Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
116TH CONGRESS
1ST SESSION
S. 1808
To require the Secretary of State to design and establish a Vulnerability
Disclosure Process to improve Department of State cybersecurity and
a bug bounty program to identify and report vulnerabilities of Internet-
facing information technology of the Department of State, and for other
purposes.
IN THE SENATE OF THE UNITED STATES
JUNE 12, 2019
Mr. GARDNER (for himself and Mr. MARKEY) introduced the following bill;
which was read twice and referred to the Committee on Foreign Relations
A BILL
To require the Secretary of State to design and establish
a Vulnerability Disclosure Process to improve Depart-
ment of State cybersecurity and a bug bounty program
to identify and report vulnerabilities of Internet-facing
information technology of the Department of State, and
for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Hack Your State De-
4
partment Act’’.
5
VerDate Sep 11 2014
02:29 Jun 14, 2019
Jkt 089200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\S1808.IS
S1808
pamtmann on DSKBFK8HB2PROD with BILLS
2
•S 1808 IS
SEC. 2. DEFINITIONS.
1
In this Act:
2
(1) BUG BOUNTY PROGRAM.—The term ‘‘bug
3
bounty program’’ means a program under which an
4
approved individual, organization, or company is
5
temporarily authorized to identify and report vulner-
6
abilities of Internet-facing information technology of
7
the Department in exchange for compensation.
8
(2) DEPARTMENT.—The term ‘‘Department’’
9
means the Department of State.
10
(3) INFORMATION
TECHNOLOGY.—The term
11
‘‘information technology’’ has the meaning given
12
such term in section 11101 of title 40, United
13
States Code.
14
(4) SECRETARY.—The term ‘‘Secretary’’ means
15
the Secretary of State.
16
(5) VDP.—The term ‘‘VDP’’ means the Vul-
17
nerability Disclosure Process established pursuant to
18
section 3.
19
SEC. 3. DEPARTMENT OF STATE VULNERABILITY DISCLO-
20
SURE PROCESS.
21
(a) IN GENERAL.—Not later than 180 days after the
22
date of the enactment of this Act, the Secretary shall de-
23
sign, establish, and make publicly known a Vulnerability
24
Disclosure Process to improve cybersecurity within the
25
Department by—
26
VerDate Sep 11 2014
02:29 Jun 14, 2019
Jkt 089200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\S1808.IS
S1808
pamtmann on DSKBFK8HB2PROD with BILLS
3
•S 1808 IS
(1) providing security researchers with clear
1
guidelines for—
2
(A) conducting vulnerability discovery ac-
3
tivities directed at Department information
4
technology; and
5
(B) submitting discovered security vulnera-
6
bilities to the Department; and
7
(2) creating Department procedures and infra-
8
structure to receive and fix discovered vulnerabili-
9
ties.
10
(b) REQUIREMENTS.—In establishing VDP pursuant
11
to subsection (a), the Secretary shall—
12
(1) identify which Department information
13
technology should be included in the process;
14
(2) determine whether the process should dif-
15
ferentiate among and specify the types of security
16
vulnerabilities that may be targeted;
17
(3) provide a readily available means of report-
18
ing discovered security vulnerabilities and the form
19
in which such vulnerabilities should be reported;
20
(4) identify which Department offices and posi-
21
tions will be responsible for receiving, prioritizing,
22
and addressing security vulnerability disclosure re-
23
ports;
24
VerDate Sep 11 2014
02:29 Jun 14, 2019
Jkt 089200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\S1808.IS
S1808
pamtmann on DSKBFK8HB2PROD with BILLS
4
•S 1808 IS
(5) consult with the Attorney General regarding
1
how to ensure that individuals, organizations, and
2
companies that comply with the VDP requirements
3
are protected from prosecution under section 1030
4
of title 18, United States Code, and similar provi-
5
sions of law for specific activities authorized under
6
VDP;
7
(6) consult with the relevant offices at the De-
8
partment of Defense that were responsible for
9
launching the 2016 Vulnerability Disclosure Pro-
10
gram, ‘‘Hack the Pentagon’’, and subsequent De-
11
partment of Defense bug bounty programs;
12
(7) engage qualified interested persons, includ-
13
ing nongovernmental sector representatives, about
14
the structure of VDP, as constructive and to the ex-
15
tent practicable; and
16
(8) award contracts to entities, as necessary, to
17
manage VDP and implement the remediation of dis-
18
covered security vulnerabilities.
19
(c) ANNUAL REPORTS.—Not later than 180 days
20
after the establishment of VDP under subsection (a) and
21
annually thereafter for the following 6 years, the Secretary
22
shall submit a report to the Committee on Foreign Rela-
23
tions of the Senate and the Committee on Foreign Affairs
24
VerDate Sep 11 2014
02:29 Jun 14, 2019
Jkt 089200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\S1808.IS
S1808
pamtmann on DSKBFK8HB2PROD with BILLS
5
•S 1808 IS
of the House of Representatives regarding the establish-
1
ment of VDP, including information relating to—
2
(1) the number and severity, in accordance with
3
the National Vulnerabilities Database of the Na-
4
tional Institute of Standards and Technology, of se-
5
curity vulnerabilities reported through VDP;
6
(2) the number of previously unidentified secu-
7
rity vulnerabilities remediated as a result of such re-
8
porting;
9
(3) the current number of outstanding pre-
10
viously unidentified security vulnerabilities and the
11
Department’s remediation plans to address such
12
vulnerabilities;
13
(4) the average period between the reporting of
14
security vulnerabilities and the remediation of such
15
vulnerabilities;
16
(5) the resources, surge staffing, roles, and re-
17
sponsibilities within the Department used to imple-
18
ment VDP and complete the necessary security vul-
19
nerability remediation; and
20
(6) any other information that the Secretary
21
determines to be relevant.
22
SEC. 4. DEPARTMENT OF STATE BUG BOUNTY PILOT PRO-
23
GRAM.
24
(a) ESTABLISHMENT OF PILOT PROGRAM.—
25
VerDate Sep 11 2014
02:29 Jun 14, 2019
Jkt 089200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\S1808.IS
S1808
pamtmann on DSKBFK8HB2PROD with BILLS
6
•S 1808 IS
(1) IN GENERAL.—Not later than 1 year after
1
the date of the enactment of this Act, the Secretary
2
shall establish a Bug Bounty Pilot Program to mini-
3
mize security vulnerabilities of Internet-facing infor-
4
mation technology of the Department.
5
(2) REQUIREMENTS.—In establishing the pilot
6
program under paragraph (1), the Secretary shall—
7
(A) provide compensation for reports of
8
previously unidentified security vulnerabilities
9
within the websites, applications, and other
10
Internet-facing information technology of the
11
Department that are accessible to the public;
12
(B) award contracts to entities, as nec-
13
essary, to manage the pilot program and for
14
executing the remediation of security vulnerabil-
15
ities identified pursuant to subparagraph (A);
16
(C) identify which Department information
17
technology should be included in the pilot pro-
18
gram;
19
(D) consult with the Attorney General on
20
how to ensure that individuals, organizations,
21
or companies that comply with the requirements
22
of the pilot program are protected from pros-
23
ecution under section 1030 of title 18, United
24
States Code, and similar provisions of law for
25
VerDate Sep 11 2014
02:29 Jun 14, 2019
Jkt 089200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\S1808.IS
S1808
pamtmann on DSKBFK8HB2PROD with BILLS
7
•S 1808 IS
specific activities authorized under the pilot
1
program;
2
(E) consult with the relevant offices at the
3
Department of Defense that were responsible
4
for launching the 2016 ‘‘Hack the Pentagon’’
5
pilot program and subsequent Department of
6
Defense bug bounty programs;
7
(F) develop a process by which an ap-
8
proved individual, organization, or company
9
can—
10
(i) register with entities referred to in
11
subparagraph (B);
12
(ii) submit to a background check, as
13
determined by the Department; and
14
(iii) receive a determination as to eli-
15
gibility for participation in the pilot pro-
16
gram;
17
(G) engage qualified interested persons, in-
18
cluding nongovernmental sector representatives,
19
about the structure of the pilot program, as
20
constructive and to the extent practicable; and
21
(H) consult with relevant United States
22
Government officials to ensure that the pilot
23
program complements persistent network and
24
vulnerability scans of the Department’s Inter-
25
VerDate Sep 11 2014
02:29 Jun 14, 2019
Jkt 089200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\S1808.IS
S1808
pamtmann on DSKBFK8HB2PROD with BILLS
8
•S 1808 IS
net-accessible systems, such as the scans con-
1
ducted pursuant to Binding Operational Direc-
2
tive 15–01, issued by the Secretary of Home-
3
land Security on May 21, 2015.
4
(3) DURATION.—The pilot program established
5
under paragraph (1) should be terminated not later
6
than 1 year after the date on which it is established.
7
(b) REPORT.—Not later than 180 days after the com-
8
pletion of the Bug Bounty Pilot Program under subsection
9
(a), the Secretary shall submit a report to the Committee
10
on Foreign Relations of the Senate and the Committee
11
on Foreign Affairs of the House of Representatives that
12
describes the pilot program, including information regard-
13
ing—
14
(1) the number of approved individuals, organi-
15
zations, or companies involved in the pilot program,
16
broken down by—
17
(A) the number of approved individuals,
18
organizations, or companies that registered for
19
the pilot program;
20
(B) the number of such entities that were
21
approved to participate in the pilot program;
22
(C) the number of such entities that sub-
23
mitted security vulnerabilities under the pilot
24
program; and
25
VerDate Sep 11 2014
02:29 Jun 14, 2019
Jkt 089200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\S1808.IS
S1808
pamtmann on DSKBFK8HB2PROD with BILLS
9
•S 1808 IS
(D) the number of such entities that re-
1
ceived compensation under the pilot program;
2
(2) the number and severity, in accordance with
3
the National Vulnerabilities Database of the Na-
4
tional Institute of Standards and Technology, of se-
5
curity vulnerabilities reported under the pilot pro-
6
gram;
7
(3) the number of previously unidentified secu-
8
rity vulnerabilities remediated as a result of the pilot
9
program;
10
(4) the current number of outstanding pre-
11
viously unidentified security vulnerabilities and the
12
Department’s plans for remediating such vulnerabili-
13
ties;
14
(5) the average period between the reporting of
15
security vulnerabilities and the remediation of such
16
vulnerabilities;
17
(6) the types of compensation provided under
18
the pilot program; and
19
(7) the lessons learned from the pilot program.
20
Æ
VerDate Sep 11 2014
02:29 Jun 14, 2019
Jkt 089200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6301
E:\BILLS\S1808.IS
S1808
pamtmann on DSKBFK8HB2PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.