summary
Introduced
12/04/2014
12/04/2014
In Committee
12/04/2014
12/04/2014
Crossed Over
Passed
Dead
01/03/2015
01/03/2015
Introduced Session
113th Congress
Bill Summary
Cyber Supply Chain Management and Transparency Act of 2014
AI Summary
This bill, the Cyber Supply Chain Management and Transparency Act of 2014, aims to strengthen the security of software, firmware, and products used by the U.S. Government by requiring the Office of Management and Budget (OMB) to issue guidelines for government agencies. These guidelines will mandate that contracts for software, firmware, or products containing "binary components" – which are defined as third-party or open-source components – must include specific clauses. These clauses will require contractors to provide a detailed list of all binary components used, verify that these components do not have known security vulnerabilities listed in databases like the National Institute of Standards and Technology (NIST) National Vulnerability Database, and notify the agency of any discovered vulnerabilities. The bill also includes provisions for waivers for vulnerable components, requiring agencies to accept the associated risks, and ensures that software is designed to allow for easy patching and updating of security flaws. Furthermore, agencies will be required to have processes in place to replace or repair vulnerable binary components, and to migrate away from unfixable vulnerable products. The bill also mandates the creation of an inventory of existing vulnerable components and an annual report from the Department of Homeland Security assessing the security of binary component suppliers. Finally, it requires agencies to report on the removal of vulnerable binary components and to prioritize critical systems in this replacement process.
Committee Categories
Government Affairs
Sponsors (2)
Last Action
Referred to the House Committee on Oversight and Government Reform. (on 12/04/2014)
Official Document
bill text
bill summary
Loading...
bill summary
Loading...
bill summary
| Document Type | Source Location |
|---|---|
| State Bill Page | https://www.congress.gov/bill/113th-congress/house-bill/5793/all-info |
| BillText | http://gpo.gov/fdsys/pkg/BILLS-113hr5793ih/pdf/BILLS-113hr5793ih.pdf |
| Bill | http://gpo.gov/fdsys/pkg/BILLS-113hr5793ih/pdf/BILLS-113hr5793ih.pdf.pdf |
Loading...