In general— Except as provided in subparagraph (B), the term publicly known, with respect to information regarding a vulnerability, means information that—
Classified material— Information about a vulnerability shall not be considered “publicly known” if the information is currently protected as classified and has been inappropriately released to the public.
Vulnerability— The term vulnerability means a design, configuration, or implementation weakness in a technology, product, system, service, or application that can be exploited or triggered to cause unexpected or unintended behavior.
Other participants— Any member of the National Security Council under section 101 of the National Security Act of 1947 (50 U.S.C. 3021) who is not a permanent or ad hoc member of the Board may, with the approval of the President, participate in activities of the Board when requested by the Board.
In general— The Board shall establish policies on matters relating to whether, when, how, to whom, and to what degree information about a vulnerability that is not publicly known should be shared or released by the Federal Government to a non-Federal entity.
Availability to the public— To the degree that the policies established under subparagraph (A) are unclassified, the Board shall make such policies available to the public.
In general— Not later than 180 days after the date of the enactment of this Act, the Board shall submit to Congress and the President a draft of the policies required by subparagraph (A), along with a description of any challenges or impediments that may require legislative or administrative action.
Publication— Not later than 240 days after the date of the enactment of this Act, the Board shall make available to the public a draft of the policies required by subparagraph (A), to the degree that such policies are unclassified.
Requirement— The head of each Federal agency shall, upon obtaining information about a vulnerability that is not publicly known, subject such information to the process established under paragraph (3)(A).
In general— The Board shall establish the process by which the Board determines whether, when, how, to whom, and to what degree the Federal Government shares or releases information to a non-Federal entity about a vulnerability that is not publicly known.
Which technologies, products, systems, services, or applications are subject to the vulnerability, including whether the products or systems are used in core Internet infrastructure, in other critical infrastructure systems, in the United States economy, or in national security systems.
The harm that could occur if an actor, such as an adversary of the United States or a criminal organization, were to obtain information about the vulnerability.
If a Federal entity would like to exploit the vulnerability to obtain information, whether there are other means available to the Federal entity to obtain such information.
In general— Under guidelines established by the Board, a Federal agency may share or release information to a non-Federal entity about a vulnerability without subjecting such information to the process under paragraph (3)(A) if the agency determines that such information is presumptively shareable or releasable. The guidelines shall specify the standards to be used to determine whether or not information is presumptively shareable or releasable for purposes of this paragraph.
Rule of construction— Subparagraph (A) shall not be construed to imply that information which is determined under such subparagraph to be presumptively shareable or releasable is exempt from the requirements of subparagraph (A) of paragraph (5) or the sharing process established under subparagraph (B) of such paragraph.
In general— In any case in which the Board determines under paragraph (3)(A) that information about a vulnerability not otherwise publicly known should be shared with or released to an appropriate vendor, the Board shall provide the information to the Secretary of Homeland Security and the Secretary shall, on behalf of the Federal Government, share or release the information as directed by the Board.
Presumptively shareable or releasable information— In any case in which a Federal agency determines under paragraph (4)(A) that information about a vulnerability is presumptively shareable or releasable, the Federal agency shall provide such information to the Secretary and the Secretary shall, on behalf of the Federal Government, share or release the information.
In general— Not later than 180 days after the date of the enactment of this Act, the Secretary of Homeland Security, in coordination with the Secretary of Commerce, shall establish the process by which the Secretary of Homeland Security shares or releases information pursuant to subparagraph (A).
any sharing or release of information under subparagraph (A) is made in accordance with voluntary consensus standards for disclosure of vulnerabilities; and
the periodic review of vulnerabilities that are determined by the Board, pursuant to the process established under paragraph (3)(A), not to be shareable or releasable, in order to determine whether such vulnerabilities may be shared or released in a manner consistent with the national security interests of the United States; and
the sharing with or releasing to appropriate non-Federal entities of information about vulnerabilities that may be shared or released in a manner consistent with the national security interests of the United States following review under subclause (I).
In general— In the case of a vulnerability that was not publicly known and determined not to be shareable or releasable pursuant to clause (i)(I) and then subsequently becomes publicly known, the vulnerability shall not be subject to the process established under paragraph (3)(A) and shall be subject to such other Federal procedures and inter-agency operation processes as may be applicable, such as procedures and processes established to carry out the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501 et seq.).
In general— Not less frequently than once each year, the Board shall submit to the appropriate committees of Congress a report on the activities of the Board and the policies issued under subsection (d).
Contents— In addition to information about the activities and policies described in subparagraph (A), the report required by such subparagraph shall also include the following:
Availability to the public— For each report submitted under subparagraph (A), the Board shall make an unclassified version of the report available to the public.
In general— Not less frequently than once each year, the Inspector General of the Department of Homeland Security shall, in consultation with the Inspectors General of other Federal agencies whose work is affected by activities of the Board, submit to the appropriate committees of Congress a report on the activities of all such Inspectors General during the preceding year in connection with the activities of the Board, the policies issued under subsection (d), and the sharing and releasing of information about vulnerabilities pursuant to such policies.
Availability to the public— For each report submitted under subparagraph (A), the Inspector General of the Department of Homeland Security shall make an unclassified version of the report available to the public.
Consultation— The Vulnerability Equities Review Board may consult with the Privacy and Civil Liberties Oversight Board as the Vulnerability Equities Review Board considers appropriate.
the Committee on Homeland Security and Governmental Affairs, the Committee on Commerce, Science, and Transportation, and the Select Committee on Intelligence of the Senate; and
the Committee on Homeland Security, the Committee on Oversight and Government Reform, the Committee on Energy and Commerce, and the Permanent Select Committee on Intelligence of the House of Representatives.