<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-House" bill-type="olc" dms-id="H17E20314E18E4F71902244C550A5BB03" key="H" public-private="public">
	<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 6735 RH: Public-Private Cybersecurity Cooperation Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2018-09-07</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
		<distribution-code display="yes">IB</distribution-code>
		<calendar display="yes">Union Calendar No. 749</calendar>
		<congress display="yes">115th CONGRESS</congress><session display="yes">2d Session</session>
		<legis-num display="yes">H. R. 6735</legis-num>
		<associated-doc display="yes" role="report">[Report No. 115–961]</associated-doc>
		<current-chamber display="yes">IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action display="yes">
			<action-date date="20180907">September 7, 2018</action-date>
			<action-desc><sponsor name-id="M001165">Mr. McCarthy</sponsor> (for himself, <cosponsor name-id="H001073">Mr. Hurd</cosponsor>, <cosponsor name-id="L000559">Mr. Langevin</cosponsor>, and <cosponsor name-id="R000601">Mr. Ratcliffe</cosponsor>) introduced the following bill; which was referred to the <committee-name added-display-style="italic" committee-id="HHM00" deleted-display-style="strikethrough">Committee on Homeland Security</committee-name></action-desc>
		</action>
		<action>
			<action-date>September 25, 2018</action-date>
			<action-desc>Reported with an amendment, committed to the Committee of the Whole House on the State of the
			 Union, and ordered to be printed</action-desc>
			<action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction>
			<action-instruction>For text of introduced bill, see copy of bill as introduced on September 7, 2018</action-instruction>
		</action>
		<action display="yes">
			<action-desc display="yes"><pagebreak></pagebreak></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title display="yes">To direct the Secretary of Homeland Security to establish a vulnerability disclosure policy for
			 Department of Homeland Security internet websites, and for other purposes.<pagebreak></pagebreak></official-title>
	</form>
	<legis-body changed="added" committee-id="HHM00" display-enacting-clause="yes-display-enacting-clause" id="H60DD865CB5224054B5E53A2F71DEA5A0" reported-display-style="italic" style="OLC">
 <section id="H306C3D6FD8E2419E91F38BCCA636F7D3" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Public-Private Cybersecurity Cooperation Act</short-title></quote>.</text> </section><section id="HFDFD7123D119412EA20280FB4E2B1F83" section-type="subsequent-section"><enum>2.</enum><header>Department of Homeland Security disclosure of security vulnerabilities</header> <subsection id="H28DC7772E1E94A559EB4C9FE9CFF66E9"><enum>(a)</enum><header>Vulnerability disclosure policy</header><text>The Secretary of Homeland Security shall establish a policy applicable to individuals, organizations, and companies that report security vulnerabilities on appropriate information systems of Department of Homeland Security. Such policy shall include each of the following:</text>
 <paragraph id="H6D087D1461144DE3B81FF4CB03D21CFB"><enum>(1)</enum><text>The appropriate information systems of the Department that individuals, organizations, and companies may use to discover and report security vulnerabilities on appropriate information systems.</text>
 </paragraph><paragraph id="HDA3665BEB24B4977A681220056300690"><enum>(2)</enum><text>The conditions and criteria under which individuals, organizations, and companies may operate to discover and report security vulnerabilities.</text>
 </paragraph><paragraph id="HE763115D5F444BD3AD2A2953F128DA85"><enum>(3)</enum><text>How individuals, organizations, and companies may disclose to the Department security vulnerabilities discovered on appropriate information systems of the Department.</text>
 </paragraph><paragraph id="HB0325E7A0E964591B93FCDED08734074"><enum>(4)</enum><text>The ways in which the Department may communicate with individuals, organizations, and companies that report security vulnerabilities.</text>
 </paragraph><paragraph id="H5C0566969ED648BEB4C3437DF8AE408D"><enum>(5)</enum><text>The process the Department shall use for public disclosure of reported security vulnerabilities.</text> </paragraph></subsection><subsection id="HEF344788B5064577A5BC2FDC9509F77C"><enum>(b)</enum><header>Remediation process</header><text>The Secretary of Homeland Security shall develop a process for the Department of Homeland Security to address the mitigation or remediation of the security vulnerabilities reported through the policy developed in subsection (a).</text>
 </subsection><subsection id="HAA5CBAA8BDAF479689109944A0DB58B2"><enum>(c)</enum><header>Consultation</header><text>In developing the security vulnerability disclosure policy under subsection (a), the Secretary of Homeland Security shall consult with each of the following:</text>
 <paragraph id="H15092DCB82F64BF1ACD82BEA9E09C53F"><enum>(1)</enum><text>The Attorney General regarding how to ensure that individuals, organizations, and companies that comply with the requirements of the policy developed under subsection (a) are protected from prosecution under section 1030 of title 18, United States Code, civil lawsuits, and similar provisions of law with respect to specific activities authorized under the policy.</text>
 </paragraph><paragraph id="HFC1D1E75C20D4FBF8D91DF22DF5B8876"><enum>(2)</enum><text>The Secretary of Defense and the Administrator of General Services regarding lessons that may be applied from existing vulnerability disclosure policies.</text>
 </paragraph><paragraph id="HB67D249700B04F76B6418DDABCADCB76"><enum>(3)</enum><text>Non-governmental security researchers.</text> </paragraph></subsection><subsection id="H0FD5242573C5421E853C6E991DA70F58"><enum>(d)</enum><header>Public availability</header><text>The Secretary of Homeland Security shall make the policy developed under subsection (a) publicly available.</text>
			</subsection><subsection id="H6A2DA71B273940B08F192F18F103D2D3"><enum>(e)</enum><header>Submission to Congress</header>
 <paragraph id="HF1BA275C003E4FDD8623C0A59869FE66"><enum>(1)</enum><header>Disclosure policy and remediation process</header><text>Not later than 90 days after the date of the enactment of this Act, the Secretary of Homeland Security shall submit to Congress a copy of the policy required under subsection (a) and the remediation process required under subsection (b).</text>
				</paragraph><paragraph id="HB513AB753A034207971B987323D2C344"><enum>(2)</enum><header>Report and briefing</header>
 <subparagraph id="H6CD4DAC5633F4958ADE2FE90F365ABFC"><enum>(A)</enum><header>Report</header><text>Not later than one year after establishing the policy required under subsection (a), the Secretary of Homeland Security shall submit to Congress a report on such policy and the remediation process required under subsection (b).</text>
 </subparagraph><subparagraph id="HA6B103842FDD48799CBCE55CEFB8C4D4"><enum>(B)</enum><header>Annual briefings</header><text>One year after the date of the submission of the report under subparagraph (A), and annually thereafter for each of the next three years, the Secretary of Homeland Security shall provide to Congress a briefing on the policy required under subsection (a) and the process required under subsection (b).</text>
 </subparagraph><subparagraph id="H569CA3FD5F4B4C68983E1732AE766577"><enum>(C)</enum><header>Matters for inclusion</header><text>The report required under subparagraph (A) and the briefings required under subparagraph (B) shall include each of the following with respect to the policy required under subsection (a) and the process required under subsection (b) for the period covered by the report or briefing, as the case may be:</text>
 <clause id="HA169933729D140F99B7D6B2D57ECEAC5"><enum>(i)</enum><text>The number of unique security vulnerabilities reported.</text> </clause><clause id="HD1E74E23B8AD409A9F883F35FCDBD051"><enum>(ii)</enum><text>The number of previously unknown security vulnerabilities mitigated or remediated.</text>
 </clause><clause id="HAD8EA628C42E40CF9DC07B075E4C229F"><enum>(iii)</enum><text>The number of unique individuals, organizations, and companies that reported security vulnerabilities.</text>
 </clause><clause id="H591380AB07124BA8B44329D647554B6D"><enum>(iv)</enum><text>The average length of time between the reporting of security vulnerabilities and mitigation or remediation of such vulnerabilities.</text>
 </clause></subparagraph></paragraph></subsection><subsection id="HB97C19406EFC4E01BA789B89847BE26C"><enum>(f)</enum><header>Definitions</header><text>In this section:</text> <paragraph id="H333C6DDEDE1B4F1DBB0E28F66EC56440"><enum>(1)</enum><text>The term <quote>security vulnerability</quote> has the meaning given that term in section 102(17) of the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501(17)</external-xref>), in information technology.</text>
 </paragraph><paragraph id="H0A9EA96A7FD34667B7E6775278BC6A19"><enum>(2)</enum><text>The term <quote>information system</quote> has the meaning given that term by section 3502(12) of title 44, United States Code.</text> </paragraph><paragraph id="HFD15536F18EE48FDBD1FF9EAADED6F8B"><enum>(3)</enum><text>The term <quote>appropriate information system</quote> means an information system that the Secretary of Homeland Security selects for inclusion under the vulnerability disclosure policy required by subsection (a).</text>
				</paragraph></subsection></section></legis-body>
	<endorsement display="yes">
		<action-date>September 25, 2018</action-date>
		<action-desc>Reported with an amendment, committed to the Committee of the Whole House on the State of the
			 Union, and ordered to be printed</action-desc></endorsement>
</bill>


