Federal
Cybersecurity Vulnerability Remediation Act
Source: Congress.gov ·
934 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
IIB
116TH CONGRESS
1ST SESSION H. R. 3710
IN THE SENATE OF THE UNITED STATES
OCTOBER 15, 2019
Received; read twice and referred to the Committee on Homeland Security and
Governmental Affairs
AN ACT
To amend the Homeland Security Act of 2002 to provide
for the remediation of cybersecurity vulnerabilities, and
for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
VerDate Sep 11 2014
23:58 Oct 15, 2019
Jkt 099200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\H3710.RFS
H3710
kjohnson on DSK79L0C42 with BILLS
2
HR 3710 RFS
SECTION 1. SHORT TITLE.
1
This Act may be cited as the ‘‘Cybersecurity Vulner-
2
ability Remediation Act’’.
3
SEC. 2. CYBERSECURITY VULNERABILITIES.
4
Section 2209 of the Homeland Security Act of 2002
5
(6 U.S.C. 659) is amended—
6
(1) in subsection (a)—
7
(A) in paragraph (5), by striking ‘‘and’’
8
after the semicolon at the end;
9
(B) by redesignating paragraph (6) as
10
paragraph (7); and
11
(C) by inserting after paragraph (5) the
12
following new paragraph:
13
‘‘(6) the term ‘cybersecurity vulnerability’ has
14
the meaning given the term ‘security vulnerability’
15
in section 102 of the Cybersecurity Information
16
Sharing Act of 2015 (6 U.S.C. 1501); and’’.
17
(2) in subsection (c)—
18
(A) in paragraph (5)—
19
(i) in subparagraph (A), by striking
20
‘‘and’’ after the semicolon at the end;
21
(ii) by redesignating subparagraph
22
(B) as subparagraph (C);
23
(iii) by inserting after subparagraph
24
(A) the following new subparagraph:
25
VerDate Sep 11 2014
23:58 Oct 15, 2019
Jkt 099200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H3710.RFS
H3710
kjohnson on DSK79L0C42 with BILLS
3
HR 3710 RFS
‘‘(B) sharing mitigation protocols to counter cy-
1
bersecurity vulnerabilities pursuant to subsection
2
(n); and’’; and
3
(iv) in subparagraph (C), as so redes-
4
ignated, by inserting ‘‘and mitigation pro-
5
tocols
to
counter
cybersecurity
6
vulnerabilities in accordance with subpara-
7
graph (B)’’ before ‘‘with Federal’’;
8
(B) in paragraph (7)(C), by striking
9
‘‘sharing’’ and inserting ‘‘share’’; and
10
(C) in paragraph (9), by inserting ‘‘mitiga-
11
tion
protocols
to
counter
cybersecurity
12
vulnerabilities,’’ after ‘‘measures,’’;
13
(3) in subsection (e)(1)(G), by striking the
14
semicolon after ‘‘and’’ at the end; and
15
(4) by adding at the end the following new sub-
16
section:
17
‘‘(n) PROTOCOLS
TO
COUNTER
CYBERSECURITY
18
VULNERABILITIES.—The Director may, as appropriate,
19
identify, develop, and disseminate actionable protocols to
20
mitigate cybersecurity vulnerabilities, including in cir-
21
cumstances in which such vulnerabilities exist because
22
software or hardware is no longer supported by a ven-
23
dor.’’.
24
VerDate Sep 11 2014
23:58 Oct 15, 2019
Jkt 099200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H3710.RFS
H3710
kjohnson on DSK79L0C42 with BILLS
4
HR 3710 RFS
SEC. 3. REPORT ON CYBERSECURITY VULNERABILITIES.
1
(a) REPORT.—Not later than 1 year after the date
2
of the enactment of this Act, the Director of the Cyberse-
3
curity and Infrastructure Security Agency of the Depart-
4
ment of Homeland Security shall submit to the Committee
5
on Homeland Security of the House of Representatives
6
and the Committee on Homeland Security and Govern-
7
mental Affairs of the Senate a report on how the Agency
8
carries out subsection (m) of section 2209 of the Home-
9
land Security Act of 2002 to coordinate vulnerability dis-
10
closures,
including
disclosures
of
cybersecurity
11
vulnerabilities (as such term is defined in such section),
12
and subsection (n) of such section (as added by section
13
2) to disseminate actionable protocols to mitigate cyberse-
14
curity vulnerabilities, that includes the following:
15
(1) A description of the policies and procedures
16
relating to the coordination of vulnerability disclo-
17
sures.
18
(2) A description of the levels of activity in fur-
19
therance of such subsections (m) and (n) of such
20
section 2209.
21
(3) Any plans to make further improvements to
22
how information provided pursuant to such sub-
23
sections can be shared (as such term is defined in
24
such section 2209) between the Department and in-
25
dustry and other stakeholders.
26
VerDate Sep 11 2014
23:58 Oct 15, 2019
Jkt 099200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H3710.RFS
H3710
kjohnson on DSK79L0C42 with BILLS
5
HR 3710 RFS
(4) Any available information on the degree to
1
which such information was acted upon by industry
2
and other stakeholders.
3
(5) A description of how privacy and civil lib-
4
erties are preserved in the collection, retention, use,
5
and sharing of vulnerability disclosures.
6
(b) FORM.—The report required under subsection (b)
7
shall be submitted in unclassified form but may contain
8
a classified annex.
9
SEC. 4. COMPETITION RELATING TO CYBERSECURITY
10
VULNERABILITIES.
11
The Under Secretary for Science and Technology of
12
the Department of Homeland Security, in consultation
13
with the Director of the Cybersecurity and Infrastructure
14
Security Agency of the Department, may establish an in-
15
centive-based program that allows industry, individuals,
16
academia, and others to compete in providing remediation
17
solutions for cybersecurity vulnerabilities (as such term is
18
defined in section 2209 of the Homeland Security Act of
19
2002, as amended by section 2).
20
Passed the House of Representatives September 26,
2019.
Attest:
CHERYL L. JOHNSON,
Clerk.
VerDate Sep 11 2014
23:58 Oct 15, 2019
Jkt 099200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H3710.RFS
H3710
kjohnson on DSK79L0C42 with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.