<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Engrossed-in-House" dms-id="H3E41C322403448CDA354F77F95CD48B4" public-private="public" key="H" bill-type="olc" stage-count="1"> 
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 2980 EH: Cybersecurity Vulnerability Remediation Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date></dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="no">I</distribution-code> 
<congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session> 
<legis-num display="yes">H. R. 2980</legis-num> 
<current-chamber display="no">IN THE HOUSE OF REPRESENTATIVES</current-chamber> 
<legis-type>AN ACT</legis-type> 
<official-title display="yes">To amend the Homeland Security Act of 2002 to provide for the remediation of cybersecurity vulnerabilities, and for other purposes.</official-title> 
</form> 
<legis-body id="HF2DFA5955A9048B4A7AAC7A0C0C01AF8" style="OLC"> 
<section id="HD333030F39134510BA5CB6A79E87D682" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Cybersecurity Vulnerability Remediation Act</short-title></quote>.</text></section> <section id="H09A34D620BA048FBA78662CD770910EC"><enum>2.</enum><header>Cybersecurity vulnerabilities</header><text display-inline="no-display-inline">Section 2209 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>) is amended—</text> 
<paragraph id="H1A8AD541D11D41E0A04C6BDF2B7A7294"><enum>(1)</enum><text>in subsection (a)—</text> <subparagraph id="H3AE5EC8CFC244BCA9CECA542AAE7A6B8"><enum>(A)</enum><text>in paragraph (5), by striking <quote>and</quote> after the semicolon at the end;</text></subparagraph> 
<subparagraph id="HD4280460CA0F429DA069B24115E7F5C9"><enum>(B)</enum><text>by redesignating paragraph (6) as paragraph (7); and</text></subparagraph> <subparagraph id="H2FF1E1CB739D4DC7A7F88756925E89EA"><enum>(C)</enum><text>by inserting after paragraph (5) the following new paragraph:</text> 
<quoted-block display-inline="no-display-inline" id="HA03788BC0CAF46B5AA7DED17B4B4E0EB" style="OLC"> 
<paragraph id="H95118DB5462F412B9E98E5B81C43626C"><enum>(6)</enum><text display-inline="yes-display-inline">the term <quote>cybersecurity vulnerability</quote> has the meaning given the term <quote>security vulnerability</quote> in section 102 of the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501</external-xref>); and</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph> <paragraph id="H4613B87D9B1144AB870F6B2E8D561CDC"><enum>(2)</enum><text>in subsection (c)—</text> 
<subparagraph id="H289A1D7318A04C159B7338AB00D59F3D"><enum>(A)</enum><text>in paragraph (5)—</text> <clause id="HA42F75F68B964D5298EE0C4D1B633CBB"><enum>(i)</enum><text>in subparagraph (A), by striking <quote>and</quote> after the semicolon at the end;</text></clause> 
<clause id="H311FDD599DD04B80BAD7E07E11EE3545"><enum>(ii)</enum><text>by redesignating subparagraph (B) as subparagraph (C);</text></clause> <clause id="HB7ED377CF8814746A9C2566A76AF6068"><enum>(iii)</enum><text>by inserting after subparagraph (A) the following new subparagraph:</text> 
<quoted-block display-inline="no-display-inline" id="HD6FE9297D7C04122AB52689BB244B762" style="OLC"> 
<subparagraph commented="no" id="HDAF3285ADD6249BDA90D82768FAD9462" indent="up1"><enum>(B)</enum><text display-inline="yes-display-inline">sharing mitigation protocols to counter cybersecurity vulnerabilities pursuant to subsection (n); and</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause> <clause commented="no" id="HB4E46CDAEDE04F1A9347DC13F1AF47E9"><enum>(iv)</enum><text>in subparagraph (C), as so redesignated, by inserting <quote>and mitigation protocols to counter cybersecurity vulnerabilities in accordance with subparagraph (B)</quote> before <quote>with Federal</quote>;</text></clause></subparagraph> 
<subparagraph id="H0289994E617F4483886FA2D48EA395D7"><enum>(B)</enum><text>in paragraph (7)(C), by striking <quote>sharing</quote> and inserting <quote>share</quote>; and</text></subparagraph> <subparagraph id="H4F89EF27239B4C6DA45FFF0A9D9D0BB3"><enum>(C)</enum><text>in paragraph (9), by inserting <quote>mitigation protocols to counter cybersecurity vulnerabilities,</quote> after <quote>measures,</quote>;</text></subparagraph></paragraph> 
<paragraph id="HACEECC7EB8FD4437A42811193F67A3D4"><enum>(3)</enum><text>in subsection (e)(1)(G), by striking the semicolon after <quote>and</quote> at the end;</text></paragraph> <paragraph id="H34D9907F4CD14BAAA21D989367EC85FC"><enum>(4)</enum><text>by redesignating subsection (o) as subsection (p); and</text></paragraph> 
<paragraph id="H2A173D6768924D8A91B3C8811DFA0640"><enum>(5)</enum><text>by inserting after subsection (n) following new subsection:</text> <quoted-block display-inline="no-display-inline" id="H5DBD4DAEF2D44934BF5FA9F087B37800" style="OLC"> <subsection id="H555F0389444C47CB89A99C61D34D00A9"><enum>(o)</enum><header>Protocols to counter certain cybersecurity vulnerabilities</header><text display-inline="yes-display-inline">The Director may, as appropriate, identify, develop, and disseminate actionable protocols to mitigate cybersecurity vulnerabilities to information systems and industrial control systems, including in circumstances in which such vulnerabilities exist because software or hardware is no longer supported by a vendor.</text></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section> 
<section id="HFA01242FFA5A4654BAEE31DA9B265B7A"><enum>3.</enum><header>Report on cybersecurity vulnerabilities</header> 
<subsection id="H8BEA27EB8A934530B13F03564395A661"><enum>(a)</enum><header>Report</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on how the Agency carries out subsection (n) of section 2209 of the Homeland Security Act of 2002 to coordinate vulnerability disclosures, including disclosures of cybersecurity vulnerabilities (as such term is defined in such section), and subsection (o) of such section (as added by section 2) to disseminate actionable protocols to mitigate cybersecurity vulnerabilities to information systems and industrial control systems, that includes the following:</text> <paragraph id="HCD1973B0C8B94994BD593B974DF4DDD6"><enum>(1)</enum><text>A description of the policies and procedures relating to the coordination of vulnerability disclosures.</text></paragraph> 
<paragraph commented="no" id="H8E169A13A2AB401795FE27D8EF595C0B"><enum>(2)</enum><text>A description of the levels of activity in furtherance of such subsections (n) and (o) of such section 2209.</text></paragraph> <paragraph id="H8687A2716CFF418C9EC7801044990137"><enum>(3)</enum><text display-inline="yes-display-inline">Any plans to make further improvements to how information provided pursuant to such subsections can be shared (as such term is defined in such section 2209) between the Department and industry and other stakeholders.</text></paragraph> 
<paragraph id="HAD1E357BDBC0471B89D001316205B90B"><enum>(4)</enum><text display-inline="yes-display-inline">Any available information on the degree to which such information was acted upon by industry and other stakeholders.</text></paragraph> <paragraph id="HEFEA80AACB4E4B02856A1D778D7518B3"><enum>(5)</enum><text>A description of how privacy and civil liberties are preserved in the collection, retention, use, and sharing of vulnerability disclosures.</text></paragraph></subsection> 
<subsection id="H5C48EF91A7A2457ABB63F75288DFA1C1"><enum>(b)</enum><header>Form</header><text display-inline="yes-display-inline">The report required under subsection (b) shall be submitted in unclassified form but may contain a classified annex.</text></subsection></section> <section id="H5775722B59E74CA1A9ABF5B4312BCF74"><enum>4.</enum><header>Competition relating to cybersecurity vulnerabilities</header><text display-inline="no-display-inline">The Under Secretary for Science and Technology of the Department of Homeland Security, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department, may establish an incentive-based program that allows industry, individuals, academia, and others to compete in identifying remediation solutions for cybersecurity vulnerabilities (as such term is defined in section 2209 of the Homeland Security Act of 2002, as amended by section 2) to information systems (as such term is defined in such section 2209) and industrial control systems, including supervisory control and data acquisition systems.</text></section> 
<section id="HB60673D0FC7E4F57A328EF55D0F8FEEC" section-type="subsequent-section"><enum>5.</enum><header>Title XXII technical and clerical amendments</header> 
<subsection id="HEC3E087772B14783868A32D7BF4A8324"><enum>(a)</enum><header>Technical amendments</header> 
<paragraph id="H63A0ECAD2D954CF6B1B536EFB75E27FD"><enum>(1)</enum><header>Homeland Security Act of 2002</header><text display-inline="yes-display-inline">Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended—</text> <subparagraph id="H277F299C3C7F4584AE6BD0FD4A4A5012"><enum>(A)</enum><text display-inline="yes-display-inline">in the first section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665">6 U.S.C. 665</external-xref>; relating to the duties and authorities relating to .gov internet domain), by amending the section enumerator and heading to read as follows:</text> 
<quoted-block style="OLC" id="HC37BC87A54584992B4249343C60C7579" display-inline="no-display-inline"> 
<section id="HE0D5C9732EB7437C85AAA07C03BE5F36"><enum>2215.</enum><header>Duties and authorities relating to .gov internet domain</header></section><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph> 
<subparagraph id="HBB6C3A534188431CB462731A37F428D1"><enum>(B)</enum><text display-inline="yes-display-inline">in the second section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665b">6 U.S.C. 665b</external-xref>; relating to the joint cyber planning office), by amending the section enumerator and heading to read as follows:</text> <quoted-block style="OLC" id="H6A90368AEBA54C228E42413DE63B1A3B" display-inline="no-display-inline"> <section id="HAF9FD10AD8564B38B66BADC9D3485564"><enum>2216.</enum><header>Joint cyber planning office</header></section><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph> <subparagraph id="H6CC55D434BE04BB3AC4D409C2D1BE821"><enum>(C)</enum><text display-inline="yes-display-inline">in the third section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665c">6 U.S.C. 665c</external-xref>; relating to the Cybersecurity State Coordinator), by amending the section enumerator and heading to read as follows:</text> 
<quoted-block style="OLC" id="HA9CC09CFCD7D4698804AA710E6482118" display-inline="no-display-inline"> 
<section id="H206CBD01C5C54BF883AA1DD2D9E4DA8D"><enum>2217.</enum><header>Cybersecurity State Coordinator</header></section><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph> 
<subparagraph id="H8DBB6E94F0FD4C84AD86C9AF5E46B5AD"><enum>(D)</enum><text display-inline="yes-display-inline">in the fourth section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665d">6 U.S.C. 665d</external-xref>; relating to Sector Risk Management Agencies), by amending the section enumerator and heading to read as follows:</text> <quoted-block style="OLC" id="H856E6AA5AB6F41A5BF5E7431F1FC43B7" display-inline="no-display-inline"> <section id="H503BC673E8A64BA0A141B0762D4211BA"><enum>2218.</enum><header>Sector Risk Management Agencies</header></section><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph> <subparagraph id="H5422BF78AE654AF4A165CD04C5571270"><enum>(E)</enum><text display-inline="yes-display-inline">in section 2216 (<external-xref legal-doc="usc" parsable-cite="usc/6/665e">6 U.S.C. 665e</external-xref>; relating to the Cybersecurity Advisory Committee), by amending the section enumerator and heading to read as follows:</text> 
<quoted-block style="OLC" id="H9D4F0409FAA248E5AD1079B14333D9F9" display-inline="no-display-inline"> 
<section id="H1A2DC1B9C45C4949AFA36EFCA3065F07"><enum>2219.</enum><header>Cybersecurity Advisory Committee</header></section><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph> 
<subparagraph id="HFE3F66D40F8E4BC39E9087480818B7D8"><enum>(F)</enum><text display-inline="yes-display-inline">in section 2217 (<external-xref legal-doc="usc" parsable-cite="usc/6/665f">6 U.S.C. 665f</external-xref>; relating to Cybersecurity Education and Training Programs), by amending the section enumerator and heading to read as follows:</text> <quoted-block style="OLC" id="H18BB8B9759124541978F9036943747BB" display-inline="no-display-inline"> <section id="H1B4A8067C45241BDA091039AADBC02A7"><enum>2220.</enum><header>Cybersecurity Education and Training Programs</header></section><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph> <paragraph id="HB6270767A0144BFA9231F656B1FC0F05"><enum>(2)</enum><header>Consolidated Appropriations Act, 2021</header><text display-inline="yes-display-inline">Paragraph (1) of section 904(b) of division U of the Consolidated Appropriations Act, 2021 (<external-xref legal-doc="public-law" parsable-cite="pl/116/260">Public Law 116–260</external-xref>) is amended, in the matter preceding subparagraph (A), by inserting <quote>of 2002</quote> after <quote>Homeland Security Act</quote>.</text></paragraph></subsection> 
<subsection id="HB3B68A4BBDE147738D72E95FF3FFF26B"><enum>(b)</enum><header>Clerical amendment</header><text display-inline="yes-display-inline">The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by striking the items relating to sections 2214 through 2217 and inserting the following new items:</text> <quoted-block style="OLC" id="H5C4956C6AE634008A12F3C14EC61885C" display-inline="no-display-inline"> <toc regeneration="no-regeneration"> <toc-entry level="section">Sec. 2214. National Asset Database.</toc-entry> <toc-entry level="section">Sec. 2215. Duties and authorities relating to .gov internet domain.</toc-entry> <toc-entry level="section">Sec. 2216. Joint cyber planning office.</toc-entry> <toc-entry level="section">Sec. 2217. Cybersecurity State Coordinator.</toc-entry> <toc-entry level="section">Sec. 2218. Sector Risk Management Agencies.</toc-entry> <toc-entry level="section">Sec. 2219. Cybersecurity Advisory Committee.</toc-entry> <toc-entry level="section">Sec. 2220. Cybersecurity Education and Training Programs.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section> </legis-body> <attestation><attestation-group><attestation-date date="20210720" chamber="House">Passed the House of Representatives July 20, 2021.</attestation-date><attestor display="no">Cheryl L. Johnson,</attestor><role>Clerk.</role></attestation-group></attestation> <endorsement display="yes"></endorsement> </bill> 

