Sec. 734. Bug bounty programs
243 words·~1 min read·
/bill/115/s/3153/pcs/section-734A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
In this section: The term appropriate committees of Congress means— the congressional intelligence committees; the Committee on Homeland Security and Governmental Affairs and the Committee on Armed Services of the Senate; and the Committee on Homeland Security and the Committee on Armed Services of the House of Representatives. The term bug bounty program means a program under which an approved computer security specialist or security researcher is temporarily authorized to identify and report vulnerabilities within the information system of an agency or department of the United States in exchange for compensation.
The term information system has the meaning given such term in section 3502 of title 44, United States Code. Not later than 180 days after the date of the enactment of this Act, the Secretary of Homeland Security, in consultation with the Secretary of Defense, shall submit to the appropriate committees of Congress a strategic plan for appropriate agencies and departments of the United States to implement bug bounty programs. The plan required by paragraph
(1)shall include— an assessment of— the Hack the Pentagon pilot program carried out by the Department of Defense in 2016 and subsequent bug bounty programs in identifying and reporting vulnerabilities within the information systems of the Department of Defense; and private sector bug bounty programs, including such programs implemented by leading technology companies in the United States; and recommendations on the feasibility of initiating bug bounty programs at appropriate agencies and departments of the United States.