H.R. 5433House115th Congress (2017-2019)Passed House

Hack Your State Department Act

Sponsored by Ted LieuRep. Ted Lieu (D-CA)
Introduced April 5, 2018

AI-Generated Summary

Updated April 15, 2026 at 9:12 PM UTC

The Hack Your State Department Act directs the Secretary of State to set up a formal process for reporting cybersecurity flaws in the department’s internet‑facing systems and to run a short‑term bug‑bounty pilot that pays researchers for finding new vulnerabilities. The goal is to improve the State Department’s overall cyber security by encouraging external security researchers to safely disclose problems and by tracking how those problems are fixed.

Key Provisions

  • Within 180 days, the Secretary must create a public Vulnerability Disclosure Process (VDP) that gives clear rules for researchers to find and report flaws, identifies which systems are covered, and sets up internal teams to receive and fix reports.
  • The VDP must include protections against prosecution for authorized researchers, involve consultation with the Attorney General and the Department of Defense’s bug‑bounty experience, and may use a contractor to manage the process.
  • The Secretary must submit annual reports to the House Foreign Affairs and Senate Foreign Relations committees for six years, detailing numbers, severity, remediation times, costs saved, and staffing related to the VDP.
  • Within one year, the Secretary must launch a bug‑bounty pilot program that pays for newly discovered vulnerabilities on public‑facing State Department IT, uses a contractor to run the program, and requires background checks and eligibility approval for participants.
  • The pilot may not run longer than one year, and a final report must be sent to the same congressional committees covering participation, vulnerability data, compensation, remediation, and lessons learned.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

11 earlier actions
SenateIntro Referral Latest Action

Received in the Senate and Read twice and referred to the Committee on Foreign Relations.

September 26, 2018

View full timeline
HouseIntro Referral

Introduced in House

April 5, 2018

HouseIntro Referral

Referred to the House Committee on Foreign Affairs.

April 5, 2018

HouseCommittee

Committee Consideration and Mark-up Session Held.

May 9, 2018

HouseCommittee

Ordered to be Reported (Amended) by Voice Vote.

May 9, 2018

HouseCommittee

Committee Agreed to Seek Consideration Under Suspension of the Rules, by Unanimous Consent.

May 9, 2018

HouseFloor

Ms. Ros-Lehtinen moved to suspend the rules and pass the bill, as amended.

September 25, 2018 • 10:36 PM

HouseFloor

Considered under suspension of the rules. (consideration: CR H8878-8880)

September 25, 2018 • 10:36 PM

HouseFloor

DEBATE - The House proceeded with forty minutes of debate on H.R. 5433.

September 25, 2018 • 10:36 PM

HouseFloor

Passed/agreed to in House: On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote.(text: CR H8878-8879)

September 25, 2018 • 10:47 PM

HouseFloor

On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H8878-8879)

September 25, 2018 • 10:47 PM

HouseFloor

Motion to reconsider laid on the table Agreed to without objection.

September 25, 2018 • 10:47 PM

SenateIntro Referral

Received in the Senate and Read twice and referred to the Committee on Foreign Relations.

September 26, 2018

Floor Debate

4 members

What members said about H.R. 5433 on the floor

1 Republican3 Democrats
Ileana Ros-Lehtinen
Rep. Ileana Ros-LehtinenR-FL-27 · Sep 25, 2018

Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 5433) to require the Secretary of State to design and establish a Vulnerability Disclosure Process (VDP) to improve Department of…

Sheila Jackson Lee
Rep. Sheila Jackson LeeD-TX-18 · Sep 25, 2018

Mr. Speaker, I rise today in support of H.R. 5433, the ``Hack Your State Department Act''. This act would direct the State Department to establish what is known in the cybersecurity community as a…

Eliot L. Engel
Rep. Eliot L. EngelD-NY-16 · Sep 25, 2018

Mr. Speaker, I yield myself such time as I may consume. Mr. Speaker, I rise in support of this measure. Mr. Speaker, I thank Representative Lieu of southern California, a very valued member of the…

Ted Lieu
Rep. Ted LieuD-CA-33 · Sep 25, 2018

Mr. Speaker, I thank Representative Engel for yielding. Mr. Speaker, I rise today in support of my legislation, H.R. 5433, the Hack Your State Department Act, that I co-authored with my friend, Ted…

Bill Text

3 versions available

Reading Mode
Latest
Referred in SenateIssued September 26, 2018

IIB

115th CONGRESS

2d Session

H. R. 5433

IN THE SENATE OF THE UNITED STATES

September 26, 2018

Received; read twice and referred to the Committee on Foreign Relations

AN ACT

To require the Secretary of State to design and establish a Vulnerability Disclosure Process (VDP) to improve Department of State cybersecurity and a bug bounty program to identify and report vulnerabilities of internet-facing information technology of the Department of State, and for other purposes.

1.

Short title

This Act may be cited as the Hack Your State Department Act.

2.

Definitions

In this Act:

(1)

Bug bounty program

The term bug bounty program means a program under which an approved individual, organization, or company is temporarily authorized to identify and report vulnerabilities of internet-facing information technology of the Department in exchange for compensation.

(2)

Department

The term Department means the Department of State.

(3)

Information technology

The term information technology has the meaning given such term in section 11101 of title 40, United States Code.

(4)

Secretary

The term Secretary means the Secretary of State.

3.

Department of State Vulnerability Disclosure Process

(a)

In general

Not later than 180 days after the date of the enactment of this Act, the Secretary shall design, establish, and make publicly known a Vulnerability Disclosure Process (VDP) to improve Department cybersecurity by—

(1)

providing security researchers with clear guidelines for—

(A)

conducting vulnerability discovery activities directed at Department information technology; and

(B)

submitting discovered security vulnerabilities to the Department; and

(2)

creating Department procedures and infrastructure to receive and fix discovered vulnerabilities.

(b)

Requirements

In establishing the VDP pursuant to paragraph (1), the Secretary shall—

(1)

identify which Department information technology should be included in the process;

(2)

determine whether the process should differentiate among and specify the types of security vulnerabilities that may be targeted;

(3)

provide a readily available means of reporting discovered security vulnerabilities and the form in which such vulnerabilities should be reported;

(4)

identify which Department offices and positions will be responsible for receiving, prioritizing, and addressing security vulnerability disclosure reports;

(5)

consult with the Attorney General regarding how to ensure that approved individuals, organizations, and companies that comply with the requirements of the process are protected from prosecution under section 1030 of title 18, United States Code, and similar provisions of law for specific activities authorized under the process;

(6)

consult with the relevant offices at the Department of Defense that were responsible for launching the 2016 Vulnerability Disclosure Program, Hack the Pentagon, and subsequent Department of Defense bug bounty programs;

(7)

engage qualified interested persons, including nongovernmental sector representatives, about the structure of the process as constructive and to the extent practicable; and

(8)

award a contract to an entity, as necessary, to manage the process and implement the remediation of discovered security vulnerabilities.

(c)

Annual reports

Not later than 180 days after the establishment of the VDP under subsection (a) and annually thereafter for the next six years, the Secretary of State shall submit to the Committee on Foreign Affairs of the House of Representatives and the Committee on Foreign Relations of the Senate a report on the following with respect to the VDP:

(1)

The number and severity, in accordance with the National Vulnerabilities Database of the National Institute of Standards and Technology, of security vulnerabilities reported.

(2)

The number of previously unidentified security vulnerabilities remediated as a result.

(3)

The current number of outstanding previously unidentified security vulnerabilities and Department of State remediation plans.

(4)

The average length of time between the reporting of security vulnerabilities and remediation of such vulnerabilities.

(5)

An estimate of the total cost savings of discovering and addressing security vulnerabilities submitted through the VDP.

(6)

The resources, surge staffing, roles, and responsibilities within the Department used to implement the VDP and complete security vulnerability remediation.

(7)

Any other information the Secretary determines relevant.

4.

Department of State bug bounty pilot program

(a)

Establishment of pilot program

(1)

In general

Not later than one year after the date of the enactment of this Act, the Secretary shall establish a bug bounty pilot program to minimize security vulnerabilities of internet-facing information technology of the Department.

(2)

Requirements

In establishing the pilot program described in paragraph (1), the Secretary shall—

(A)

provide compensation for reports of previously unidentified security vulnerabilities within the websites, applications, and other internet-facing information technology of the Department that are accessible to the public;

(B)

award a contract to an entity, as necessary, to manage such pilot program and for executing the remediation of security vulnerabilities identified pursuant to subparagraph (A);

(C)

identify which Department information technology should be included in such pilot program;

(D)

consult with the Attorney General on how to ensure that approved individuals, organizations, or companies that comply with the requirements of such pilot program are protected from prosecution under section 1030 of title 18, United States Code, and similar provisions of law for specific activities authorized under such pilot program;

(E)

consult with the relevant offices at the Department of Defense that were responsible for launching the 2016 Hack the Pentagon pilot program and subsequent Department of Defense bug bounty programs;

(F)

develop a process by which an approved individual, organization, or company can register with the entity referred to in subparagraph (B), submit to a background check as determined by the Department, and receive a determination as to eligibility for participation in such pilot program;

(G)

engage qualified interested persons, including nongovernmental sector representatives, about the structure of such pilot program as constructive and to the extent practicable; and

(H)

consult with relevant United States Government officials to ensure that such pilot program compliments persistent network and vulnerability scans of the Department of State’s internet-accessible systems, such as the scans conducted pursuant to Binding Operational Directive BOD-15-01.

(3)

Duration

The pilot program established under paragraph (1) should be short-term in duration and not last longer than one year.

(b)

Report

Not later than 180 days after the date on which the bug bounty pilot program under subsection (a) is completed, the Secretary shall submit to the Committee on Foreign Relations of the Senate and the Committee on Foreign Affairs of the House of Representatives a report on such pilot program, including information relating to—

(1)

the number of approved individuals, organizations, or companies involved in such pilot program, broken down by the number of approved individuals, organizations, or companies that—

(A)

registered;

(B)

were approved;

(C)

submitted security vulnerabilities; and

(D)

received compensation;

(2)

the number and severity, in accordance with the National Vulnerabilities Database of the National Institute of Standards and Technology, of security vulnerabilities reported as part of such pilot program;

(3)

the number of previously unidentified security vulnerabilities remediated as a result of such pilot program;

(4)

the current number of outstanding previously unidentified security vulnerabilities and Department remediation plans;

(5)

the average length of time between the reporting of security vulnerabilities and remediation of such vulnerabilities;

(6)

the types of compensation provided under such pilot program; and


(7)

the lessons learned from such pilot program.

Passed the House of Representatives September 25, 2018.

Karen L. Haas,

Clerk.