81_FR_64320 81 FR 64139 - Multistakeholder Process on Internet of Things Security Upgradability and Patching

81 FR 64139 - Multistakeholder Process on Internet of Things Security Upgradability and Patching

DEPARTMENT OF COMMERCE
National Telecommunications and Information Administration

Federal Register Volume 81, Issue 181 (September 19, 2016)

Page Range64139-64141
FR Document2016-22459

The National Telecommunications and Information Administration (NTIA) will convene meetings of a multistakeholder process concerning Internet of Things Security Upgradability and Patching. This Notice announces the first meeting, which is scheduled for October 19, 2016.

Federal Register, Volume 81 Issue 181 (Monday, September 19, 2016)
[Federal Register Volume 81, Number 181 (Monday, September 19, 2016)]
[Notices]
[Pages 64139-64141]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2016-22459]


-----------------------------------------------------------------------

DEPARTMENT OF COMMERCE

National Telecommunications and Information Administration


Multistakeholder Process on Internet of Things Security 
Upgradability and Patching

AGENCY: National Telecommunications and Information Administration, 
U.S. Department of Commerce.

ACTION: Notice of open meeting.

-----------------------------------------------------------------------

SUMMARY: The National Telecommunications and Information Administration 
(NTIA) will convene meetings of a multistakeholder process concerning 
Internet of Things Security Upgradability and Patching. This Notice 
announces the first meeting, which is scheduled for October 19, 2016.

DATES: The meeting will be held on October 19, 2016, from 10:00 a.m. to 
4:00 p.m., Central Daylight Time.

ADDRESSES: The meeting will be held in the Trinity Ballroom at the 
Renaissance Austin Hotel, 9721 Arboretum Boulevard, Austin, Texas 
78759.

FOR FURTHER INFORMATION CONTACT: Allan Friedman, National 
Telecommunications and Information Administration, U.S. Department of 
Commerce, 1401 Constitution Avenue NW., Room 4725, Washington, DC 
20230; telephone: (202) 482-4281; email: [email protected]. Please 
direct media inquiries to NTIA's Office of Public Affairs: (202) 482-
7002; email: [email protected].

SUPPLEMENTARY INFORMATION: 
    Background: In March of 2015 the National Telecommunications and 
Information Administration issued a Request for Comment to ``identify 
substantive cybersecurity issues that affect the digital ecosystem and 
digital economic growth where broad consensus, coordinated action, and 
the development of best practices could substantially improve security 
for organizations and consumers.'' \1\ We received comments from a 
range of stakeholders, including trade associations, large companies, 
cybersecurity startups, civil society organizations and independent 
computer security experts.\2\ The comments recommended a diverse set of 
issues that might be addressed through the multistakeholder process, 
including cybersecurity policy and practice in the emerging area of 
Internet of Things (IoT).
---------------------------------------------------------------------------

    \1\ U.S. Department of Commerce, Internet Policy Task Force, 
Request for Public Comment, Stakeholder Engagement on Cybersecurity 
in the Digital Ecosystem, 80 FR 14360, Docket No. 150312253-5253-01 
(Mar. 19, 2015), available at: https://www.ntia.doc.gov/files/ntia/publications/cybersecurity_rfc_03192015.pdf.
    \2\ NTIA has posted the public comments received at https://www.ntia.doc.gov/federal-register-notice/2015/comments-stakeholder-engagement-cybersecurity-digital-ecosystem.
---------------------------------------------------------------------------

    In a separate but related matter in April 2016, NTIA, the 
Department's Internet Policy Task Force, and its Digital Economy 
Leadership Team sought comments on the benefits, challenges, and 
potential roles for the government in fostering the advancement of the 
Internet of Things.'' \3\ Over 130 stakeholders responded with comments 
addressing many substantive issues and

[[Page 64140]]

opportunities related to IoT.\4\ Security was one of the most common 
topics raised.
---------------------------------------------------------------------------

    \3\ U.S. Department of Commerce, Internet Policy Task Force, 
Request for Public Comment, Benefits, Challenges, and Potential 
Roles for the Government in Fostering the Advancement of the 
Internet of Things, 81 FR 19956, Docket No. 160331306-6306-01 (April 
5, 2016), available at: https://www.ntia.doc.gov/federal-register-notice/2016/rfc-potential-roles-government-fostering-advancement-internet-of-things.
    \4\ NTIA has posted the public comments received at https://www.ntia.doc.gov/federal-register-notice/2016/comments-potential-roles-government-fostering-advancement-internet-of-things.
---------------------------------------------------------------------------

    Many commenters emphasized the need for a secure lifecycle approach 
to IoT devices that considers the development, maintenance, and end-of-
life phases and decisions for a device. On August 2, 2016, after 
reviewing these comments, NTIA announced that the next multistakeholder 
process on cybersecurity would be on IoT security upgradability and 
patching.\5\
---------------------------------------------------------------------------

    \5\ NTIA, Increasing the Potential of IoT through Security and 
Transparency (Aug. 2, 2016), available at: https://www.ntia.doc.gov/blog/2016/increasing-potential-iot-through-security-and-transparency.
---------------------------------------------------------------------------

    The matter of patching vulnerable systems is now an accepted part 
of cybersecurity.\6\ Unaddressed technical flaws in systems leave the 
users of software and systems at risk. The nature of these risks 
varies, and mitigating these risks requires various efforts from the 
developers and owners of these systems. One of the more common means of 
mitigation is for the developer or other maintaining party to issue a 
security patch to address the vulnerability. Patching has become more 
commonly accepted, even for consumers, as more operating systems and 
applications shift to visible reminders and automated updates. Yet as 
one security expert notes, this evolution of the software industry has 
yet to become the dominant model in IoT.\7\
---------------------------------------------------------------------------

    \6\ See, e.g. Murugiah Souppaya and Karen Scarfone, Guide to 
Enterprise Patch Management Technologies, Special Publication 800-40 
Revision 3, National Institute of Standards and Technology, NIST SP 
800-40 (2013) available at: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r3.pdf.
    \7\ Bruce Schneier, The Internet of Things Is Wildly Insecure--
And Often Unpatchable, Wired (Jan. 6, 2014) available at: https://www.schneier.com/blog/archives/2014/01/security_risks_9.html.
---------------------------------------------------------------------------

    To help realize the full innovative potential of IoT, users need 
reasonable assurance that connected devices, embedded systems, and 
their applications will be secure. A key part of that security is the 
mitigation of potential security vulnerabilities in IoT devices or 
applications through patching and security upgrades.
    The ultimate objective of the multistakeholder process is to foster 
a market offering more devices and systems that support security 
upgrades through increased consumer awareness and understanding. 
Enabling a thriving market for patchable IoT requires common 
definitions so that manufacturers and solution providers have shared 
visions for security, and consumers know what they are purchasing. 
Currently, no such common, widely accepted definitions exist, so many 
manufacturers struggle to effectively communicate to consumers the 
security features of their devices. This is detrimental to the digital 
ecosystem as a whole, as it does not reward companies that invest in 
patching and it prevents consumers from making informed purchasing 
choices.
    The immediate goal of this process will be to develop a broad, 
shared definition or set of definitions around security upgradability 
for consumer IoT, as well as strategies for communicating the security 
features of IoT devices to consumers. One initial step will be to 
explore and map out the many dimensions of security upgradability and 
patching for the relevant systems and applications. A goal will be to 
design and explore definitions that are easily understandable, while 
being backed by technical specifications and organizational practices 
and processes. A final step will be to develop a strategy to share 
these definitions throughout the broader development community, and 
ultimately with consumers. This may include raising awareness in the 
consumer space to help consumers understand security options and drive 
market forces.
    Stakeholders will determine the shape of the conversation and the 
process. NTIA has announced that the scope of the discussion will be 
around consumer devices, but stakeholders will ultimately determine 
which technologies, sectors, and applications will be discussed in the 
process, and covered by the resulting definitions and framework.
    While we anticipate a technical discussion in the process of 
exploring security upgrades, NTIA does not expect this discussion to 
develop new technical standards. This multistakeholder process is not a 
formal standards development process. Stakeholders may wish to use 
existing standards in their discussion and definitions, or may wish to 
call for new standards or standards processes as part of their 
recommendations.
    Stakeholders will determine the exact nature of the outcome of this 
process. Because it is unlikely that a one-size-fits-all solution will 
be feasible in this dynamic space, stakeholders will need to determine 
how to scope and organize the work through sub-groups or other means. 
Success of the process will be evaluated by the extent to which 
stakeholders embrace and implement the consensus findings within their 
individual practices or organizations, and work to promulgate them 
throughout the community. Although the stakeholders determine the 
outcome of the process, it is important to note that the process will 
not result in a new law or regulation.
    Matters to Be Considered: The October 19, 2016, meeting will be the 
first in a series of NTIA-convened multistakeholder discussions 
concerning IoT security upgradability and patching. Subsequent meetings 
will follow on a schedule determined by those participating in the 
first meeting. Stakeholders will engage in an open, transparent, 
consensus-driven process to understand the range of issues in security 
upgradability, and develop a set of definitions useful to both industry 
and consumers. The multistakeholder process will involve hearing and 
understanding the perspectives of diverse stakeholders, including a 
range of IoT manufacturers, solution providers, security experts, and 
consumer advocates.
    The October 19, 2016, meeting is intended to bring stakeholders 
together to share the range of views on security upgradability and 
patching, and to establish more concrete goals and structure of the 
process. The objectives of this first meeting are to: (1) Briefly 
review the importance of patching and the challenges in the existing 
ecosystem; (2) briefly share different perspectives on existing 
technologies and practices; (3) engage stakeholders in a discussion of 
key security upgrade dimensions, features, and concerns; (4) engage 
stakeholders in a discussion of logistical issues, including internal 
structures such as a small drafting committee or various working 
groups, and the location and frequency of future meetings; and (5) 
identify concrete goals and stakeholder work following the first 
meeting.
    The main objective of further meetings will be to encourage and 
facilitate continued discussion among stakeholders to build out a 
mapping of the range of issues, and develop a consensus view of a 
consolidated set of potential definitions. Discussions will also cover 
best practices for sharing security information with consumers. This 
discussion may include circulation of stakeholder-developed strawman 
drafts and discussion of the appropriate scope of the initiative. 
Stakeholders may also agree on procedural work plans for the group, 
including additional meetings or modified logistics for future 
meetings. NTIA suggests that stakeholders consider setting clear 
deadlines for a working draft and a phase for external review of this 
draft,

[[Page 64141]]

before reconvening to take account of external feedback.
    More information about stakeholders' work will be available at: 
https://www.ntia.doc.gov/other-publication/2016/multistakeholder-process-iot-security.
    Time and Date: NTIA will convene the first meeting of the 
multistakeholder process on IoT Security Upgradability and Patching on 
October 19, 2016, from 10:00 a.m. to 4:00 p.m., Central Daylight Time. 
Please refer to NTIA's Web site, https://www.ntia.doc.gov/other-publication/2016/multistakeholder-process-iot-security, for the most 
current information.
    Place: The meeting will be held in the Trinity Ballroom at the 
Renaissance Austin Hotel, 9721 Arboretum Boulevard, Austin, Texas 
78759. The location of the meeting is subject to change. Please refer 
to NTIA's Web site, https://www.ntia.doc.gov/other-publication/2016/multistakeholder-process-iot-security, for the most current 
information.
    Other Information: The meeting is open to the public and the press 
on a first-come, first-served basis. Space is limited. To assist the 
agency in determining space and webcast technology requirements, NTIA 
requests that interested persons pre-register for the meeting at 
https://www.ntia.doc.gov/other-publication/2016/multistakeholder-process-iot-security.
    The meeting is physically accessible to people with disabilities. 
Requests for sign language interpretation or other auxiliary aids 
should be directed to Allan Friedman at (202) 482-4281 or 
[email protected] at least seven (7) business days prior to each 
meeting. The meetings will also be webcast. Requests for real-time 
captioning of the webcast or other auxiliary aids should be directed to 
Allan Friedman at (202) 482-4281 or [email protected] at least 
seven (7) business days prior to each meeting. There will be an 
opportunity for stakeholders viewing the webcast to participate 
remotely in the meetings through a moderated conference bridge, 
including polling functionality. Access details for the meetings are 
subject to change. Please refer to NTIA's Web site, http://www.ntia.doc.gov/other-publication/2016/multistakeholder-process-iot-security, for the most current information.

    Dated: September 14, 2016.
Kathy D. Smith,
Chief Counsel, National Telecommunications and Information 
Administration.
[FR Doc. 2016-22459 Filed 9-16-16; 8:45 am]
BILLING CODE 3510-60-P



                                                                                   Federal Register / Vol. 81, No. 181 / Monday, September 19, 2016 / Notices                                                                          64139

                                                                                                                   Company                                                                                     2014 Ad Valorem rate

                                                  Hyundai Steel Company Ltd ......................................................................................................................   0.23 percent ad valorem (de minimis).



                                                  Disclosure                                                             Dated: September 12, 2016.                                         FOR FURTHER INFORMATION CONTACT:
                                                                                                                       Ronald K. Lorentzen,                                                 Allan Friedman, National
                                                     We intend to disclose to parties in                               Acting Assistant Secretary for Enforcement                           Telecommunications and Information
                                                  this proceeding the calculations                                     and Compliance.                                                      Administration, U.S. Department of
                                                  performed for these final results within                                                                                                  Commerce, 1401 Constitution Avenue
                                                  five days of the date of the publication                             Appendix
                                                                                                                                                                                            NW., Room 4725, Washington, DC
                                                  of this notice in the Federal Register, in                           I. Summary                                                           20230; telephone: (202) 482–4281;
                                                  accordance with 19 CFR 351.224(b).                                   II. Period of Review                                                 email: afriedman@ntia.doc.gov. Please
                                                                                                                       III. Scope of the Order                                              direct media inquiries to NTIA’s Office
                                                  Assessment Rates                                                     IV. Attribution of Subsidies                                         of Public Affairs: (202) 482–7002; email:
                                                                                                                       V. Bona Fides Analysis                                               press@ntia.doc.gov.
                                                     In accordance with 19 CFR                                         VI. Analysis of Programs
                                                  351.212(b)(2), the Department intends to                                                                                                  SUPPLEMENTARY INFORMATION:
                                                                                                                       VII. Analysis of Comments
                                                  issue assessment instructions to U.S.                                   Comment 1: Whether the Department
                                                                                                                                                                                               Background: In March of 2015 the
                                                  Customs and Border Protection (CBP) 15                                     Should Initiate an Investigation into the                      National Telecommunications and
                                                  days after the date of publication of                                      GOK’s Provision of Electricity for less                        Information Administration issued a
                                                  these final results to liquidate                                           than adequate remuneration (LTAR)                              Request for Comment to ‘‘identify
                                                  shipments of subject merchandise                                        Comment 2: Whether the Department                                 substantive cybersecurity issues that
                                                                                                                             Improperly Countervailed Acquisition                           affect the digital ecosystem and digital
                                                  produced by DSM and Hyundai Steel                                          Tax Exemptions Received By Hyundai                             economic growth where broad
                                                  entered, or withdrawn form warehouse,                                      Steel under the Restrictions of Special                        consensus, coordinated action, and the
                                                  for consumption on or after January 1,                                     Taxation Act (RSTA) Article 120 in
                                                                                                                             Connection with its Acquisition of
                                                                                                                                                                                            development of best practices could
                                                  2014, through December 31, 2014,
                                                                                                                             HYSCO’s Cold-Rolled Assets                                     substantially improve security for
                                                  without regard to CVDs because a de                                                                                                       organizations and consumers.’’ 1 We
                                                  minimis subsidy rate was calculated for                                 Comment 3: Whether the Department
                                                                                                                             Improperly Countervailed Property Tax                          received comments from a range of
                                                  each company.                                                              Exemptions Received by the Pohang                              stakeholders, including trade
                                                  Cash Deposit Instructions                                                  Plant under the Restriction of Special                         associations, large companies,
                                                                                                                             Location Taxation Act (RSLTA)                                  cybersecurity startups, civil society
                                                    The Department also intends to                                        Comment 4: Whether the Department                                 organizations and independent
                                                                                                                             Should Initiate an Investigation into the
                                                  instruct CBP to collect cash deposits of                                   GOK’s Provision of Electricity for More
                                                                                                                                                                                            computer security experts.2 The
                                                  zero percent on shipments of the subject                                   than Adequate Remuneration (MTAR)                              comments recommended a diverse set of
                                                  merchandise produced and/or exported                                 VIII. Recommendation                                                 issues that might be addressed through
                                                  by DSM and Hyundai Steel entered or                                  [FR Doc. 2016–22403 Filed 9–16–16; 8:45 am]
                                                                                                                                                                                            the multistakeholder process, including
                                                  withdrawn from warehouse, for                                                                                                             cybersecurity policy and practice in the
                                                                                                                       BILLING CODE 3510–DS–P
                                                  consumption on or after the date of                                                                                                       emerging area of Internet of Things
                                                  publication of the final results of this                                                                                                  (IoT).
                                                  review. For all non-reviewed firms, we                               DEPARTMENT OF COMMERCE                                                  In a separate but related matter in
                                                  will instruct CBP to collect cash                                                                                                         April 2016, NTIA, the Department’s
                                                  deposits of estimated countervailing                                 National Telecommunications and                                      Internet Policy Task Force, and its
                                                  duties at the most recent company-                                   Information Administration                                           Digital Economy Leadership Team
                                                  specific or all-others rate applicable to                                                                                                 sought comments on the benefits,
                                                  the company. These cash deposit                                      Multistakeholder Process on Internet                                 challenges, and potential roles for the
                                                  requirements, when imposed, shall                                    of Things Security Upgradability and                                 government in fostering the
                                                                                                                       Patching                                                             advancement of the Internet of
                                                  remain in effect until further notice.
                                                                                                                                                                                            Things.’’ 3 Over 130 stakeholders
                                                                                                                       AGENCY:  National Telecommunications
                                                  Return or Destruction of Proprietary                                                                                                      responded with comments addressing
                                                                                                                       and Information Administration, U.S.
                                                  Information                                                                                                                               many substantive issues and
                                                                                                                       Department of Commerce.
                                                     This notice also serves as a reminder                             ACTION: Notice of open meeting.                                         1 U.S. Department of Commerce, Internet Policy

                                                  to parties subject to administrative                                                                                                      Task Force, Request for Public Comment,
                                                                                                                       SUMMARY:   The National                                              Stakeholder Engagement on Cybersecurity in the
                                                  protective order (APO) of their                                      Telecommunications and Information                                   Digital Ecosystem, 80 FR 14360, Docket No.
                                                  responsibility concerning the                                        Administration (NTIA) will convene                                   150312253–5253–01 (Mar. 19, 2015), available at:
                                                  disposition of proprietary information                               meetings of a multistakeholder process                               https://www.ntia.doc.gov/files/ntia/publications/
                                                  disclosed under APO in accordance                                    concerning Internet of Things Security                               cybersecurity_rfc_03192015.pdf.
                                                                                                                                                                                               2 NTIA has posted the public comments received
                                                  with 19 CFR 351.305(a)(3). Timely                                    Upgradability and Patching. This Notice                              at https://www.ntia.doc.gov/federal-register-notice/
                                                  written notification of the return/                                  announces the first meeting, which is                                2015/comments-stakeholder-engagement-
                                                  destruction of APO materials or                                      scheduled for October 19, 2016.                                      cybersecurity-digital-ecosystem.
mstockstill on DSK3G9T082PROD with NOTICES




                                                  conversion to judicial protective order is                           DATES: The meeting will be held on
                                                                                                                                                                                               3 U.S. Department of Commerce, Internet Policy

                                                  hereby requested. Failure to comply                                                                                                       Task Force, Request for Public Comment, Benefits,
                                                                                                                       October 19, 2016, from 10:00 a.m. to                                 Challenges, and Potential Roles for the Government
                                                  with the regulations and the terms of an                             4:00 p.m., Central Daylight Time.                                    in Fostering the Advancement of the Internet of
                                                  APO is a sanctionable violation.                                     ADDRESSES: The meeting will be held in                               Things, 81 FR 19956, Docket No. 160331306–6306–
                                                                                                                                                                                            01 (April 5, 2016), available at: https://
                                                     We are issuing and publishing these                               the Trinity Ballroom at the Renaissance                              www.ntia.doc.gov/federal-register-notice/2016/rfc-
                                                  final results in accordance with sections                            Austin Hotel, 9721 Arboretum                                         potential-roles-government-fostering-advancement-
                                                  751(a)(1) and 777(i)(1) of the Act.                                  Boulevard, Austin, Texas 78759.                                      internet-of-things.



                                             VerDate Sep<11>2014       21:47 Sep 16, 2016       Jkt 238001     PO 00000       Frm 00014      Fmt 4703     Sfmt 4703      E:\FR\FM\19SEN1.SGM          19SEN1


                                                  64140                      Federal Register / Vol. 81, No. 181 / Monday, September 19, 2016 / Notices

                                                  opportunities related to IoT.4 Security                 have shared visions for security, and                 and work to promulgate them
                                                  was one of the most common topics                       consumers know what they are                          throughout the community. Although
                                                  raised.                                                 purchasing. Currently, no such                        the stakeholders determine the outcome
                                                     Many commenters emphasized the                       common, widely accepted definitions                   of the process, it is important to note
                                                  need for a secure lifecycle approach to                 exist, so many manufacturers struggle to              that the process will not result in a new
                                                  IoT devices that considers the                          effectively communicate to consumers                  law or regulation.
                                                  development, maintenance, and end-of-                   the security features of their devices.                  Matters to Be Considered: The
                                                  life phases and decisions for a device.                 This is detrimental to the digital                    October 19, 2016, meeting will be the
                                                  On August 2, 2016, after reviewing these                ecosystem as a whole, as it does not                  first in a series of NTIA-convened
                                                  comments, NTIA announced that the                       reward companies that invest in                       multistakeholder discussions
                                                  next multistakeholder process on                        patching and it prevents consumers                    concerning IoT security upgradability
                                                  cybersecurity would be on IoT security                  from making informed purchasing                       and patching. Subsequent meetings will
                                                  upgradability and patching.5                            choices.                                              follow on a schedule determined by
                                                     The matter of patching vulnerable                       The immediate goal of this process                 those participating in the first meeting.
                                                  systems is now an accepted part of                      will be to develop a broad, shared                    Stakeholders will engage in an open,
                                                  cybersecurity.6 Unaddressed technical                   definition or set of definitions around               transparent, consensus-driven process
                                                  flaws in systems leave the users of                     security upgradability for consumer IoT,              to understand the range of issues in
                                                  software and systems at risk. The nature                as well as strategies for communicating               security upgradability, and develop a set
                                                  of these risks varies, and mitigating                   the security features of IoT devices to               of definitions useful to both industry
                                                  these risks requires various efforts from               consumers. One initial step will be to                and consumers. The multistakeholder
                                                  the developers and owners of these                      explore and map out the many                          process will involve hearing and
                                                  systems. One of the more common                         dimensions of security upgradability                  understanding the perspectives of
                                                  means of mitigation is for the developer                and patching for the relevant systems                 diverse stakeholders, including a range
                                                  or other maintaining party to issue a                   and applications. A goal will be to                   of IoT manufacturers, solution
                                                  security patch to address the                           design and explore definitions that are               providers, security experts, and
                                                  vulnerability. Patching has become                      easily understandable, while being                    consumer advocates.
                                                  more commonly accepted, even for                        backed by technical specifications and
                                                                                                                                                                   The October 19, 2016, meeting is
                                                  consumers, as more operating systems                    organizational practices and processes.
                                                                                                                                                                intended to bring stakeholders together
                                                  and applications shift to visible                       A final step will be to develop a strategy
                                                                                                                                                                to share the range of views on security
                                                  reminders and automated updates. Yet                    to share these definitions throughout the
                                                                                                                                                                upgradability and patching, and to
                                                  as one security expert notes, this                      broader development community, and
                                                                                                                                                                establish more concrete goals and
                                                  evolution of the software industry has                  ultimately with consumers. This may
                                                                                                                                                                structure of the process. The objectives
                                                  yet to become the dominant model in                     include raising awareness in the
                                                                                                                                                                of this first meeting are to: (1) Briefly
                                                  IoT.7                                                   consumer space to help consumers
                                                                                                                                                                review the importance of patching and
                                                     To help realize the full innovative                  understand security options and drive
                                                                                                          market forces.                                        the challenges in the existing ecosystem;
                                                  potential of IoT, users need reasonable
                                                                                                             Stakeholders will determine the shape              (2) briefly share different perspectives
                                                  assurance that connected devices,
                                                                                                          of the conversation and the process.                  on existing technologies and practices;
                                                  embedded systems, and their
                                                                                                          NTIA has announced that the scope of                  (3) engage stakeholders in a discussion
                                                  applications will be secure. A key part
                                                                                                          the discussion will be around consumer                of key security upgrade dimensions,
                                                  of that security is the mitigation of
                                                                                                          devices, but stakeholders will ultimately             features, and concerns; (4) engage
                                                  potential security vulnerabilities in IoT
                                                                                                          determine which technologies, sectors,                stakeholders in a discussion of logistical
                                                  devices or applications through
                                                                                                          and applications will be discussed in                 issues, including internal structures
                                                  patching and security upgrades.
                                                     The ultimate objective of the                        the process, and covered by the                       such as a small drafting committee or
                                                  multistakeholder process is to foster a                 resulting definitions and framework.                  various working groups, and the
                                                  market offering more devices and                           While we anticipate a technical                    location and frequency of future
                                                  systems that support security upgrades                  discussion in the process of exploring                meetings; and (5) identify concrete goals
                                                  through increased consumer awareness                    security upgrades, NTIA does not expect               and stakeholder work following the first
                                                  and understanding. Enabling a thriving                  this discussion to develop new                        meeting.
                                                  market for patchable IoT requires                       technical standards. This                                The main objective of further
                                                  common definitions so that                              multistakeholder process is not a formal              meetings will be to encourage and
                                                  manufacturers and solution providers                    standards development process.                        facilitate continued discussion among
                                                                                                          Stakeholders may wish to use existing                 stakeholders to build out a mapping of
                                                     4 NTIA has posted the public comments received       standards in their discussion and                     the range of issues, and develop a
                                                  at https://www.ntia.doc.gov/federal-register-notice/    definitions, or may wish to call for new              consensus view of a consolidated set of
                                                  2016/comments-potential-roles-government-               standards or standards processes as part              potential definitions. Discussions will
                                                  fostering-advancement-internet-of-things.                                                                     also cover best practices for sharing
                                                     5 NTIA, Increasing the Potential of IoT through
                                                                                                          of their recommendations.
                                                  Security and Transparency (Aug. 2, 2016), available
                                                                                                             Stakeholders will determine the exact              security information with consumers.
                                                  at: https://www.ntia.doc.gov/blog/2016/increasing-      nature of the outcome of this process.                This discussion may include circulation
                                                  potential-iot-through-security-and-transparency.        Because it is unlikely that a one-size-               of stakeholder-developed strawman
                                                     6 See, e.g. Murugiah Souppaya and Karen
                                                                                                          fits-all solution will be feasible in this            drafts and discussion of the appropriate
                                                  Scarfone, Guide to Enterprise Patch Management          dynamic space, stakeholders will need                 scope of the initiative. Stakeholders may
mstockstill on DSK3G9T082PROD with NOTICES




                                                  Technologies, Special Publication 800–40 Revision
                                                  3, National Institute of Standards and Technology,      to determine how to scope and organize                also agree on procedural work plans for
                                                  NIST SP 800–40 (2013) available at: http://             the work through sub-groups or other                  the group, including additional
                                                  nvlpubs.nist.gov/nistpubs/SpecialPublications/          means. Success of the process will be                 meetings or modified logistics for future
                                                  NIST.SP.800-40r3.pdf.                                   evaluated by the extent to which                      meetings. NTIA suggests that
                                                     7 Bruce Schneier, The Internet of Things Is Wildly

                                                  Insecure—And Often Unpatchable, Wired (Jan. 6,
                                                                                                          stakeholders embrace and implement                    stakeholders consider setting clear
                                                  2014) available at: https://www.schneier.com/blog/      the consensus findings within their                   deadlines for a working draft and a
                                                  archives/2014/01/security_risks_9.html.                 individual practices or organizations,                phase for external review of this draft,


                                             VerDate Sep<11>2014   21:47 Sep 16, 2016   Jkt 238001   PO 00000   Frm 00015   Fmt 4703   Sfmt 4703   E:\FR\FM\19SEN1.SGM   19SEN1


                                                                            Federal Register / Vol. 81, No. 181 / Monday, September 19, 2016 / Notices                                                  64141

                                                  before reconvening to take account of                     Dated: September 14, 2016.                          visiting http://reginfo.gov. All
                                                  external feedback.                                      Kathy D. Smith,                                       comments must be submitted in
                                                     More information about stakeholders’                 Chief Counsel, National Telecommunications            English, or if not, accompanied by an
                                                  work will be available at: https://
                                                                                                          and Information Administration.                       English translation. Comments will be
                                                                                                          [FR Doc. 2016–22459 Filed 9–16–16; 8:45 am]           posted as received to http://
                                                  www.ntia.doc.gov/other-publication/
                                                                                                          BILLING CODE 3510–60–P                                www.cftc.gov.
                                                  2016/multistakeholder-process-iot-
                                                  security.                                                                                                     FOR FURTHER INFORMATION CONTACT:
                                                                                                                                                                Melissa D’Arcy, Special Counsel,
                                                     Time and Date: NTIA will convene                     COMMODITY FUTURES TRADING                             Division of Clearing and Risk,
                                                  the first meeting of the multistakeholder               COMMISSION                                            Commodity Futures Trading
                                                  process on IoT Security Upgradability                                                                         Commission, Three Lafayette Centre,
                                                  and Patching on October 19, 2016, from                  Agency Information Collection                         1155 21st Street NW., Washington, DC
                                                  10:00 a.m. to 4:00 p.m., Central Daylight               Activities Under OMB Review                           20581; (202) 418–5086; email: mdarcy@
                                                  Time. Please refer to NTIA’s Web site,                  AGENCY: Commodity Futures Trading                     cftc.gov, and refer to OMB Control No.
                                                  https://www.ntia.doc.gov/other-                         Commission.                                           3038–0102.
                                                  publication/2016/multistakeholder-                                                                            SUPPLEMENTARY INFORMATION:
                                                                                                          ACTION: Notice.
                                                  process-iot-security, for the most current                                                                       Title: ‘‘Clearing Exemption for Certain
                                                  information.                                            SUMMARY:    In compliance with the                    Swaps Entered into by Cooperatives,’’
                                                     Place: The meeting will be held in the               Paperwork Reduction Act of 1995                       (OMB Control No. 3038–0102). This is
                                                  Trinity Ballroom at the Renaissance                     (‘‘PRA’’), this notice announces that the             a request for extension of a currently
                                                  Austin Hotel, 9721 Arboretum                            Information Collection Request (‘‘ICR’’)              approved information collection.
                                                                                                          abstracted below has been forwarded to                   Abstract: Section 2(h)(1)(A) of the
                                                  Boulevard, Austin, Texas 78759. The
                                                                                                          the Office of Management and Budget                   Commodity Exchange Act requires
                                                  location of the meeting is subject to                                                                         certain entities to submit for clearing
                                                                                                          (‘‘OMB’’) for review and comment. The
                                                  change. Please refer to NTIA’s Web site,                                                                      certain swaps if they are required to be
                                                                                                          ICR describes the nature of the
                                                  https://www.ntia.doc.gov/other-                         information collection and its expected               cleared by the Commission.
                                                  publication/2016/multistakeholder-                      costs and burden.                                     Commission regulation 50.51 permits
                                                  process-iot-security, for the most current                                                                    certain cooperatives to elect not to clear
                                                                                                          DATES: Comments must be submitted on
                                                  information.                                            or before October 19, 2016.                           certain swaps that otherwise would be
                                                     Other Information: The meeting is                    ADDRESSES: Comments regarding the
                                                                                                                                                                required to be cleared, provided that
                                                  open to the public and the press on a                   burden estimated or any other aspect of               they meet certain conditions. The rule
                                                  first-come, first-served basis. Space is                the information collection, including                 further requires the reporting of certain
                                                  limited. To assist the agency in                        suggestions for reducing the burden,                  information if the exemption for
                                                  determining space and webcast                           may be submitted directly to the Office               cooperatives is elected. This collection
                                                  technology requirements, NTIA requests                                                                        pertains to information the Commission
                                                                                                          of Information and Regulatory Affairs
                                                                                                                                                                needs to monitor use of the cooperative
                                                  that interested persons pre-register for                (‘‘OIRA’’) in OMB, within 30 days of the
                                                                                                                                                                exemption and assess market risk in
                                                  the meeting at https://                                 notice’s publication, by email at
                                                                                                                                                                connection therewith. An agency may
                                                  www.ntia.doc.gov/other-publication/                     OIRAsubmissions@omb.eop.gov. Please
                                                                                                                                                                not conduct or sponsor, and a person is
                                                  2016/multistakeholder-process-iot-                      identify the comments by OMB Control
                                                                                                                                                                not required to respond to, a collection
                                                  security.                                               No. 3038–0102. Please provide the
                                                                                                                                                                of information unless it displays a
                                                                                                          Commodity Futures Trading
                                                     The meeting is physically accessible                                                                       currently valid OMB control number.
                                                                                                          Commission (‘‘CFTC’’ or                                  Burden Statement: The Commission
                                                  to people with disabilities. Requests for
                                                                                                          ‘‘Commission’’) with a copy of all                    is revising its estimate of the burden for
                                                  sign language interpretation or other                   submitted comments at the address
                                                  auxiliary aids should be directed to                                                                          this collection to reflect the current
                                                                                                          listed below. Please refer to OMB                     number of respondents and respondent
                                                  Allan Friedman at (202) 482–4281 or                     Control No. 3038–0102, found on http://
                                                  afriedman@ntia.doc.gov at least seven                                                                         burden. The respondent burden for this
                                                                                                          reginfo.gov.                                          collection is estimated to be as follows:
                                                  (7) business days prior to each meeting.                   Comments may also be mailed to the                    Respondents/Affected Entities: Parties
                                                  The meetings will also be webcast.                      Office of Information and Regulatory                  electing the cooperative exemption
                                                  Requests for real-time captioning of the                Affairs, Office of Management and                     under Commission regulation 50.51.
                                                  webcast or other auxiliary aids should                  Budget, Attention: Desk Officer for the                  Estimated Number of Respondents:
                                                  be directed to Allan Friedman at (202)                  Commodity Futures Trading                             25.
                                                  482–4281 or afriedman@ntia.doc.gov at                   Commission, 725 17th Street NW.,                         Estimated Average Burden Hours per
                                                  least seven (7) business days prior to                  Washington, DC 20503, or submitted                    Respondent: 1 hour.
                                                  each meeting. There will be an                          through the Commission’s Web site at                     Estimated Total Annual Burden
                                                  opportunity for stakeholders viewing                    http://comments.cftc.gov. Follow the                  Hours on Respondents: 25 hours.
                                                  the webcast to participate remotely in                  instructions for submitting comments                     Frequency of Collection: Annually; on
                                                  the meetings through a moderated                        through the Web site.                                 occasion.
                                                  conference bridge, including polling                       Comments may also be mailed to:                       There are no capital costs or operating
                                                  functionality. Access details for the                   Christopher Kirkpatrick, Secretary of the             and maintenance costs associated with
                                                                                                          Commission, Commodity Futures
mstockstill on DSK3G9T082PROD with NOTICES




                                                  meetings are subject to change. Please                                                                        this collection.
                                                                                                          Trading Commission, Three Lafayette                     Authority: 44 U.S.C. 3501 et seq.
                                                  refer to NTIA’s Web site, http://
                                                                                                          Centre, 1155 21st Street NW.,
                                                  www.ntia.doc.gov/other-publication/                                                                             Dated: September 14, 2016.
                                                                                                          Washington, DC 20581 or by Hand
                                                  2016/multistakeholder-process-iot-                                                                            Robert N. Sidman,
                                                                                                          Delivery/Courier at the same address.
                                                  security, for the most current                             A copy of the supporting statements                Deputy Secretary of the Commission.
                                                  information.                                            for the collection of information                     [FR Doc. 2016–22481 Filed 9–16–16; 8:45 am]
                                                                                                          discussed above may be obtained by                    BILLING CODE 6351–01–P




                                             VerDate Sep<11>2014   21:47 Sep 16, 2016   Jkt 238001   PO 00000   Frm 00016   Fmt 4703   Sfmt 9990   E:\FR\FM\19SEN1.SGM   19SEN1



Document Created: 2016-09-17 02:30:13
Document Modified: 2016-09-17 02:30:13
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice of open meeting.
DatesThe meeting will be held on October 19, 2016, from 10:00 a.m. to 4:00 p.m., Central Daylight Time.
ContactAllan Friedman, National Telecommunications and Information Administration, U.S. Department of Commerce, 1401 Constitution Avenue NW., Room 4725, Washington, DC 20230; telephone: (202) 482-4281; email: [email protected] Please direct media inquiries to NTIA's Office of Public Affairs: (202) 482- 7002; email: [email protected]
FR Citation81 FR 64139 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR