Showing posts with label VDP. Show all posts
Showing posts with label VDP. Show all posts

Friday, April 4, 2025

Review - HR 1258 Introduced – Contractor VDP

Back in February Rep Lieu (D,CA) introduced HR 1258, the Improving Contractor Cybersecurity Act. The bill would require federal contractors to have a vulnerability disclosure program (VDP). No new funding is provided.

The bill is essentially the same as HR 5310 that was introduced by Liew in August, 2023. No action was taken on that bill in the 118th Congress.

The bill would amend Chapter 47, of division C, of subtitle I, of 41 USC, adding a new §4715, Vulnerability disclosure policy and program required.

Moving Forward

Lieu is not a member of the House Oversight and Government Reform Committee to which this bill was assigned for consideration. This means that there is probably not sufficient influence for the bill to be considered in Committee, the same problem that Lieu had with HR 5310 in the 118th Congress. I suspect that there would be some Republicans that would oppose this bill as an unneeded, and potentially expensive, requirement for federal contractors. While there may possibly be sufficient bipartisan support for this bill to pass in Committee, I am not sure that there would be the necessary leadership interest to see this bill move forward.

Commentary

While the definition of ‘information technology’ used in this bill is broadly enough written to include control systems and operational technologies, there is an interesting shortcoming; it only applies to “the equipment [that] is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use” of the equipment. It specifically excludes any equipment acquired by a federal contractor incidental to a federal contract.” Thus, devices networked to ‘federally required equipment’ need not be included in the required VDP.

 

For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-1258-introduced - subscription required.

Monday, March 3, 2025

House Passes HR 872 – Contractor VDP

Today, the House took up HR 872, the Federal Cybersecurity Vulnerability Reduction Act of 2023, under the suspension of the rules process. After 20 minutes of debate, the bill was passed by voice vote. The bill would require the OMB and DOD to review Federal Acquisition Regulations (FAR) to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required by 15 USC 278g–3c. No funding is authorized by this legislation.

The bill will now be sent to the Senate for consideration. This legislation is not politically important enough to be considered under regular order in the Senate. There is a chance that this bill could reach the Seante floor under the unanimous consent process. Unfortunately, that process is subject to all sorts of political machinations that could draw an objection that has nothing to do with merits of the legislation. In years past, this bill would be a logical addition to a spending or authorization bill, that has become less likely since the Republicans took control of the House in 2022. 

Monday, October 28, 2024

Review - S 5028 Introduced – Contractor VDP

Last month Sen Warner (D,VA) introduced S 5028, the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2024. The bill would require changes to the Federal Acquisition Regulations to require federal contractors to have a vulnerability disclosure program. No new funding is authorized by this legislation.

This bill is very similar in intent to HR 5310 and HR 5255. The major difference between this bill and the other two is that the Senate bill is focused on the FAR as the mechanism for requiring contractors to have a vulnerable disclosure program. There has been no action taken on HR 5310, but HR 5255 was amended and ordered favorably reported back in May. That report has not yet been published.

Moving Forward

While Warner is not a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned, his sole cosponsor {Lankford (R,OK)} is a member. This means that there may be sufficient influence to see the bill considered in Committee. Beyond the increased regulation of contractors which some elements of the Republican fringe have a knee-jerk opposition to, I see nothing that would cause any organized opposition to this bill. I suspect that this bill would receive some level of bipartisan support in Committee.

 

For more information about the provisions of the bill, as well as more discussion about it’s prospects, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-5028-introduced - subscription required.

Friday, September 15, 2023

Review - HR 4552 Introduced – 2023 FISMA

Back in July, Rep Mace (R,SC) introduced HR 4552, the Federal Information Security Modernization Act of 2023. This is the perennial update of the Federal agency cybersecurity rules. It includes two items of potentially broader interest here: penetration testing policy and vulnerability disclosure policy.

Moving Forward

Mace, and all four of her cosponsors {Rep Raskin (D,MD) Rep Comer (R,KY), Rep Connolly (D,VA) and Rep Davis (D,NC)}, are members of the House Oversight and Accountability Committee to which the bill was assigned for consideration. This means that there is almost certainly sufficient influence to see the bill considered in Committee. I do not see anything that would engender organized opposition to the legislation. I suspect that there would be significant bipartisan support for the bill, probably enough that it could be considered under the House’s suspension of the rules process.

It will be interesting to see how much the Committee’s investigative efforts directed at the Biden Administration will affect their ability to consider bipartisan legislation like HR 4552.

Commentary

I found it odd that §12’s new §3559b removed the contractor cybersecurity requirements of 15 U.S.C. 278g–3e. There is nothing in that section that deals with VDP requirements. It looks to my suspicious mind like someone is trying to reduce cybersecurity requirements for contractors. In any case the deletion of that section should be remove from this section since it has nothing to do with VDP.

 

For more details about the penetration testing and vulnerability disclosure program provisions of the legislation, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-4552-introduced - subscription required.

Saturday, April 30, 2022

Review - OMB Approves CISA Vulnerability Reporting ICR Extension

Yesterday, OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an extension of an information collection request for “Vulnerability Discovery Program” (OMB Control Number: 1601-0028). DHS submitted the extension request for this ICR after OIRA approved a short-term revision of the ICR to allow the DHS VDP form to be used by other (undesignated) agencies of the Federal government to support those agencies in responding to the DHS Binding Operational Directive 20-01. The 60-day extension notice for this ICR was published in March 2021.

The Federal government has been using the DHS VDP reporting form for just a little over a year now. It would be interesting to see how many agencies are using the reporting form and how many have reached an agreement with DHS to have DHS manage their VDP program. This would be an interesting topic for a GAO or CRS report, if any congressional staffers are reading this.

For more details on the DHS response to public comments on their 60-day ICR notice, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/omb-approves-dhs-vulnerability-reporting - subscription required.


Saturday, July 31, 2021

Review - CISA Announces VDP Platform

Earlier this week CISA announced the establishment of their Vulnerability Disclosure Policy Platform (VDP Platform). According to the announcement: “The VDP Platform provides a single, centrally managed online website for agencies to list systems in scope for their vulnerability disclosure policies, enabling security researchers and members of the general public to find vulnerabilities in agency websites and submit reports for analysis.”

According to the CISA fact sheet on the VDP Platform, the Platform is being offered as a software-as-a-service program to support individual department and agency VDPs. CISA’s Cyber Quality Services Management Office (QSMO) provides platform oversight, and the Platform is currently operated by BugCrowd. Supported agencies will retain responsibility for vulnerability confirmation and remediation. While the platform is designed to support bug bounty programs, there does not appear to be any agency that is currently sponsoring such a program.

The OMB’s Office of Information and Regulatory Affairs (OIRA) approved an emergency information collection request expansion to cover this VDP Platform back in March. CISA was required to update that ICR by September 30th, 2021.

For more detailed information, including links to agency VDP sites, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/cisa-announces-vdp-platform - subscription required. 

Thursday, July 15, 2021

Review - HR 3608 Introduced - Improving Contractor Cybersecurity Act

Back in May, Rep Lieu introduced HR 3608, the Improving Contractor Cybersecurity Act. The bill amends 41 USC by adding a new §4715, Vulnerability disclosure policy and program required. It would require all federal  information technology contractors to maintain a vulnerability disclosure policy and program.

Lieu is not a member of the House Oversight and Reform Committee to which this bill was assigned for consideration. This means that the Committee is unlikely to take up this bill. I suspect that there would be substantial opposition to this bill from business interests supported by Republican members of the House, and frankly many Democratic members as well. If the bill were considered in Committee, I would not be surprised if there were insufficient votes to see it adopted as introduced.

For a more detailed analysis of the bill requirements and my observations on the problems with the language, see my analysis at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3608-introduced - subscription required.

Sunday, July 11, 2021

Review - HR 3313 Introduced - Hack Your State Department

Back in May, Rep Lieu introduced HR 3313, the Hack Your State Department Act. The bill would require the State Department to establish a vulnerability disclosure process (VDP) and a bug bounty pilot program. No monies are authorized in the bill for either program.

Lieu is a member, as are his three cosponsors {Rep Spanberger (D,VA), Rep Pfluger (R,TX), Rep Tenney (R,NY)}  of the House Foreign Affairs Committee, the committee to which this bill was assigned for consideration. This means that there should be sufficient influence to see the bill considered in Committee. I do not see anything in the bill that would engender any organized opposition. I suspect that the bill would receive enough bipartisan support for it to be successfully considered in the full House under the suspension of the rules process.

For a more detailed analysis of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/publish/post/38630756 - subscription required.

Saturday, May 22, 2021

Public Comments on CISA Vulnerability Discovery ICR Revision – 5-22-21

On March 19th, 2021 DHS published a 60-day information collection request (ICR) notice to support the expansion of their Vulnerability Discovery program (VDP) to other agencies in the federal government. The comment period closed on the ICR notice this week. Only one additional comment was received beyond the two I reported on over a month ago. The last comment comes from CERT/CC at the Carnegie Mellon University's Software Engineering Institute.

CERT/CC’s comment contains a very good description of the type of information needed in an actionable vulnerability report.

CISA will not evaluate the comments received and prepare their 30-day ICR notice. I suspect that there will be only a relatively short delay until that notice is published in the Federal Register. Typically this takes a couple of months, but has been known to take years on more controversial ICRs.

Saturday, April 10, 2021

Public Comments on CISA Vulnerability Discovery ICR Revision – 4-10-21

Last month DHS published [Link added 4-10-21 1422 EDT] a 60-day information collection request (ICR) notice to support the expansion of their Vulnerability Discovery program (VDP) to other agencies in the federal government. This post is (maybe?) part of a series of posts that looks at public comments submitted in response to that ICR. The end of the comment period is May 18th, 2021.

To date there are two public responses to that ICR notice. One, of course, is from my blog post [.PDF download link], the other is from Andrew Hunt. Along with a brief comment, Hunt provides a marked-up copy [.PDF download link] of the 60-day ICR notice, clarifying the changes that he suggests.

Hunt suggests:

“Overall, shift language from 'all agencies with their web forms' to 'DHS CISA centralized reporting'. They have the expertise to collect this sensitive information, secure it appropriately, disseminate appropriately, and engage agencies to remediate their exposures. Review 'lawful method to practice...discover new vulnerabilities' language if that is not intended to provide safe harbor protections to hackers. Remove references to 'Solarwinds Hack' and replace with codenames (e.g. SunBurst, SunShuttle) or descriptions to reduce liability of brand damage to the Solarwinds company as it is trying to recover from this truly terrible attack. Reword the definition of a 'vulnerability' as more to do with redirection of expected execution and behavior rather than controls bypass. A vulnerability can exist without a defined/intended control.”

He makes the following additional points in the marked-up document:

• Controls are not always defined before being vulnerable. A better definition: ‘coerces hardware/software to execute or behave in unintended ways from the design’.

• “… lawful method to practice and discover new cyber methods to discover the vulnerabilities….” CLARIFY: this sounds like a safe-harbor statement for hackers.

• If you do not guarantee confidentiality, then no one will play with you. Exempt this from FOIA.

• Use one site, done right, secured, and managed by those with the experience to do so. Remediation of vulnerabilities are notified, then managed by CISA. Agencies follow CISA direction to properly mitigate the vulnerability.

Commentary

While Hunt’s comments are brief he brings up some interesting points. First, his suggestion that DHS run a centralized VDP meshes well with my observations about the requirements of 44 USC 3509. The more interesting point, however, is his take on the definition of ‘security vulnerabilities’ used in the ICR notice. That definition comes from 6 USC 1501(17) and it reads:

“The term "security vulnerability" means any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control.”

Hunt makes the point that: “Controls are not always defined before being vulnerable. A better definition: ‘coerces hardware/software to execute or behave in unintended ways from the design’.” Playing with Hunt’s comments just a bit, I would like to offer this formal version of Hunt’s suggestion:

“The term “security vulnerability” means any attribute of hardware, software, process or procedure that would allow or cause that hardware, software, process or procedure to execute or perform in an unintended way from the design.”

Unfortunately, an ICR is not the appropriate vehicle for changing a regulatory definition. DHS is not, however, required to utilize the definition from §1501 in this ICR. They could instead use my formal definition above, substituting “Security vulnerabilities may be defined as” for the first five words of the revised definition.

His comment about removing the SolarWinds name from discussion in the ‘Supplementary Information’ portion of the Notice brings up an interesting point. While I personally do not care much about wounded corporate egos, DHS is not responding to the vulnerabilities in the SolarWind products (that is the sole responsibility of the company), they are responding to the effects of the attacks wrought by SunBurst, SunShuttle etc. Thus, naming them rather than SolarWinds is probably more appropriate.

Finally, I am not sure that I agree with his FOIA comment. Researchers have no need to ‘protect’ their discovery of vulnerabilities. Vendor and agency developers might, but their response is not the subject of the ICR. There would certainly be some justification for restricting access to the vulnerability information pending mitigation actions. Reported vulnerabilities should probably be protected as sensitive but unclassified information pending mitigation development.

 
/* Use this with templates/template-twocol.html */