<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H7C2EC8C03F824482977576F2A635A48B" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 5358 IH: To direct the Secretary of Homeland Security to establish an election research program to test the security of election systems, and for other purposes.</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2021-09-24</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 5358</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20210924">September 24, 2021</action-date><action-desc><sponsor name-id="B001298">Mr. Bacon</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HHA00">Committee on House Administration</committee-name>, and in addition to the Committee on <committee-name committee-id="HHM00">Homeland Security</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To direct the Secretary of Homeland Security to establish an election research program to test the security of election systems, and for other purposes.</official-title></form><legis-body id="HA3AE1CBFD5FF4AE8B79C7E368731552C" style="OLC"><section id="H57702DCBA01043BFA0F95BF1FB88FC06" section-type="section-one"><enum>1.</enum><header>Election research program</header><subsection id="H3E69BCA59E224CF3B95C65F2811C25CE"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended by adding at the end the following new section:</text><quoted-block style="OLC" id="H5429A3F6ABAE40B39E10B9E83A091EE6" display-inline="no-display-inline"><section id="HDF1BE386CF6044AB9A94F731B4D6E402"><enum>2218.</enum><header>Election research program</header><subsection id="H875C4425952548E4839C17CBFEB962A2"><enum>(a)</enum><header>Establishment of election research program</header><paragraph id="H9AB0085A6B7F4FDE949F2A319CBE7FCF"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 180 days after the date of the enactment of this section, the Secretary, in coordination with the heads of election service providers, shall establish and administer an election research program to test each election system provided by each election service provider (under fair, reasonable, and nondiscriminatory terms) on behalf of an election agency to identify potentially vulnerable information.</text></paragraph><paragraph id="H7D632F61A5AB43E88DDB8AB1A4FAA480"><enum>(2)</enum><header>Testing</header><text>In carrying out the program required under paragraph (1), qualified independent security researchers shall apply the methodology developed pursuant to paragraph (3) to each election system provided pursuant to paragraph (1) to identify potentially vulnerable information. </text></paragraph><paragraph id="H9CF07CF8737D4264AB781E1140C3955A"><enum>(3)</enum><header>Methodology</header><text display-inline="yes-display-inline">The Secretary, in consultation with the Director, shall develop a methodology to be used by independent security researchers to test each election system provided by each election solution provider to identify potentially vulnerable information. </text></paragraph><paragraph id="HC84693091BE5440D9297DBC8193EAAD8"><enum>(4)</enum><header>Qualifications for qualified independent researcher</header><text display-inline="yes-display-inline">The Secretary, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall establish the qualifications for the independent security researchers referred to in subsection paragraph (3).</text></paragraph></subsection><subsection id="H559EFEDAF143429DA63838F12F6DA409"><enum>(b)</enum><header>Coordinated vulnerability disclosure guidelines</header><text display-inline="yes-display-inline">Not later than 180 days after the date of the enactment of this section, the Secretary, in consultation with the Commissioners of the Election Assistance Commission, cybersecurity researchers, and covered industry experts, shall establish policies and procedures for the processing and resolution of potentially vulnerable information relating to an election system, to the extent practicable, aligned with Standards 29147 and 30111 of the International Standards Organization, including—</text><paragraph id="HB0BBFF76149242038F95D4AAD8B034FB"><enum>(1)</enum><text>processes for an election service provider to—</text><subparagraph id="H672749C9FA3B4368A847711DCBDB2A29"><enum>(A)</enum><text>receive information relating to potentially vulnerable information relating to an election system; and</text></subparagraph><subparagraph id="H6A345CB4E42B427F923C3F1B84BC4F41"><enum>(B)</enum><text>disseminate resolution information relating to potentially vulnerable information relating to an election system; and</text></subparagraph></paragraph><paragraph id="HCEEDDB907F6947E7B33F42B388E14B35" display-inline="no-display-inline"><enum>(2)</enum><text>guidance, such as the Guide to Vulnerability Reporting for America’s Election Administrators, with respect to the information items to be produced through the implementation of the vulnerability disclosure process of the election service provider.</text></paragraph></subsection><subsection id="HD830A7D845C34CF6926B89A52A50DE60"><enum>(c)</enum><header>Definitions</header><text>In this section:</text><paragraph id="H724C003F63A4419A999644CD347004B3"><enum>(1)</enum><header>Covered field</header><text display-inline="yes-display-inline">The term <quote>covered field</quote> means computer science, engineering, information science, information systems management, mathematics, operations research, statistics, or technology management.</text></paragraph><paragraph id="HAD1F0B88AAC849C6880A83BF7C687B05"><enum>(2)</enum><header>Covered industry expert</header><text>The term <quote>covered industry expert</quote> means an individual who has—</text><subparagraph id="H4A4AF579A1A8475CAAB16FCB589814D1"><enum>(A)</enum><text display-inline="yes-display-inline">successfully completed 2 full years of progressively higher level graduate education leading to a Master's or equivalent graduate degree from an accredited institution of higher education (given the meaning of such term in section 101 of the Higher Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/1001">20 U.S.C. 1001</external-xref>)) in a covered field; or </text></subparagraph><subparagraph id="H5C2163B9270A40A3BD2708E01CC97B5F"><enum>(B)</enum><text>a degree that requires at least 24 semester hours in a covered field required the development or adaptation of applications, systems or networks.</text></subparagraph></paragraph><paragraph id="H714FCF5E69584D70B19B9B6F204252CF"><enum>(3)</enum><header>Director</header><text>The term <quote>Director</quote> means the Director of the National Institute of Standards and Technology.</text></paragraph><paragraph id="HB0BA2B55CCDF45B58F08979D1BF46194"><enum>(4)</enum><header>Election agency</header><text>The term <quote>election agency</quote> means the Federal Election Commission.</text></paragraph><paragraph id="H7C02EB284B984C24B2663E0B38351F2A"><enum>(5)</enum><header>Election service provider</header><text display-inline="yes-display-inline">The term <quote>covered election service provider</quote> means a private sector entity which develops, manufactures, sells, and/or implements and maintains technology that enables the administration of elections. Including but not limited to, voting systems, electronic pollbooks, election management systems, and voter registration systems.</text></paragraph><paragraph id="H2EBF1676796E46F6AED9AC6E62B461EC"><enum>(6)</enum><header>Election system</header><text>The term <quote>election system</quote> means—</text><subparagraph id="HE4EC2CD1E5F84539BCFFC58AD4E4F9FF"><enum>(A)</enum><text>the total combination of mechanical, electromechanical, or electronic equipment (including the software, firmware, and documentation required to program, control, and support the equipment) that is used to—</text><clause id="H2AD5C2A4AB8946F387F6E3C6458BF696" display-inline="no-display-inline"><enum>(i)</enum><text>define ballots;</text></clause><clause id="H4AC1B87CB9D74CF79F262BBEFC5EF718" display-inline="no-display-inline"><enum>(ii)</enum><text>cast and count votes;</text></clause><clause id="H39EB3DF653E4404E8653EA10892CA4ED" display-inline="no-display-inline"><enum>(iii)</enum><text>report or display election results; and</text></clause><clause id="H16C3D136B027451295085E81843939C2" display-inline="no-display-inline"><enum>(iv)</enum><text>maintain and produce any audit trail information; and</text></clause></subparagraph><subparagraph id="H7904991225AD438BB8ACFA6FDBAD43DA"><enum>(B)</enum><text>the practices and associated documentation used to—</text><clause id="H48112E89FEEC4DE0BEDD5762886A3AC7"><enum>(i)</enum><text>identify system components and versions of such components;</text></clause><clause id="H1F5199975145430EA6B70AAAE2B0CA58"><enum>(ii)</enum><text>test the system during its development and maintenance;</text></clause><clause id="HE46BE987930641E7A0E555B0FABFE690"><enum>(iii)</enum><text>maintain records of system errors and defects;</text></clause><clause id="H2237699ED72A4B86974C04223EF01332"><enum>(iv)</enum><text>determine specific system changes to be made to a system after the initial qualification of the system; and</text></clause><clause id="H919EEFEA716B4F5FB7308C25732B4D21"><enum>(v)</enum><text>make available any materials to the voter (such as notices, instructions, forms, or paper ballots).</text></clause></subparagraph></paragraph><paragraph id="H779B1D5A56184E23A7B370DD158AFAEE"><enum>(7)</enum><header>Potentially vulnerable information</header><text display-inline="yes-display-inline">The term <term>potential vulnerability information</term> means a flaw in code or design that creates a potential point of security compromise for an endpoint or network.</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="HABEAFF24F93340E6B821B0C548B07355"><enum>(b)</enum><header>Clerical amendment</header><text display-inline="yes-display-inline">The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by inserting after the item relating to section 2217 the following new item:</text><quoted-block style="OLC" id="HBC59B6FDA397407DB939E46462387C1C" display-inline="no-display-inline"><toc regeneration="no-regeneration"><toc-entry level="section">2218. Election research program.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section></legis-body></bill> 

