Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 116th Congress · H.R. 3352 (Referred in Senate) — To provide for certain authorities of the Department of State, and for other purposes. · Sec. 506

Sec. 506. Vulnerability Disclosure Policy and Bug Bounty Pilot Program

979 words·~4 min read·/bill/116/hr/3352/rfs/section-506

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

In this section: The term bug bounty program means a program under which an approved individual, organization, or company is temporarily authorized to identify and report vulnerabilities of internet-facing information technology of the Department in exchange for compensation. The term Department means the Department of State. The term information technology has the meaning given such term in section 11101 of title 40, United States Code. The term Secretary means the Secretary of State. Not later than 180 days after the date of the enactment of this Act, the Secretary shall design, establish, and make publicly known a Vulnerability Disclosure Process
(VDP)to improve Department cybersecurity by— providing security researchers with clear guidelines for— conducting vulnerability discovery activities directed at Department information technology; and submitting discovered security vulnerabilities to the Department; and creating Department procedures and infrastructure to receive and fix discovered vulnerabilities. In establishing the VDP pursuant to paragraph (1), the Secretary shall— identify which Department information technology should be included in the process; determine whether the process should differentiate among and specify the types of security vulnerabilities that may be targeted; provide a readily available means of reporting discovered security vulnerabilities and the form in which such vulnerabilities should be reported; identify which Department offices and positions will be responsible for receiving, prioritizing, and addressing security vulnerability disclosure reports; consult with the Attorney General regarding how to ensure that individuals, organizations, and companies that comply with the requirements of the process are protected from prosecution under section 1030 of title 18, United States Code, and similar provisions of law for specific activities authorized under the process; consult with the relevant offices at the Department of Defense that were responsible for launching the 2016 Vulnerability Disclosure Program, Hack the Pentagon , and subsequent Department of Defense bug bounty programs; engage qualified interested persons, including nongovernmental sector representatives, about the structure of the process as constructive and to the extent practicable; and award contracts to entities, as necessary, to manage the process and implement the remediation of discovered security vulnerabilities. Not later than 180 days after the establishment of the VDP under paragraph
(1)and annually thereafter for the next 6 years, the Secretary of State shall submit to the Committee on Foreign Affairs of the House of Representatives and the Committee on Foreign Relations of the Senate a report on the VDP, including information relating to the following: The number and severity, in accordance with the National Vulnerabilities Database of the National Institute of Standards and Technology, of security vulnerabilities reported. The number of previously unidentified security vulnerabilities remediated as a result. The current number of outstanding previously unidentified security vulnerabilities and Department of State remediation plans. The average length of time between the reporting of security vulnerabilities and remediation of such vulnerabilities. The resources, surge staffing, roles, and responsibilities within the Department used to implement the VDP and complete security vulnerability remediation. Any other information the Secretary determines relevant. Not later than 1 year after the date of the enactment of this Act, the Secretary shall establish a bug bounty pilot program to minimize security vulnerabilities of internet-facing information technology of the Department. In establishing the pilot program described in paragraph (1), the Secretary shall— provide compensation for reports of previously unidentified security vulnerabilities within the websites, applications, and other internet-facing information technology of the Department that are accessible to the public; award contracts to entities, as necessary, to manage such pilot program and for executing the remediation of security vulnerabilities identified pursuant to subparagraph (A); identify which Department information technology should be included in such pilot program; consult with the Attorney General on how to ensure that individuals, organizations, or companies that comply with the requirements of such pilot program are protected from prosecution under section 1030 of title 18, United States Code, and similar provisions of law for specific activities authorized under such pilot program; consult with the relevant offices at the Department of Defense that were responsible for launching the 2016 Hack the Pentagon pilot program and subsequent Department of Defense bug bounty programs; develop a process by which an approved individual, organization, or company can register with the entity referred to in subparagraph (B), submit to a background check as determined by the Department, and receive a determination as to eligibility for participation in such pilot program; engage qualified interested persons, including nongovernmental sector representatives, about the structure of such pilot program as constructive and to the extent practicable; and consult with relevant United States Government officials to ensure that such pilot program complements persistent network and vulnerability scans of the Department of State’s internet-accessible systems, such as the scans conducted pursuant to Binding Operational Directive BOD–15–01. The pilot program established under paragraph
(1)should be short-term in duration and not last longer than 1 year. Not later than 180 days after the date on which the bug bounty pilot program under subsection
(a)is completed, the Secretary shall submit to the Committee on Foreign Relations of the Senate and the Committee on Foreign Affairs of the House of Representatives a report on such pilot program, including information relating to— the number of approved individuals, organizations, or companies involved in such pilot program, broken down by the number of approved individuals, organizations, or companies that— registered; were approved; submitted security vulnerabilities; and received compensation; the number and severity, in accordance with the National Vulnerabilities Database of the National Institute of Standards and Technology, of security vulnerabilities reported as part of such pilot program; the number of previously unidentified security vulnerabilities remediated as a result of such pilot program; the current number of outstanding previously unidentified security vulnerabilities and Department remediation plans; the average length of time between the reporting of security vulnerabilities and remediation of such vulnerabilities; the types of compensation provided under such pilot program; and the lessons learned from such pilot program.
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.