US Codex
Bill
Notes

H.R. 6735 — what changed

Public-Private Cybersecurity Cooperation Act

From Introduced in House to Reported in House. 1 section amended and 1 added between Introduced in House and Reported in House.

Section 1 Short title

added This Act may be cited as the “Public-Private Cybersecurity Cooperation Act”.

(a)
removed Vulnerability disclosure policy— The Secretary of Homeland Security shall establish a policy applicable to individuals, organizations, and companies that report security vulnerabilities on Department of Homeland Security public internet websites that shall include—
(1)
removed the information technology to which the policy applies;
(2)
removed the conditions under which parties may legally operate to discover and report security vul­ner­a­bil­i­ties;
(3)
removed how individuals, organizations, and companies should disclose discovered security vul­ner­a­bil­i­ties to the Department;
(4)
removed the communication that parties that report security vulnerabilities should expect from the Department; and
(5)
removed how the Department will disclose, or how parties that report security vulnerabilities may disclose, reported security vulnerabilities.
(b)
removed Remediation process— The Secretary shall develop a process for the Department of Homeland Security to address how the Department will mitigate or remediate security vulnerabilities reported through the policy developed in subsection (a).
(c)
removed Consultation— In developing the security vulnerability disclosure policy under subsection (a), the Secretary shall consult with—
(1)
removed the Attorney General regarding how to ensure that individuals, organizations, and companies that comply with the requirements of the policy developed under subsection (a) are protected from prosecution under section 1030 of title 18, United States Code, civil lawsuits, and similar provisions of law with respect to specific activities authorized under the policy;
(2)
removed the Secretary of Defense and the Administrator of General Services regarding lessons that may be applied from existing vulnerability disclosure programs; and
(3)
removed non-governmental security researchers.
(d)
removed Public availability— The Secretary shall make the policy developed under subsection (a) publicly available.
(e)
removed Submission to Congress—
(1)
removed Not later than 90 days after the date of the enactment of this Act, the Secretary shall submit to Congress the policy required under subsection (a) and the remediation process required under subsection (b).
(2)
removed Not later than one year after creating the policy required under subsection (a) the Secretary shall submit a report to Congress, and annually thereafter for each of the next three years, the Secretary shall brief Congress with the following information with respect to the policy required under subsection (a) and the process required under subsection (b):
(A)
removed the number of unique security vul­ner­a­bil­i­ties reported;
(B)
removed the number of previously unknown security vulnerabilities mitigated or remediated;
(C)
removed the number of unique parties that reported security vulnerabilities; and
(D)
removed the average length of time between the reporting of security vulnerabilities and mitigation or remediation of such vul­ner­a­bil­i­ties.
(f)
removed Definitions— In this section—
(1)
removed the term “security vulnerability” has the meaning given that term in section 1501 of title 6, United States Code, in information technology; and
(2)
removed the term “information system” has the meaning given that term by section 3502 of title 44, United States Code.

Sec. 2 Department of Homeland Security disclosure of security vulnerabilities

added
(a)
added Vulnerability disclosure policy— The Secretary of Homeland Security shall establish a policy applicable to individuals, organizations, and companies that report security vulnerabilities on appropriate information systems of Department of Homeland Security. Such policy shall include each of the following:
(1)
added The appropriate information systems of the Department that individuals, organizations, and companies may use to discover and report security vulnerabilities on appropriate information systems.
(2)
added The conditions and criteria under which individuals, organizations, and companies may operate to discover and report security vulnerabilities.
(3)
added How individuals, organizations, and companies may disclose to the Department security vulnerabilities discovered on appropriate information systems of the Department.
(4)
added The ways in which the Department may communicate with individuals, organizations, and companies that report security vulnerabilities.
(5)
added The process the Department shall use for public disclosure of reported security vulnerabilities.
(b)
added Remediation process— The Secretary of Homeland Security shall develop a process for the Department of Homeland Security to address the mitigation or remediation of the security vulnerabilities reported through the policy developed in subsection (a).
(c)
added Consultation— In developing the security vulnerability disclosure policy under subsection (a), the Secretary of Homeland Security shall consult with each of the following:
(1)
added The Attorney General regarding how to ensure that individuals, organizations, and companies that comply with the requirements of the policy developed under subsection (a) are protected from prosecution under section 1030 of title 18, United States Code, civil lawsuits, and similar provisions of law with respect to specific activities authorized under the policy.
(2)
added The Secretary of Defense and the Administrator of General Services regarding lessons that may be applied from existing vulnerability disclosure policies.
(3)
added Non-governmental security researchers.
(d)
added Public availability— The Secretary of Homeland Security shall make the policy developed under subsection (a) publicly available.
(e)
added Submission to Congress—
(1)
added Disclosure policy and remediation process— Not later than 90 days after the date of the enactment of this Act, the Secretary of Homeland Security shall submit to Congress a copy of the policy required under subsection (a) and the remediation process required under subsection (b).
(2)
added Report and briefing—
(A)
added Report— Not later than one year after establishing the policy required under subsection (a), the Secretary of Homeland Security shall submit to Congress a report on such policy and the remediation process required under subsection (b).
(B)
added Annual briefings— One year after the date of the submission of the report under subparagraph (A), and annually thereafter for each of the next three years, the Secretary of Homeland Security shall provide to Congress a briefing on the policy required under subsection (a) and the process required under subsection (b).
(C)
added Matters for inclusion— The report required under subparagraph (A) and the briefings required under subparagraph (B) shall include each of the following with respect to the policy required under subsection (a) and the process required under subsection (b) for the period covered by the report or briefing, as the case may be:
(i)
added The number of unique security vulnerabilities reported.
(ii)
added The number of previously unknown security vulnerabilities mitigated or remediated.
(iii)
added The number of unique individuals, organizations, and companies that reported security vulnerabilities.
(iv)
added The average length of time between the reporting of security vulnerabilities and mitigation or remediation of such vulnerabilities.
(f)
added Definitions— In this section:
(1)
added The term “security vulnerability” has the meaning given that term in section 102(17) of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501(17)), in information technology.
(2)
added The term “information system” has the meaning given that term by section 3502(12) of title 44, United States Code.
(3)
added The term “appropriate information system” means an information system that the Secretary of Homeland Security selects for inclusion under the vulnerability disclosure policy required by subsection (a).