★ ANNUAL REVIEW 2027 SPONSORSHIPS NOW OPEN   Learn more →

Log In  |  Become a Member  |  Sponsor  |  ⌕ Search

News/Cyber & Privacy/California Internet of Things Security Law Vague on Standards
Free SampleYou’re reading a free sample of the Cyber & Privacy Brief. Members get every case digest like this, six days a week.See Membership Options
Expert Opinion·Cyber & Privacy Brief

California Internet of Things Security Law Vague on Standards

On Friday, September 28, 2018, California Governor Jerry Brown signed the nation’s first Internet of Things cybersecurity law. Although the new law presents some compliance issues, it does not appear to conflict with federal regulatory policy, unlike some have alleged regarding the state’s recent forays into net neutrality and online privacy.  However, the law’s substantive security language is quite vague – there is no guidance or definition under state law regarding how the term “reasonable” is to be applied to specific security features. And, existing FTC precedent on reasonable security has focused on the need to establish a comprehensive security program, not on individual security features. Moreover, under the law, the device manufacturer’s “reasonable” measures have to be “appropriate” to the device and the information it collects – yet another layer of ambiguity.

Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.