Sec. 3. Report on cybersecurity vulnerabilities
244 words·~1 min read·
/bill/117/hr/2980/eh/section-3A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than 1 year after the date of the enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on how the Agency carries out subsection
(n)of section 2209 of the Homeland Security Act of 2002 to coordinate vulnerability disclosures, including disclosures of cybersecurity vulnerabilities (as such term is defined in such section), and subsection
(o)of such section (as added by section 2) to disseminate actionable protocols to mitigate cybersecurity vulnerabilities to information systems and industrial control systems, that includes the following: A description of the policies and procedures relating to the coordination of vulnerability disclosures. A description of the levels of activity in furtherance of such subsections
(n)and
(o)of such section 2209. Any plans to make further improvements to how information provided pursuant to such subsections can be shared (as such term is defined in such section 2209) between the Department and industry and other stakeholders. Any available information on the degree to which such information was acted upon by industry and other stakeholders. A description of how privacy and civil liberties are preserved in the collection, retention, use, and sharing of vulnerability disclosures. The report required under subsection
(b)shall be submitted in unclassified form but may contain a classified annex.