Cloud Migration Service Providers

  • BIG Data & Analytics
  • CLOUD
  • Data Center
  • IOT
  • Machine Learning & AI
  • SECURITY
  • Server
  • BlockChain
  • Virtualization
You are here: Home / BIG Data & Analytics / What’s the True Impact of California’s New IoT Law?

What’s the True Impact of California’s New IoT Law?

January 31, 2020 by cbn Leave a Comment

While there are a few specifics that IoT manufacturers will have to adhere to, the remainder of the law is a bit fuzzy in terms of consequences.

When California Senate bill 327 passed in 2019, many hailed it as a major victory for the field of IoT device and data protection for not only California, but the rest of the nation as well.

Yet, on closer inspection, the newly enacted law may not have as much bite as many believe. While there are a few specifics that IoT manufacturers will have to adhere to, the remainder of the law is open to interpretation. Additionally, little is said regarding penalties for those companies that are found to be defying the rules.

Image: jamesteohart - stockadobe.com

Image: jamesteohart – stockadobe.com

To better understand the impact of SB 327, I reached out to Ashley Thomas, an associate at the law firm Morris Manning & Martin LLP in Washington D.C. Ashley specializes in technology transactions and cyber security compliance. When I asked why the bill was quite vague in terms of what manufacturers were required to do from an IoT data security perspective, Ashley said, “It helps provide the manufacturer with the flexibility they need to design and implement the cyber security features for their specific product. After all, the law broadly defines an IoT device as anything that can connect to the Internet and assigned an IP address or Bluetooth address. Additionally, given the rapid nature in how technology evolves, any specific requirement might be quickly outdated.”

While SB 327 does leave many details out of how the manufacturer is to provide “reasonable security” measures around exactly how devices are secure, the law does focus on a few “must-haves” from a compliance standpoint. For one, the use of preprogrammed passwords must be unique to each device — and the device must require the user to immediately generate a new means of authentication prior to being granted access to the device configuration settings for the first time.

There is no mention of security patches or how long the manufacturer must protect against emerging security threats from an end-of-life or end-of-support perspective. The law only states that the level of security a device requires depends on what that device does. According to Ashley, this is one of those grey areas that she’d like to see bolstered in the future.

Another obvious omission in the bill revolves around any penalties that the California attorney general might hand out if a manufacturer is found to be not following the law. Ashley was quick to point out that the law does not outline any specific amount from a penalty perspective. “Nor does it offer a private right of action for the consumer. Meaning, the consumer cannot seek legal recourse under this law. However, consumers can use other laws in California to pursue legal action. For example, the consumer may be able to prove that harm was suffered under the States’ unfair and deceptive practices statute. Also, the new California Consumer Privacy Act (CCPA) has a private right of action avenue if the harm suffered was due to breaches of unencrypted or nonredacted data.”

While new IoT and data security laws are helping, Ashley still believes it’s up to the consumer to be the final judge and jury when it comes to choosing which IoT devices can and should reside on their network from a security perspective. “I think you need to evaluate the terms and conditions that a manufacturer outlines from a device and data security perspective. Also, be sure to really understand how the device is configured, what data it is collecting and where that data is going.”

In short, it’s business as usual when vetting IoT devices and manufacturers — even with the newly enacted legislation.

Check out our other related articles on InformationWeek:

Enterprise Guide to Data Privacy

Enterprise Guide to Edge Computing

2020: A look Ahead

[Navigating the ever-changing data center industry is no easy feat. Data Center World is where you and your team can source and explore solutions, technologies and concepts you need to plan, manage and optimize your data center.  Join the IT industry at Data Center World, March 16-19, in San Antonio, TX.
Using the code IW100 will grant you $100 off a conference pass. Learn More Here.]

 

Andrew has well over a decade of enterprise networking under his belt through his consulting practice, which specializes in enterprise network architectures and datacenter build-outs and prior experience at organizations such as State Farm Insurance, United Airlines and the … View Full Bio

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.

More Insights

Share on FacebookShare on TwitterShare on LinkedinShare on Pinterest

Filed Under: BIG Data & Analytics

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Archives

  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • March 2016
  • October 2014

Recent Posts

  • Fintech, Cloud, and Bringing Machine Learning to the Edge
  • The Power of Decision Intelligence: Strategies for Success
  • How Corporate Risk Management is Changing
  • How CINC Cut Down Churn on Its Apps for Real Estate Agents
  • Why Chatbot Experiences Break Down and How Organizations Can Improve Them

Recent Comments

  • Purefit Keto Reviews on Are PDUs Your Best Platform for DCIM Instrumentation?
  • https://gemcr.org/ on 10 Things You Should Know About Deep Learning

Categories

  • BIG Data & Analytics
  • BlockChain
  • CLOUD
  • Data Center
  • IOT
  • Machine Learning & AI
  • SECURITY
  • Server
  • Uncategorized
  • Virtualization

Categories

  • BIG Data & Analytics (1,751)
  • BlockChain (410)
  • CLOUD (3,001)
  • Data Center (638)
  • IOT (1,964)
  • Machine Learning & AI (88)
  • SECURITY (1,421)
  • Server (1)
  • Uncategorized (2,010)
  • Virtualization (331)

Subscribe Our Newsletter

 Subscribing I accept the privacy rules of this site

Copyright © 2022 · News Pro Theme on Genesis Framework · WordPress · Log in