IIB
117th CONGRESS
1st Session
H. R. 2980
IN THE SENATE OF THE UNITED STATES
July 21, 2021
Received; read twice and referred to the Committee on Homeland Security and Governmental Affairs
AN ACT
To amend the Homeland Security Act of 2002 to provide for the remediation of cybersecurity vulnerabilities, and for other purposes.
Short title
This Act may be cited as the Cybersecurity Vulnerability Remediation Act
.
Cybersecurity vulnerabilities
Section 2209 of the Homeland Security Act of 2002 (6 U.S.C. 659) is amended—
in subsection (a)—
in paragraph (5), by striking and
after the semicolon at the end;
by redesignating paragraph (6) as paragraph (7); and
by inserting after paragraph (5) the following new paragraph:
the term cybersecurity vulnerability
has the meaning given the term security vulnerability
in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501); and
.
in subsection (c)—
in paragraph (5)—
in subparagraph (A), by striking and
after the semicolon at the end;
by redesignating subparagraph (B) as subparagraph (C);
by inserting after subparagraph (A) the following new subparagraph:
sharing mitigation protocols to counter cybersecurity vulnerabilities pursuant to subsection (n); and
; and
in subparagraph (C), as so redesignated, by inserting and mitigation protocols to counter cybersecurity vulnerabilities in accordance with subparagraph (B)
before with Federal
;
in paragraph (7)(C), by striking sharing
and inserting share
; and
in paragraph (9), by inserting mitigation protocols to counter cybersecurity vulnerabilities,
after measures,
;
in subsection (e)(1)(G), by striking the semicolon after and
at the end;
by redesignating subsection (o) as subsection (p); and
by inserting after subsection (n) following new subsection:
Protocols to counter certain cybersecurity vulnerabilities
The Director may, as appropriate, identify, develop, and disseminate actionable protocols to mitigate cybersecurity vulnerabilities to information systems and industrial control systems, including in circumstances in which such vulnerabilities exist because software or hardware is no longer supported by a vendor.
.
Report on cybersecurity vulnerabilities
Report
Not later than 1 year after the date of the enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on how the Agency carries out subsection (n) of section 2209 of the Homeland Security Act of 2002 to coordinate vulnerability disclosures, including disclosures of cybersecurity vulnerabilities (as such term is defined in such section), and subsection (o) of such section (as added by section 2) to disseminate actionable protocols to mitigate cybersecurity vulnerabilities to information systems and industrial control systems, that includes the following:
A description of the policies and procedures relating to the coordination of vulnerability disclosures.
A description of the levels of activity in furtherance of such subsections (n) and (o) of such section 2209.
Any plans to make further improvements to how information provided pursuant to such subsections can be shared (as such term is defined in such section 2209) between the Department and industry and other stakeholders.
Any available information on the degree to which such information was acted upon by industry and other stakeholders.
A description of how privacy and civil liberties are preserved in the collection, retention, use, and sharing of vulnerability disclosures.
Form
The report required under subsection (b) shall be submitted in unclassified form but may contain a classified annex.
Competition relating to cybersecurity vulnerabilities
The Under Secretary for Science and Technology of the Department of Homeland Security, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department, may establish an incentive-based program that allows industry, individuals, academia, and others to compete in identifying remediation solutions for cybersecurity vulnerabilities (as such term is defined in section 2209 of the Homeland Security Act of 2002, as amended by section 2) to information systems (as such term is defined in such section 2209) and industrial control systems, including supervisory control and data acquisition systems.
Title XXII technical and clerical amendments
Technical amendments
Homeland Security Act of 2002
Subtitle A of title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651 et seq.) is amended—
in the first section 2215 (6 U.S.C. 665; relating to the duties and authorities relating to .gov internet domain), by amending the section enumerator and heading to read as follows:
Duties and authorities relating to .gov internet domain
;
in the second section 2215 (6 U.S.C. 665b; relating to the joint cyber planning office), by amending the section enumerator and heading to read as follows:
Joint cyber planning office
;
in the third section 2215 (6 U.S.C. 665c; relating to the Cybersecurity State Coordinator), by amending the section enumerator and heading to read as follows:
Cybersecurity State Coordinator
;
in the fourth section 2215 (6 U.S.C. 665d; relating to Sector Risk Management Agencies), by amending the section enumerator and heading to read as follows:
Sector Risk Management Agencies
;
in section 2216 (6 U.S.C. 665e; relating to the Cybersecurity Advisory Committee), by amending the section enumerator and heading to read as follows:
Cybersecurity Advisory Committee
; and
in section 2217 (6 U.S.C. 665f; relating to Cybersecurity Education and Training Programs), by amending the section enumerator and heading to read as follows:
Cybersecurity Education and Training Programs
.
Consolidated Appropriations Act, 2021
Paragraph (1) of section 904(b) of division U of the Consolidated Appropriations Act, 2021 (Public Law 116–260) is amended, in the matter preceding subparagraph (A), by inserting of 2002
after Homeland Security Act
.
Clerical amendment
The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by striking the items relating to sections 2214 through 2217 and inserting the following new items:
Sec. 2214. National Asset Database.
Sec. 2215. Duties and authorities relating to .gov internet domain.
Sec. 2216. Joint cyber planning office.
Sec. 2217. Cybersecurity State Coordinator.
Sec. 2218. Sector Risk Management Agencies.
Sec. 2219. Cybersecurity Advisory Committee.
Sec. 2220. Cybersecurity Education and Training Programs.
.
Passed the House of Representatives July 20, 2021.
Cheryl L. Johnson,
Clerk