Federal
Cybersecurity Vulnerability Remediation Act
Source: Congress.gov ·
1,488 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
IIB
117TH CONGRESS
1ST SESSION H. R. 2980
IN THE SENATE OF THE UNITED STATES
JULY 21, 2021
Received; read twice and referred to the Committee on Homeland Security and
Governmental Affairs
AN ACT
To amend the Homeland Security Act of 2002 to provide
for the remediation of cybersecurity vulnerabilities, and
for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\H2980.RFS
H2980
kjohnson on DSK79L0C42PROD with BILLS
2
HR 2980 RFS
SECTION 1. SHORT TITLE.
1
This Act may be cited as the ‘‘Cybersecurity Vulner-
2
ability Remediation Act’’.
3
SEC. 2. CYBERSECURITY VULNERABILITIES.
4
Section 2209 of the Homeland Security Act of 2002
5
(6 U.S.C. 659) is amended—
6
(1) in subsection (a)—
7
(A) in paragraph (5), by striking ‘‘and’’
8
after the semicolon at the end;
9
(B) by redesignating paragraph (6) as
10
paragraph (7); and
11
(C) by inserting after paragraph (5) the
12
following new paragraph:
13
‘‘(6) the term ‘cybersecurity vulnerability’ has
14
the meaning given the term ‘security vulnerability’
15
in section 102 of the Cybersecurity Information
16
Sharing Act of 2015 (6 U.S.C. 1501); and’’.
17
(2) in subsection (c)—
18
(A) in paragraph (5)—
19
(i) in subparagraph (A), by striking
20
‘‘and’’ after the semicolon at the end;
21
(ii) by redesignating subparagraph
22
(B) as subparagraph (C);
23
(iii) by inserting after subparagraph
24
(A) the following new subparagraph:
25
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H2980.RFS
H2980
kjohnson on DSK79L0C42PROD with BILLS
3
HR 2980 RFS
‘‘(B) sharing mitigation protocols to counter cy-
1
bersecurity vulnerabilities pursuant to subsection
2
(n); and’’; and
3
(iv) in subparagraph (C), as so redes-
4
ignated, by inserting ‘‘and mitigation pro-
5
tocols
to
counter
cybersecurity
6
vulnerabilities in accordance with subpara-
7
graph (B)’’ before ‘‘with Federal’’;
8
(B) in paragraph (7)(C), by striking
9
‘‘sharing’’ and inserting ‘‘share’’; and
10
(C) in paragraph (9), by inserting ‘‘mitiga-
11
tion
protocols
to
counter
cybersecurity
12
vulnerabilities,’’ after ‘‘measures,’’;
13
(3) in subsection (e)(1)(G), by striking the
14
semicolon after ‘‘and’’ at the end;
15
(4) by redesignating subsection (o) as sub-
16
section (p); and
17
(5) by inserting after subsection (n) following
18
new subsection:
19
‘‘(o) PROTOCOLS TO COUNTER CERTAIN CYBERSE-
20
CURITY VULNERABILITIES.—The Director may, as appro-
21
priate, identify, develop, and disseminate actionable proto-
22
cols to mitigate cybersecurity vulnerabilities to informa-
23
tion systems and industrial control systems, including in
24
circumstances in which such vulnerabilities exist because
25
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H2980.RFS
H2980
kjohnson on DSK79L0C42PROD with BILLS
4
HR 2980 RFS
software or hardware is no longer supported by a ven-
1
dor.’’.
2
SEC. 3. REPORT ON CYBERSECURITY VULNERABILITIES.
3
(a) REPORT.—Not later than 1 year after the date
4
of the enactment of this Act, the Director of the Cyberse-
5
curity and Infrastructure Security Agency of the Depart-
6
ment of Homeland Security shall submit to the Committee
7
on Homeland Security of the House of Representatives
8
and the Committee on Homeland Security and Govern-
9
mental Affairs of the Senate a report on how the Agency
10
carries out subsection (n) of section 2209 of the Homeland
11
Security Act of 2002 to coordinate vulnerability disclo-
12
sures, including disclosures of cybersecurity vulnerabilities
13
(as such term is defined in such section), and subsection
14
(o) of such section (as added by section 2) to disseminate
15
actionable
protocols
to
mitigate
cybersecurity
16
vulnerabilities to information systems and industrial con-
17
trol systems, that includes the following:
18
(1) A description of the policies and procedures
19
relating to the coordination of vulnerability disclo-
20
sures.
21
(2) A description of the levels of activity in fur-
22
therance of such subsections (n) and (o) of such sec-
23
tion 2209.
24
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H2980.RFS
H2980
kjohnson on DSK79L0C42PROD with BILLS
5
HR 2980 RFS
(3) Any plans to make further improvements to
1
how information provided pursuant to such sub-
2
sections can be shared (as such term is defined in
3
such section 2209) between the Department and in-
4
dustry and other stakeholders.
5
(4) Any available information on the degree to
6
which such information was acted upon by industry
7
and other stakeholders.
8
(5) A description of how privacy and civil lib-
9
erties are preserved in the collection, retention, use,
10
and sharing of vulnerability disclosures.
11
(b) FORM.—The report required under subsection (b)
12
shall be submitted in unclassified form but may contain
13
a classified annex.
14
SEC. 4. COMPETITION RELATING TO CYBERSECURITY
15
VULNERABILITIES.
16
The Under Secretary for Science and Technology of
17
the Department of Homeland Security, in consultation
18
with the Director of the Cybersecurity and Infrastructure
19
Security Agency of the Department, may establish an in-
20
centive-based program that allows industry, individuals,
21
academia, and others to compete in identifying remedi-
22
ation solutions for cybersecurity vulnerabilities (as such
23
term is defined in section 2209 of the Homeland Security
24
Act of 2002, as amended by section 2) to information sys-
25
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H2980.RFS
H2980
kjohnson on DSK79L0C42PROD with BILLS
6
HR 2980 RFS
tems (as such term is defined in such section 2209) and
1
industrial control systems, including supervisory control
2
and data acquisition systems.
3
SEC. 5. TITLE XXII TECHNICAL AND CLERICAL AMEND-
4
MENTS.
5
(a) TECHNICAL AMENDMENTS.—
6
(1) HOMELAND SECURITY ACT OF 2002.—Sub-
7
title A of title XXII of the Homeland Security Act
8
of 2002 (6 U.S.C. 651 et seq.) is amended—
9
(A) in the first section 2215 (6 U.S.C.
10
665; relating to the duties and authorities relat-
11
ing to .gov internet domain), by amending the
12
section enumerator and heading to read as fol-
13
lows:
14
‘‘SEC. 2215. DUTIES AND AUTHORITIES RELATING TO .GOV
15
INTERNET DOMAIN.’’;
16
(B) in the second section 2215 (6 U.S.C.
17
665b; relating to the joint cyber planning of-
18
fice), by amending the section enumerator and
19
heading to read as follows:
20
‘‘SEC. 2216. JOINT CYBER PLANNING OFFICE.’’;
21
(C) in the third section 2215 (6 U.S.C.
22
665c; relating to the Cybersecurity State Coor-
23
dinator), by amending the section enumerator
24
and heading to read as follows:
25
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\H2980.RFS
H2980
kjohnson on DSK79L0C42PROD with BILLS
7
HR 2980 RFS
‘‘SEC. 2217. CYBERSECURITY STATE COORDINATOR.’’;
1
(D) in the fourth section 2215 (6 U.S.C.
2
665d; relating to Sector Risk Management
3
Agencies), by amending the section enumerator
4
and heading to read as follows:
5
‘‘SEC. 2218. SECTOR RISK MANAGEMENT AGENCIES.’’;
6
(E) in section 2216 (6 U.S.C. 665e; relat-
7
ing to the Cybersecurity Advisory Committee),
8
by amending the section enumerator and head-
9
ing to read as follows:
10
‘‘SEC. 2219. CYBERSECURITY ADVISORY COMMITTEE.’’; and
11
(F) in section 2217 (6 U.S.C. 665f; relat-
12
ing to Cybersecurity Education and Training
13
Programs), by amending the section enu-
14
merator and heading to read as follows:
15
‘‘SEC. 2220. CYBERSECURITY EDUCATION AND TRAINING
16
PROGRAMS.’’.
17
(2)
CONSOLIDATED
APPROPRIATIONS
ACT,
18
2021.—Paragraph (1) of section 904(b) of division U
19
of the Consolidated Appropriations Act, 2021 (Pub-
20
lic Law 116–260) is amended, in the matter pre-
21
ceding subparagraph (A), by inserting ‘‘of 2002’’
22
after ‘‘Homeland Security Act’’.
23
(b) CLERICAL AMENDMENT.—The table of contents
24
in section 1(b) of the Homeland Security Act of 2002 is
25
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\H2980.RFS
H2980
kjohnson on DSK79L0C42PROD with BILLS
8
HR 2980 RFS
amended by striking the items relating to sections 2214
1
through 2217 and inserting the following new items:
2
‘‘Sec. 2214. National Asset Database.
‘‘Sec. 2215. Duties and authorities relating to .gov internet domain.
‘‘Sec. 2216. Joint cyber planning office.
‘‘Sec. 2217. Cybersecurity State Coordinator.
‘‘Sec. 2218. Sector Risk Management Agencies.
‘‘Sec. 2219. Cybersecurity Advisory Committee.
‘‘Sec. 2220. Cybersecurity Education and Training Programs.’’.
Passed the House of Representatives July 20, 2021.
Attest:
CHERYL L. JOHNSON,
Clerk.
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\H2980.RFS
H2980
kjohnson on DSK79L0C42PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.