<?xml version="1.0" encoding="UTF-8"?><BillSummaries>
<item congress="115" measure-type="hr" measure-number="7327" measure-id="id115hr7327" originChamber="HOUSE" orig-publish-date="2018-12-19" update-date="2019-03-25">
<title>Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure Technology Act</title>
<summary summary-id="id115hr7327v49" currentChamber="BOTH" update-date="2019-03-25">
<action-date>2018-12-21</action-date>
<action-desc>Public Law</action-desc>
<summary-text><![CDATA[<p><b>Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure Technology Act or the SECURE Technology Act</b></p> <p>TITLE I--DEPARTMENT OF HOMELAND SECURITY INFORMATION SECURITY AND OTHER MATTERS</p> <p>(Sec. 101) This bill directs the Department of Homeland Security (DHS) to: (1) establish a policy applicable to individuals, organizations, and companies to report security vulnerabilities on DHS information systems; and (2) develop a process to address the mitigation or remediation of the vulnerabilities reported. DHS shall make such policy publicly available and submit a copy to Congress with the required remediation process.</p> <p>(Sec. 102) DHS shall establish, within the Office of the Chief Information Officer, a bug bounty pilot program to minimize security vulnerabilities.</p> <p> &quot;Bug bounty program&quot; means a program under which: (1) individuals, organizations, and companies are temporarily authorized to identify and report vulnerabilities of DHS information systems; and (2) eligible individuals, organizations, and companies receive compensation in exchange for such reports. </p> <p>TITLE II--FEDERAL ACQUISITION SUPPLY CHAIN SECURITY</p> <p><i>Federal Acquisition Supply Chain Security Act of 2018</i></p> <p>(Sec. 202) This bill establishes a Federal Acquisition Security Council. The council shall: (1) identify and recommend development of supply chain risk management standards, guidelines, and practices for assessing and developing mitigation strategies to address supply chain risks; and (2) develop a strategic plan for addressing supply chain risks posed by the acquisition of certain technology and equipment (covered articles). </p> <p>(Sec. 203) The bill sets forth standards for executive agencies in assessing supply chain risks and extends to such agencies authorities for mitigating supply chain risks in the procurement of covered articles. </p> <p>(Sec. 204) The bill adds agency responsibilities relating to assessing and avoiding, mitigating, transferring, or accepting supply chain risks and complying with exclusion and removal orders.</p>]]></summary-text>
</summary>
<summary summary-id="id115hr7327v00" currentChamber="HOUSE" update-date="2019-03-25">
<action-date>2018-12-19</action-date>
<action-desc>Introduced in House</action-desc>
<summary-text><![CDATA[<p><b>Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure Technology Act or the SECURE Technology Act</b></p> <p>This bill directs the Department of Homeland Security (DHS) to:</p> <ul> <li> establish a policy applicable to individuals, organizations, and companies to report security vulnerabilities on DHS information systems;</li> <li> develop a process to address the mitigation or remediation of the vulnerabilities reported; and</li> <li> establish, within the Office of the Chief Information Officer, a bug bounty pilot program to minimize such vulnerabilities.</li> </ul> <p><i>Federal Acquisition Supply Chain Security Act of 2018</i></p> <p>This bill establishes a Federal Acquisition Security Council. The council shall: (1) identify and recommend development of supply chain risk management standards, guidelines, and practices for assessing and developing mitigation strategies to address supply chain risks; and (2) develop a strategic plan for addressing supply chain risks posed by the acquisition of certain technology and equipment (covered articles). </p> <p>The bill sets forth standards for executive agencies in assessing supply chain risks and extends to such agencies authorities for mitigating supply chain risks in the procurement of covered articles. </p>]]></summary-text>
</summary>
</item>
<dublinCore xmlns:dc="http://purl.org/dc/elements/1.1/">
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
<dc:contributor>Congressional Research Service, Library of Congress</dc:contributor>
<dc:description>This file contains bill summaries for federal legislation. A bill summary describes the most significant provisions of a piece of legislation and details the effects the legislative text may have on current law and federal programs. Bill summaries are authored by the Congressional Research Service (CRS) of the Library of Congress. As stated in Public Law 91-510 (2 USC 166 (d)(6)), one of the duties of CRS is "to prepare summaries and digests of bills and resolutions of a public general nature introduced in the Senate or House of Representatives". For more information, refer to the User Guide that accompanies this file.</dc:description>
</dublinCore>
</BillSummaries>
