Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
IIB
116TH CONGRESS
1ST SESSION
H. R. 328
IN THE SENATE OF THE UNITED STATES
JANUARY 23 (legislative day, JANUARY 22), 2019
Received; read twice and referred to the Committee on Foreign Relations
AN ACT
To require the Secretary of State to design and establish
a Vulnerability Disclosure Process (VDP) to improve De-
partment of State cybersecurity and a bug bounty pro-
gram to identify and report vulnerabilities of internet-
facing information technology of the Department of
State, and for other purposes.
VerDate Sep 11 2014
20:37 Jan 23, 2019
Jkt 089200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6652
E:\BILLS\H328.RFS
H328
pamtmann on DSKBFK8HB2PROD with BILLS
2
HR 328 RFS
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Hack Your State De-
4
partment Act’’.
5
SEC. 2. DEFINITIONS.
6
In this Act:
7
(1) BUG BOUNTY PROGRAM.—The term ‘‘bug
8
bounty program’’ means a program under which an
9
approved individual, organization, or company is
10
temporarily authorized to identify and report
11
vulnerabilities of internet-facing information tech-
12
nology of the Department in exchange for compensa-
13
tion.
14
(2) DEPARTMENT.—The term ‘‘Department’’
15
means the Department of State.
16
(3) INFORMATION
TECHNOLOGY.—The term
17
‘‘information technology’’ has the meaning given
18
such term in section 11101 of title 40, United
19
States Code.
20
(4) SECRETARY.—The term ‘‘Secretary’’ means
21
the Secretary of State.
22
VerDate Sep 11 2014
20:37 Jan 23, 2019
Jkt 089200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H328.RFS
H328
pamtmann on DSKBFK8HB2PROD with BILLS
3
HR 328 RFS
SEC. 3. DEPARTMENT OF STATE VULNERABILITY DISCLO-
1
SURE PROCESS.
2
(a) IN GENERAL.—Not later than 180 days after the
3
date of the enactment of this Act, the Secretary shall de-
4
sign, establish, and make publicly known a Vulnerability
5
Disclosure Process (VDP) to improve Department cyber-
6
security by—
7
(1) providing security researchers with clear
8
guidelines for—
9
(A) conducting vulnerability discovery ac-
10
tivities directed at Department information
11
technology; and
12
(B) submitting discovered security vulnera-
13
bilities to the Department; and
14
(2) creating Department procedures and infra-
15
structure to receive and fix discovered vulnerabili-
16
ties.
17
(b) REQUIREMENTS.—In establishing the VDP pur-
18
suant to paragraph (1), the Secretary shall—
19
(1) identify which Department information
20
technology should be included in the process;
21
(2) determine whether the process should dif-
22
ferentiate among and specify the types of security
23
vulnerabilities that may be targeted;
24
VerDate Sep 11 2014
20:37 Jan 23, 2019
Jkt 089200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H328.RFS
H328
pamtmann on DSKBFK8HB2PROD with BILLS
4
HR 328 RFS
(3) provide a readily available means of report-
1
ing discovered security vulnerabilities and the form
2
in which such vulnerabilities should be reported;
3
(4) identify which Department offices and posi-
4
tions will be responsible for receiving, prioritizing,
5
and addressing security vulnerability disclosure re-
6
ports;
7
(5) consult with the Attorney General regarding
8
how to ensure that individuals, organizations, and
9
companies that comply with the requirements of the
10
process are protected from prosecution under section
11
1030 of title 18, United States Code, and similar
12
provisions of law for specific activities authorized
13
under the process;
14
(6) consult with the relevant offices at the De-
15
partment of Defense that were responsible for
16
launching the 2016 Vulnerability Disclosure Pro-
17
gram, ‘‘Hack the Pentagon’’, and subsequent De-
18
partment of Defense bug bounty programs;
19
(7) engage qualified interested persons, includ-
20
ing nongovernmental sector representatives, about
21
the structure of the process as constructive and to
22
the extent practicable; and
23
VerDate Sep 11 2014
20:37 Jan 23, 2019
Jkt 089200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H328.RFS
H328
pamtmann on DSKBFK8HB2PROD with BILLS
5
HR 328 RFS
(8) award contracts to entities, as necessary, to
1
manage the process and implement the remediation
2
of discovered security vulnerabilities.
3
(c) ANNUAL REPORTS.—Not later than 180 days
4
after the establishment of the VDP under subsection (a)
5
and annually thereafter for the next six years, the Sec-
6
retary of State shall submit to the Committee on Foreign
7
Affairs of the House of Representatives and the Com-
8
mittee on Foreign Relations of the Senate a report on the
9
VDP, including information relating to the following:
10
(1) The number and severity, in accordance
11
with the National Vulnerabilities Database of the
12
National Institute of Standards and Technology, of
13
security vulnerabilities reported.
14
(2) The number of previously unidentified secu-
15
rity vulnerabilities remediated as a result.
16
(3) The current number of outstanding pre-
17
viously unidentified security vulnerabilities and De-
18
partment of State remediation plans.
19
(4) The average length of time between the re-
20
porting of security vulnerabilities and remediation of
21
such vulnerabilities.
22
(5) The resources, surge staffing, roles, and re-
23
sponsibilities within the Department used to imple-
24
VerDate Sep 11 2014
20:37 Jan 23, 2019
Jkt 089200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H328.RFS
H328
pamtmann on DSKBFK8HB2PROD with BILLS
6
HR 328 RFS
ment the VDP and complete security vulnerability
1
remediation.
2
(6) Any other information the Secretary deter-
3
mines relevant.
4
SEC. 4. DEPARTMENT OF STATE BUG BOUNTY PILOT PRO-
5
GRAM.
6
(a) ESTABLISHMENT OF PILOT PROGRAM.—
7
(1) IN
GENERAL.—Not later than one year
8
after the date of the enactment of this Act, the Sec-
9
retary shall establish a bug bounty pilot program to
10
minimize security vulnerabilities of internet-facing
11
information technology of the Department.
12
(2) REQUIREMENTS.—In establishing the pilot
13
program described in paragraph (1), the Secretary
14
shall—
15
(A) provide compensation for reports of
16
previously unidentified security vulnerabilities
17
within the websites, applications, and other
18
internet-facing information technology of the
19
Department that are accessible to the public;
20
(B) award contracts to entities, as nec-
21
essary, to manage such pilot program and for
22
executing the remediation of security vulnerabil-
23
ities identified pursuant to subparagraph (A);
24
VerDate Sep 11 2014
20:37 Jan 23, 2019
Jkt 089200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\H328.RFS
H328
pamtmann on DSKBFK8HB2PROD with BILLS
7
HR 328 RFS
(C) identify which Department information
1
technology should be included in such pilot pro-
2
gram;
3
(D) consult with the Attorney General on
4
how to ensure that individuals, organizations,
5
or companies that comply with the requirements
6
of such pilot program are protected from pros-
7
ecution under section 1030 of title 18, United
8
States Code, and similar provisions of law for
9
specific activities authorized under such pilot
10
program;
11
(E) consult with the relevant offices at the
12
Department of Defense that were responsible
13
for launching the 2016 ‘‘Hack the Pentagon’’
14
pilot program and subsequent Department of
15
Defense bug bounty programs;
16
(F) develop a process by which an ap-
17
proved individual, organization, or company can
18
register with the entity referred to in subpara-
19
graph (B), submit to a background check as de-
20
termined by the Department, and receive a de-
21
termination as to eligibility for participation in
22
such pilot program;
23
(G) engage qualified interested persons, in-
24
cluding nongovernmental sector representatives,
25
VerDate Sep 11 2014
20:37 Jan 23, 2019
Jkt 089200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\H328.RFS
H328
pamtmann on DSKBFK8HB2PROD with BILLS
8
HR 328 RFS
about the structure of such pilot program as
1
constructive and to the extent practicable; and
2
(H) consult with relevant United States
3
Government officials to ensure that such pilot
4
program complements persistent network and
5
vulnerability scans of the Department of State’s
6
internet-accessible systems, such as the scans
7
conducted pursuant to Binding Operational Di-
8
rective BOD–15–01.
9
(3) DURATION.—The pilot program established
10
under paragraph (1) should be short-term in dura-
11
tion and not last longer than one year.
12
(b) REPORT.—Not later than 180 days after the date
13
on which the bug bounty pilot program under subsection
14
(a) is completed, the Secretary shall submit to the Com-
15
mittee on Foreign Relations of the Senate and the Com-
16
mittee on Foreign Affairs of the House of Representatives
17
a report on such pilot program, including information re-
18
lating to—
19
(1) the number of approved individuals, organi-
20
zations, or companies involved in such pilot pro-
21
gram, broken down by the number of approved indi-
22
viduals, organizations, or companies that—
23
(A) registered;
24
(B) were approved;
25
VerDate Sep 11 2014
20:37 Jan 23, 2019
Jkt 089200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\H328.RFS
H328
pamtmann on DSKBFK8HB2PROD with BILLS
9
HR 328 RFS
(C) submitted security vulnerabilities; and
1
(D) received compensation;
2
(2) the number and severity, in accordance with
3
the National Vulnerabilities Database of the Na-
4
tional Institute of Standards and Technology, of se-
5
curity vulnerabilities reported as part of such pilot
6
program;
7
(3) the number of previously unidentified secu-
8
rity vulnerabilities remediated as a result of such
9
pilot program;
10
(4) the current number of outstanding pre-
11
viously unidentified security vulnerabilities and De-
12
partment remediation plans;
13
(5) the average length of time between the re-
14
porting of security vulnerabilities and remediation of
15
such vulnerabilities;
16
(6) the types of compensation provided under
17
such pilot program; and
18
(7) the lessons learned from such pilot pro-
19
gram.
20
Passed the House of Representatives January 22,
2019.
Attest:
KAREN L. HAAS,
Clerk.
VerDate Sep 11 2014
20:37 Jan 23, 2019
Jkt 089200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6201
E:\BILLS\H328.RFS
H328
pamtmann on DSKBFK8HB2PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.