To amend title 41, United States Code, to require information technology contractors to maintain a vulnerability disclosure policy and program, and for other purposes.
About This Bill
Committee
Latest Action · August 29, 2023
Referred to the House Committee on Oversight and Accountability.
The Improving Contractor Cybersecurity Act requires companies that hold federal information technology contracts to establish and maintain formal vulnerability disclosure policies. These policies must allow the public to anonymously report security flaws, clearly explain how to submit reports, establish timelines for responding to researchers, and guarantee that good-faith security researchers cannot be sued for following the policy. The legislation applies to all new federal IT contracts signed after the bill becomes law and affects any company seeking to contract with executive agencies for information technology work. Contractors must also report significant vulnerabilities to the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency, which will then share critical findings with national vulnerability databases to help protect government and industry systems. The bill does not include specific funding allocations, as it primarily establishes new contracting requirements that place responsibility on vendors to manage vulnerability disclosure programs.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.