House passes bill requiring federal contractors to have vulnerability disclosure policies
Full article889 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The legislation to make contractors implement VDPs aligned with NIST guidelines is aimed at protecting Americans’ data, co-sponsor Rep. Nancy Mace says.
Listen to this article
0:00
Learn more.
A bill that would close a loophole in federal cybersecurity standards by requiring government contractors to abide by vulnerability disclosure policies moved one step closer to law Monday after sailing through the House.
The passage of the Federal Contractor Cybersecurity Vulnerability Reduction Act in the House came a month after Reps. Nancy Mace, R-S.C., and Shontel Brown, D-Ohio reintroduced their legislation, which had a companion version last year from Sens. Mark Warner, D-Va., and James Lankford, R-Okla.
Under the bill, covered contractors with the federal government would have to implement vulnerability disclosure policies (VDPs) that are consistent with National Institute of Standards and Technology guidelines. The Office of Management and Budget and the Defense Department would be required to update federal acquisition policies accordingly.
Mace said in a floor speech Monday that the policies currently in place for federal agencies enable third-party researchers and white-hat hackers to work with the government to identify and patch vulnerabilities before a cyberattack occurs, preventing “malign actors affiliated with China, Russia, Iran and others” to exploit insecure IT systems.
“This was an important step in federal cybersecurity, but the work of federal agencies is supplemented by millions of contractors working on behalf of federal departments and agencies,” said Mace, who chairs the House Oversight and Government Reform Subcommittee on Cybersecurity, Information Technology, and Government Innovation.
The federal government awards over 11 million contracts annually, Mace added, giving contractors access to “vast amounts of sensitive information, including personally identifiable information of American citizens.” Compelling federal contractors to follow NIST best practices and guidelines “will help protect the sensitive data of American citizens and our national security,” she said.
Rep. Gerry Connolly, D-Va., ranking member of the House Oversight Committee, called VDPs “an extremely effective tool” to defend systems from cyber threats.
“Most federal agencies already have such policies, as do federal contractors and subcontractors providing information systems and Internet of Things devices to federal agencies,” he said. “By requiring all federal contractors to follow suit, this bill shores up another front in the neverending battle to protect the federal government’s information systems and data, and thereby the American public.”
The bill is backed by several tech companies, including Microsoft, Tenable, Trend Micro and Schneider Electric. A letter from HackerOne and signed by those companies and others was sent to congressional leadership Friday, urging the lawmakers to “swiftly” pass the legislation.
“We commend the bill’s co-sponsors for their leadership on this issue and applaud the House for making this legislation a priority,” Ilona Cohen, chief legal and policy officer of HackerOne, said in a statement. “We look forward to working with the Senate to enact this important bipartisan legislation that will increase protections for sensitive government information and personal data.”
More Scoops
House Republicans roll out national privacy bill
Experts say the federal legislation takes inspiration from states laws in Virginia and Kentucky, but a lack of bipartisan support could spell trouble.
House lawmakers take aim at education requirements for federal cyber jobs
House passes bill to formalize NTIA’s cyber role following Salt Typhoon attacks
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/house-passes-federal-contractors-vdp-bill/