US Codex
Bill
Notes

S. 1281 — what changed

Hack the Department of Homeland Security Act of 2018

From Reported in Senate to Engrossed in Senate. 1 section amended between Reported in Senate and Engrossed in Senate.

Sec. 2 Department of Homeland Security bug bounty pilot program

(a)
Definitions— In this section:
(1)
changed Bug bounty program— The term bug bounty program means a program under which an approved computer security specialist individual, organization, or security researcher company is temporarily authorized to identify and report vulnerabilities within the of Internet-facing information system technology of the Department in exchange for cash payment.compensation.
(2)
Department— The term Department means the Department of Homeland Security.
(3)
changed Information system—technology— The term information system technology has the meaning given the term in section 3502 11101 of title 44, 40, United States Code.
(4)
Pilot program— The term pilot program means the bug bounty pilot program required to be established under subsection (b)(1).
(5)
Secretary— The term Secretary means the Secretary of Homeland Security.
(b)
Establishment of pilot program—
(1)
changed In general— Not later than 180 days after the date of enactment of this Act, the Secretary shall establish establish, within the Office of the Chief Information Officer, a bug bounty pilot program to minimize vulnerabilities to the of Internet-facing information systems technology of the Department.
(2)
Requirements— In establishing the pilot program, the Secretary shall—
(A)
changed provide monetary compensation for reports of previously unidentified security vulnerabilities within the websites, applications, and other Internet-facing information systems technology of the Department that are accessible to the public;
(B)
changed develop an expeditious process by which computer security researchers can register with the Department, submit to award a background check competitive contract to an entity, as determined by necessary, to manage the Department, pilot program and receive a determination as to approval for participation in executing the remediation of vulnerabilities identified as a consequence of the pilot program;
(C)
designate mission-critical operations within the Department that should be excluded from the pilot program;
(D)
changed consult with the Attorney General on how to ensure that computer security specialists and security researchers who participate in approved individuals, organizations, or companies that comply with the requirements of the pilot program are protected from prosecution under section 1030 of title 18, United States Code, and similar provisions of law for specific activities authorized under the pilot program;
(E)
consult with the relevant offices at the Department of Defense that were responsible for launching the 2016 “Hack the Pentagon” pilot program and subsequent Department of Defense bug bounty programs;
(F)
changed award competitive contracts as necessary develop an expeditious process by which an approved individual, organization, or company can register with the entity described in subparagraph (B), submit to manage a background check as determined by the pilot program Department, and for executing the remediation of vulnerabilities identified as receive a consequence of determination as to eligibility for participation in the pilot program; and
(G)
changed engage qualified interested persons, including commercial non-government sector representatives, about the structure of the pilot program as constructive and to the extent practicable.
(c)
changed Report— Not later than 90 180 days after the date on which the pilot program is completed, the Secretary of Homeland Security shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the pilot program, which shall include—
(1)
changed the number of computer security researchers approved individuals, organizations, or companies involved in the pilot program, broken down by the number of computer security researchers who—approved individuals, organizations, or companies that—
(A)
registered;
(B)
were approved;
(C)
submitted security vulnerabilities; and
(D)
changed received monetary compensation;
(2)
changed the number and severity of previously unidentified vulnerabilities reported as part of the pilot program;
(3)
the number of previously unidentified security vulnerabilities remediated as a result of the pilot program;
(4)
added the current number of outstanding previously unidentified security vulnerabilities and Department remediation plans;
(5)
renumbered was (4)(6) the average length of time between the reporting of security vulnerabilities and remediation of the vulnerabilities;
(6)
added the types of compensation provided under the pilot program; and
(5)
removed the average amount of monetary compensation paid per unique vulnerability submitted under the pilot program and the total amount of monetary compensation paid to computer security researchers under the pilot program; and
(7)
renumbered was (4)(8) the lessons learned from the pilot program.
(d)
Authorization of appropriations— There are authorized to be appropriated to the Department $250,000 for fiscal year 2018 to carry out this Act.