product criteria of a NIST conforming labeling scheme.(2) Satisfies a conformity assessment as described by a NIST conforming labeling scheme that includes a third-party test, inspection, or certification.(3) Bears the binary label as described by a NIST conforming labeling scheme.
6475
6576 1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time.(c) A manufacturer of a connected device may elect to satisfy the requirements of subdivision (a) by ensuring the connected device does all of the following:(1) Meets or exceeds the baseline product criteria of a NIST conforming labeling scheme.(2) Satisfies a conformity assessment as described by a NIST conforming labeling scheme that includes a third-party test, inspection, or certification.(3) Bears the binary label as described by a NIST conforming labeling scheme.
6677
6778
6879
6980 1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:
7081
7182 (1) Appropriate to the nature and function of the device.
7283
7384 (2) Appropriate to the information it may collect, contain, or transmit.
7485
7586 (3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.
7687
7788 (b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:
7889
7990 (1) The preprogrammed password is unique to each device manufactured.
8091
8192 (2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time.
8293
8394 (c) A manufacturer of a connected device may elect to satisfy the requirements of subdivision (a) by ensuring the connected device does all of the following:
8495
8596 (1) Meets or exceeds the baseline product criteria of a NIST conforming labeling scheme.
8697
8798 (2) Satisfies a conformity assessment as described by a NIST conforming labeling scheme that includes a third-party test, inspection, or certification.
8899
89100 (3) Bears the binary label as described by a NIST conforming labeling scheme.
90101
91102 SEC. 3. Section 1798.91.05 of the Civil Code, as added by Section 1 of Chapter 860 of the Statutes of 2018, is amended to read:1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the internet, directly or indirectly, and that is assigned an internet protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) NIST conforming labeling scheme means a labeling scheme conforming to the Cybersecurity White Paper titled Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products published by the National Institute of Standards and Technology (NIST) on February 4, 2022, including any revisions or successor publications.(e) Security feature means a feature of a device designed to provide security for that device.(f) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer.
92103
93104 SEC. 3. Section 1798.91.05 of the Civil Code, as added by Section 1 of Chapter 860 of the Statutes of 2018, is amended to read:
94105
95106 ### SEC. 3.
96107
97108 1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the internet, directly or indirectly, and that is assigned an internet protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) NIST conforming labeling scheme means a labeling scheme conforming to the Cybersecurity White Paper titled Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products published by the National Institute of Standards and Technology (NIST) on February 4, 2022, including any revisions or successor publications.(e) Security feature means a feature of a device designed to provide security for that device.(f) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer.
98109
99110 1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the internet, directly or indirectly, and that is assigned an internet protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) NIST conforming labeling scheme means a labeling scheme conforming to the Cybersecurity White Paper titled Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products published by the National Institute of Standards and Technology (NIST) on February 4, 2022, including any revisions or successor publications.(e) Security feature means a feature of a device designed to provide security for that device.(f) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer.
100111
101112 1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the internet, directly or indirectly, and that is assigned an internet protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) NIST conforming labeling scheme means a labeling scheme conforming to the Cybersecurity White Paper titled Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products published by the National Institute of Standards and Technology (NIST) on February 4, 2022, including any revisions or successor publications.(e) Security feature means a feature of a device designed to provide security for that device.(f) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer.
102113
103114
104115
105116 1798.91.05. For the purposes of this title, the following terms have the following meanings:
106117
107118 (a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.
108119
109120 (b) Connected device means any device, or other physical object that is capable of connecting to the internet, directly or indirectly, and that is assigned an internet protocol address or Bluetooth address.
110121
111122 (c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.
112123
113124 (d) NIST conforming labeling scheme means a labeling scheme conforming to the Cybersecurity White Paper titled Recommended Criteria for Cybersecurity Labeling for Consumer Internet of Things (IoT) Products published by the National Institute of Standards and Technology (NIST) on February 4, 2022, including any revisions or successor publications.
114125
115126 (e) Security feature means a feature of a device designed to provide security for that device.
116127
117128 (f) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer.
118129
119130 SEC. 4. Title 1.81.26 (commencing with Section 1798.91.04) of Part 4 of Division 3 of the Civil Code, as added by Section 1 of Chapter 886 of the Statutes of 2018, is repealed.
120131
121132 SEC. 4. Title 1.81.26 (commencing with Section 1798.91.04) of Part 4 of Division 3 of the Civil Code, as added by Section 1 of Chapter 886 of the Statutes of 2018, is repealed.
122133
123134 ### SEC. 4.