Sec. 3402. Election Security Bug Bounty Program
387 words·~2 min read·
/bill/116/hr/1/rh/section-3402A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than 1 year after the date of the enactment of this Act, the Secretary shall establish a program to be known as the Election Security Bug Bounty Program (hereafter in this subtitle referred to as the Program ) to improve the cybersecurity of the systems used to administer elections for Federal office by facilitating and encouraging assessments by independent technical experts, in cooperation with State and local election officials and election service providers, to identify and report election cybersecurity vulnerabilities.
Participation in the Program shall be entirely voluntary for State and local election officials and election service providers. In developing the Program, the Secretary shall solicit input from, and encourage participation by, State and local election officials. In establishing and carrying out the Program, the Secretary shall— establish a process for State and local election officials and election service providers to voluntarily participate in the Program; designate appropriate information systems to be included in the Program; provide compensation to eligible individuals, organizations, and companies for reports of previously unidentified security vulnerabilities within the information systems designated under subparagraph
(A)and establish criteria for individuals, organizations, and companies to be considered eligible for such compensation in compliance with Federal laws; consult with the Attorney General on how to ensure that approved individuals, organizations, or companies that comply with the requirements of the Program are protected from prosecution under section 1030 of title 18, United States Code, and similar provisions of law, and from liability under civil actions for specific activities authorized under the Program; consult with the Secretary of Defense and the heads of other departments and agencies that have implemented programs to provide compensation for reports of previously undisclosed vulnerabilities in information systems, regarding lessons that may be applied from such programs; develop an expeditious process by which an individual, organization, or company can register with the Department, submit to a background check as determined by the Department, and receive a determination as to eligibility for participation in the Program; and engage qualified interested persons, including representatives of private entities, about the structure of the Program and, to the extent practicable, establish a recurring competition for independent technical experts to assess election systems for the purpose of identifying and reporting election cybersecurity vulnerabilities; The Secretary may award competitive contracts as necessary to manage the Program.