FEDERAL · 22 U.S.C. · Chapter 110

Vulnerability disclosure policy and bug bounty program report

22 U.S.C. § 10306
Title22Foreign Relations and Intercourse
Chapter110 — INFORMATION SECURITY AND CYBER DIPLOMACY

This text of 22 U.S.C. § 10306 (Vulnerability disclosure policy and bug bounty program report) is published on Counsel Stack Legal Research, covering United States primary law. Counsel Stack provides free access to over 12 million legal documents including statutes, case law, regulations, and constitutions.

Bluebook
22 U.S.C. § 10306.

Text

(a)Definitions In this section: The term "bug bounty program" means a program under which an approved individual, organization, or company is temporarily authorized to identify and report vulnerabilities of internet-facing information technology of the Department in exchange for compensation. The term "information technology" has the meaning given such term in section 11101 of title 40.
(b)Vulnerability Disclosure Policy Not later than 180 days after December 23, 2022, the Secretary shall design, establish, and make publicly known a Vulnerability Disclosure Policy (referred to in this section as the "VDP") to improve Department cybersecurity by—
(A)creating Department policy and infrastructure to receive reports of and remediate discovered vulnerabilities in line with existing policies

Free access — add to your briefcase to read the full text and ask questions with AI

Related

§ 11101
40 U.S.C. § 11101

Source Credit

History

(Pub. L. 117–263, div. I, title XCV, §9509, Dec. 23, 2022, 136 Stat. 3907.)

Editorial Notes

Statutory Notes and Related Subsidiaries

Definitions
"Department" and "Secretary" as used in this section mean the Department and Secretary of State, unless otherwise specified, see section 9002 of Pub. L. 117–263, set out as a note under section 2651 of this title.

Cite This Page — Counsel Stack

Bluebook (online)
22 U.S.C. § 10306, Counsel Stack Legal Research, https://law.counselstack.com/usc/22/10306.