Us Code § 10306 - Vulnerability disclosure policy and bug bounty program report

Full text of Us Code United States Code § 10306 — Vulnerability disclosure policy and bug bounty program report, with citation guidance and answers to common questions.

§ 10306. Vulnerability disclosure policy and bug bounty program report

(a) Definitions

In this section:

(1) Bug bounty program

The term "bug bounty program" means a program under which an approved individual, organization, or company is temporarily authorized to identify and report vulnerabilities of internet-facing information technology of the Department in exchange for compensation.

(2) Information technology

The term "information technology" has the meaning given such term in section 11101 of title 40.

(b) Vulnerability Disclosure Policy

(1) In general

Not later than 180 days after December 23, 2022, the Secretary shall design, establish, and make publicly known a Vulnerability Disclosure Policy (referred to in this section as the "VDP") to improve Department cybersecurity by—

(A) creating Department policy and infrastructure to receive reports of and remediate discovered vulnerabilities in line with existing policies of the Office of Management and Budget and the Department of Homeland Security Binding Operational Directive 20–01 or any subsequent directive; and

(B) providing a report on such policy and infrastructure to Congress.

(2) Annual reports

Not later than 180 days after the establishment of the VDP pursuant to paragraph (1), and annually thereafter for the following 5 years, the Secretary shall submit a report on the VDP to the Committee on Foreign Relations of the Senate, the Committee on Homeland Security and Governmental Affairs of the Senate, the Select Committee on Intelligence of the Senate, the Committee on Foreign Affairs of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the Permanent Select Committee on Intelligence of the House of Representatives that includes information relating to—

(A) the number and severity of all security vulnerabilities reported;

(B) the number of previously unidentified security vulnerabilities remediated as a result;

(C) the current number of outstanding previously unidentified security vulnerabilities and Department of State remediation plans;

(D) the average time between the reporting of security vulnerabilities and remediation of such vulnerabilities;

(E) the resources, surge staffing, roles, and responsibilities within the Department used to implement the VDP and complete security vulnerability remediation;

(F) how the VDP identified vulnerabilities are incorporated into existing Department vulnerability prioritization and management processes;

(G) any challenges in implementing the VDP and plans for expansion or contraction in the scope of the VDP across Department information systems; and

(H) any other topic that the Secretary determines to be relevant.

(c) Bug bounty program report

(1) In general

Not later than 180 days after December 23, 2022, the Secretary shall submit a report to Congress that describes any ongoing efforts by the Department or a third-party vendor under contract with the Department to establish or carry out a bug bounty program that identifies security vulnerabilities of internet-facing information technology of the Department.

(2) Report

Not later than 180 days after the date on which any bug bounty program is established, the Secretary shall submit a report to the Committee on Foreign Relations of the Senate, the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Foreign Affairs of the House of Representatives, and the Committee on Homeland Security of the House of Representatives regarding such program, including information relating to—

(A) the number of approved individuals, organizations, or companies involved in such program, disaggregated by the number of approved individuals, organizations, or companies that—

(i) registered;

(ii) were approved;

(iii) submitted security vulnerabilities; and

(iv) received compensation;


(B) the number and severity of all security vulnerabilities reported as part of such program;

(C) the number of previously unidentified security vulnerabilities remediated as a result of such program;

(D) the current number of outstanding previously unidentified security vulnerabilities and Department remediation plans for such outstanding vulnerabilities;

(E) the average length of time between the reporting of security vulnerabilities and remediation of such vulnerabilities;

(F) the types of compensation provided under such program;

(G) the lessons learned from such program;

(H) the public accessibility of contact information for the Department regarding the bug bounty program;

(I) the incorporation of bug bounty program identified vulnerabilities into existing Department vulnerability prioritization and management processes; and

(J) any challenges in implementing the bug bounty program and plans for expansion or contraction in the scope of the bug bounty program across Department information systems.

(Pub. L. 117–263, div. I, title XCV, §9509, Dec. 23, 2022, 136 Stat. 3907.)


Statutory Notes and Related Subsidiaries

Definitions

"Department" and "Secretary" as used in this section mean the Department and Secretary of State, unless otherwise specified, see section 9002 of Pub. L. 117–263, set out as a note under section 2651 of this title.

About This Section

22 U.S.C. § 10306 is part of Title 22 of the United States Code. The United States Code is the official codification of federal statutes maintained by the Office of the Law Revision Counsel of the U.S. House of Representatives. Congress amends the Code through new public laws, which are eventually incorporated into the relevant title.

This section may be cited in legal writing as 22 U.S.C. § 10306. For the most current official text, including any recent amendments, use the official source links below. Do not rely on this page as the sole authority for legal citation or litigation.

How to Read This Statute

Statutes are organized by title, chapter, section, and subsection. Pay attention to words like "shall," "may," "and," and "or," because they determine whether a requirement is mandatory or permissive and whether multiple conditions must all be met. Historical notes and amendments often appear at the end of a section.

Using This Page

This page is intended for research and educational use. Lawyers, students, journalists, and compliance professionals can use it as a starting point, but should always verify the current text through an official government source before relying on it for legal advice, filings, or compliance decisions.

Sources

Frequently Asked Questions About Us Code § 10306

What does United States Code § 10306 cover?

Section 10306 ("Vulnerability disclosure policy and bug bounty program report") is part of the United States Code, the codified statutory law of Us Code. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.

How do I cite Us Code § 10306?

A common citation format is "United States Code § 10306" (Us Code). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.

Is this the official text of Us Code law?

No. This page is for research and education and may not include the most recent amendments. For official current law, check the Us Code official source linked on this page or consult a licensed Us Code attorney.

How does Us Code § 10306 apply to my situation?

Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Us Code can advise on how this section applies to you. Contact your state or local bar association for a referral.

Sources & Verification

Not legal advice. Verify against the official source and consult a licensed attorney in Us Code.