Legis Daily

Improving Contractor Cybersecurity Act

USA117th CongressHR-3608| House 
| Updated: 5/28/2021
Ted Lieu

Ted Lieu

Democratic Representative

California

Oversight and Government Reform Committee

  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted
Improving Contractor Cybersecurity Act This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program. The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published, information regarding any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; and any other situation where the contractor determines it would be helpful or necessary to involve CISA. CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.
View Full Text

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline
May 28, 2021
Introduced in House
May 28, 2021
Referred to the House Committee on Oversight and Reform.
  • May 28, 2021
    Introduced in House


  • May 28, 2021
    Referred to the House Committee on Oversight and Reform.

Government Operations and Politics

Computers and information technologyGovernment information and archivesPublic contracts and procurement

Improving Contractor Cybersecurity Act

USA117th CongressHR-3608| House 
| Updated: 5/28/2021
Improving Contractor Cybersecurity Act This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program. The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published, information regarding any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; and any other situation where the contractor determines it would be helpful or necessary to involve CISA. CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.
View Full Text

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline
May 28, 2021
Introduced in House
May 28, 2021
Referred to the House Committee on Oversight and Reform.
  • May 28, 2021
    Introduced in House


  • May 28, 2021
    Referred to the House Committee on Oversight and Reform.
Ted Lieu

Ted Lieu

Democratic Representative

California

Oversight and Government Reform Committee

Government Operations and Politics

  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted
Computers and information technologyGovernment information and archivesPublic contracts and procurement