(a)
In general— Not later than 180 days after the date of the enactment of this Act, the Secretary shall design, establish, and make publicly known a Vulnerability Disclosure Process (VDP) to improve Department cybersecurity by—
(1)
providing security researchers with clear guidelines for—
(A)
conducting vulnerability discovery activities directed at Department information technology; and
(B)
submitting discovered security vulnerabilities to the Department; and
(2)
creating Department procedures and infrastructure to receive and fix discovered vulnerabilities.
(b)
Requirements— In establishing the VDP pursuant to paragraph (1), the Secretary shall—
(1)
identify which Department information technology should be included in the process;
(2)
determine whether the process should differentiate among and specify the types of security vulnerabilities that may be targeted;
(3)
provide a readily available means of reporting discovered security vulnerabilities and the form in which such vulnerabilities should be reported;
(4)
identify which Department offices and positions will be responsible for receiving, prioritizing, and addressing security vulnerability disclosure reports;
(5)
consult with the Attorney General regarding how to ensure that individuals, organizations, and companies that comply with the requirements of the process are protected from prosecution under section 1030 of title 18, United States Code, and similar provisions of law for specific activities authorized under the process;
(6)
consult with the relevant offices at the Department of Defense that were responsible for launching the 2016 Vulnerability Disclosure Program, “Hack the Pentagon”, and subsequent Department of Defense bug bounty programs;
(7)
engage qualified interested persons, including nongovernmental sector representatives, about the structure of the process as constructive and to the extent practicable; and
(8)
award contracts to entities, as necessary, to manage the process and implement the remediation of discovered security vulnerabilities.
(c)
Annual reports— Not later than 180 days after the establishment of the VDP under subsection (a) and annually thereafter for the next six years, the Secretary of State shall submit to the Committee on Foreign Affairs of the House of Representatives and the Committee on Foreign Relations of the Senate a report on the VDP, including information relating to the following:
(1)
The number and severity, in accordance with the National Vulnerabilities Database of the National Institute of Standards and Technology, of security vulnerabilities reported.
(2)
The number of previously unidentified security vulnerabilities remediated as a result.
(3)
The current number of outstanding previously unidentified security vulnerabilities and Department of State remediation plans.
(4)
The average length of time between the reporting of security vulnerabilities and remediation of such vulnerabilities.
(5)
The resources, surge staffing, roles, and responsibilities within the Department used to implement the VDP and complete security vulnerability remediation.
(6)
Any other information the Secretary determines relevant.