S. 1281 — what changed
Hack the Department of Homeland Security Act of 2018
From Referred in House to Reported in House. 2 sections amended between Referred in House and Reported in House.
Section 1 Short title
changed
This Act may be cited as the “Hack the Department of Homeland Security Act of 2017” 2018” or the “Hack DHS Act”.
Sec. 2 Department of Homeland Security bug bounty pilot program
Definitions— In this section:
changed
Bug bounty program— The term bug “bug bounty program program” means a program under which an approved individual, organization, or company is temporarily authorized to identify and report vulnerabilities of Internet-facing information technology of the Department in exchange for compensation.which—
added
individuals, organizations, and companies are temporarily authorized to identify and report vulnerabilities of appropriate information systems of the Department; and
added
eligible individuals, organizations, and companies receive compensation in exchange for such reports.
Department— The term Department means the Department of Homeland Security.
changed
Information technology—Eligible individual, organization, or company— The term information technology has the meaning given “eligible individual, organization, or company” means an individual, organization, or company that meets such criteria as the term Secretary determines in section 11101 of title 40, United States Code.order to receive compensation in compliance with Federal laws.
added
Information system— The term “information system” has the meaning given that term by section 3502 of title 44, United States Code.
renumbered
was (2)(6)
Pilot program— The term pilot program means the bug bounty pilot program required to be established under subsection (b)(1).
renumbered
was (2)(7)
Secretary— The term Secretary means the Secretary of Homeland Security.
Establishment of pilot program—
changed
In general— Not later than 180 days after the date of enactment of this Act, the Secretary shall establish, within the Office of the Chief Information Officer, a bug bounty pilot program to minimize vulnerabilities of Internet-facing appropriate information technology systems of the Department.
changed
Requirements— In establishing and conducting the pilot program, the Secretary shall—
changed
provide compensation for reports of previously unidentified security vulnerabilities within the websites, applications, and other Internet-facing designate appropriate information technology of the Department that are accessible systems to be included in the public;pilot program;
changed
award a competitive contract to an entity, as necessary, provide compensation to manage the pilot program eligible individuals, organizations, and companies for executing the remediation reports of previously unidentified security vulnerabilities identified as a consequence of within the pilot program;information systems designated under subparagraph (A);
changed
designate mission-critical operations within the Department that should establish criteria for individuals, organizations, and companies to be excluded from considered eligible for compensation under the pilot program;program in compliance with Federal laws;
changed
consult with the Attorney General on how to ensure that approved individuals, organizations, or companies that comply with the requirements of the pilot program are protected from prosecution under section 1030 of title 18, United States Code, and similar provisions of law law, and civil lawsuits for specific activities authorized under the pilot program;
changed
consult with the relevant offices at the Department Secretary of Defense that were responsible for launching the 2016 “Hack and the Pentagon” pilot program heads of other departments and subsequent Department agencies that have implemented programs to provide compensation for reports of Defense bug bounty programs;previously undisclosed vulnerabilities in information systems, regarding lessons that may be applied from such programs; and
changed
develop an expeditious process by which an approved individual, organization, or company can register with the entity described in subparagraph (B), Department, submit to a background check as determined by the Department, and receive a determination as to eligibility for participation in the pilot program; eligibility; and
engage qualified interested persons, including non-government sector representatives, about the structure of the pilot program as constructive and to the extent practicable.
added
Contract— In establishing the pilot program, the Secretary, subject to the availability of appropriations, may award one or more competitive contracts to an entity, as necessary, to manage the pilot program.
Report— Not later than 180 days after the date on which the pilot program is completed, the Secretary of Homeland Security shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the pilot program, which shall include—
changed
the number of approved individuals, organizations, or companies involved that participated in the pilot program, broken down by the number of approved individuals, organizations, or companies that—
registered;
changed
were approved;determined eligible;
submitted security vulnerabilities; and
received compensation;
the number and severity of vulnerabilities reported as part of the pilot program;
the number of previously unidentified security vulnerabilities remediated as a result of the pilot program;
the current number of outstanding previously unidentified security vulnerabilities and Department remediation plans;
the average length of time between the reporting of security vulnerabilities and remediation of the vulnerabilities;
the types of compensation provided under the pilot program; and
the lessons learned from the pilot program.
changed
Authorization of appropriations— There are authorized to be appropriated to the Department $250,000 for fiscal year 2018 2019 to carry out this Act.