Bill requiring federal contractors to have vulnerability disclosure policies gets House redo
Full article794 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Reps. Nancy Mace and Shontel Brown reintroduced VDP legislation after the 2024 bipartisan, bicameral bill didn’t get a full Senate vote.
Listen to this article
0:00
Learn more.
Bipartisan legislation to close a loophole in federal cybersecurity standards by requiring vulnerability disclosure policies for government contractors is getting another shot at passage in this Congress.
The Federal Contractor Cybersecurity Vulnerability Reduction Act, a bicameral, bipartisan bill that stalled out last year in the Senate, was reintroduced Friday in the House by Reps. Nancy Mace, R-S.C., and Shontel Brown, D-Ohio.
The bill, whose 2024 companion in the upper chamber came from Sens. Mark Warner, D-Va., and James Lankford, R-Okla., calls on the Office of Management and Budget and the Defense Department to update federal acquisition policies to require all federal contractors to institute vulnerability disclosure policies (VDPs).
“This is a matter of national security,” Mace said in a press release. “Federal contractors handle some of the most sensitive information and critical infrastructure in the country. Without basic vulnerability disclosure policies, we are leaving a gaping hole in our cybersecurity defenses. This bipartisan bill ensures contractors uphold the same cybersecurity standards as federal agencies, reducing risks before they turn into catastrophic breaches.”
Brown added that the bill would help to “better protect sensitive data from malicious actors.”
“Cybersecurity isn’t optional, it’s essential,” she said. “To ensure that our systems are fully secure, we need to make sure federal contractors follow national guidelines to protect digital infrastructure.”
Under current law, federal agencies must have vulnerability disclosure policies that align with National Institute of Standards and Technology benchmarks. U.S. government contractors have no such obligation.
In a fact sheet released by Warner and Lankford last August when they rolled out the Senate version of Mace’s bill, the lawmakers pointed to the 2015 Office of Personnel Management data breach, which was made possible by vulnerabilities in systems used by two contractors that stored data on federal employee background checks.
In the last Congress, the bill had bipartisan support and notable industry backing. Ilona Cohen, chief legal and policy officer of HackerOne, said in a statement to CyberScoop that “escalating cyber threats from China and other foreign adversaries” make it especially “critical to protect sensitive government information and personal data.”
“The Federal Contractor Cybersecurity Vulnerability Reduction Act addresses a gap in our nation’s cybersecurity defenses by requiring federal contractors to take a proactive approach to identifying and mitigating vulnerabilities before they can be exploited,” Cohen added. “We commend Representatives Mace and Brown for their leadership on this essential legislation.”
More Scoops
F5 vulnerability highlights weak points in DHS’s CDM program
The Continuous Diagnostics and Mitigation program is oft-praised, but there are areas where it doesn’t yet excel, as a recent CISA emergency directive shows.
House lawmakers take aim at education requirements for federal cyber jobs
Senators take another swing at vulnerability disclosure policy bill for federal contractors
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/federal-contractors-vulnerability-disclosure-policies-house-bill/