{"database": "press", "table": "releases", "rows": [["https://www.king.senate.gov/newsroom/press-releases/icymi-nyts-editorial-applauds-pentagon-cyber-program-king-and-heinrich-want-expanded", "ICYMI: NYTs Editorial Applauds Pentagon Cyber Program King & Heinrich Want Expanded", "2016-11-28", "2016", "2016-11", "Independent", "House", "ME", "Angus King", "K000383", "www.king.senate.gov", null, null, "legacy", "ICYMI: NYTs Editorial Applauds Pentagon Cyber Program King &amp; Heinrich Want Expanded\n\t\t\t\t\n\t\t\t\n\t\t\t\n\t\t\t\n\t\t\t\tMonday, November 28, 2016\n\t\t\t\n\t\t\t\n\t\n\t\t\t\n\t\t\tIn case you missed it, an editorial from the New York Times today applauded the Department of Defense for once again pursuing a \u201cBug Bounty\u201d program, which rewards so-called \u201cwhite hat\u201d hackers who detect and report security vulnerabilities within the Pentagon\u2019s cyber-networks. On October 24, 2016, U.S. Senators Angus King (I-Maine) and Martin Heinrich (D-N.M.), members of the Senate Select Committee on Intelligence, also commended the program in a letter to President Obama and urged him to expand it across the entire government.\r\n\u201cWe believe such programs represent a cost-effective way to supplement and support the people who defend our government\u2019s IT systems \u2013 and these efforts should not be limited to the Pentagon\u2019s networks,\u201d Senators King and Heinrich wrote in their October letter.\u00a0 \u201cAs such, we request that your administration work with us to establish standards and appropriate coordination platforms to build on the success of the Department\u2019s pilot and promote government-wide bug bounty programs.\u201d\r\n+++\r\nNew York Times Editorial: Pentagon: Looking for a Few Good Hackers\r\nBy\u00a0THE EDITORIAL BOARD| NOV. 28, 2016\r\n\r\nIn June 2015, the Office of Personnel Management announced that foreign hackers\u00a0had stolen the personnel records\u00a0of millions of federal employees, one of the most damaging cyberattacks in history. Just weeks later, the office of the Joint Chiefs of Staff shut down its unclassified email system for several days after officials detected that it had been breached.\r\nThese serious intrusions came months after a group affiliated with the Islamic State briefly commandeered\u00a0the Central Command\u2019s Twitter account\u00a0and rebranded it as the \u201cCyber Caliphate.\u201d\r\nGiven the enormity of the problem, one of the responses by the Department of Defense might seem befuddling. They\u2019ve asked hackers willing to play by strict rules to find vulnerabilities in some of the Pentagon\u2019s unclassified computer system.\r\nWell-intentioned computer security experts routinely scan the internet in search of vulnerabilities, which they often map out and report. Until now, doing that on Pentagon sites carried the considerable legal risk of running afoul of the Computer Fraud and Abuse Act.\r\n\u201cHack the Pentagon\u201d kicked off in April with a monthlong trial program that attracted 1,400 so-called white hackers to fiddle with Department of Defense websites on the hunt for weak points that could be exploited to steal data or jam systems. Those hackers spotted 138 weaknesses, according to the Pentagon, and were paid $75,000 in rewards.\r\nEncouraged by the results, the Defense Department last week\u00a0announced a formal policy\u00a0permitting outside computer experts to test for vulnerabilities in the system and report them to the department. Secretary of Defense\u00a0Ashton Carter called the initiative\u00a0\u201ca \u2018see something, say something\u2019 policy for the digital domain.\u201d Those hackers won\u2019t be paid for their reports, but officials hope they will do it out of a sense of duty.\r\nIn addition, the department has started \u201cHack the Army,\u201d a program asking hackers who have been approved by the government to test the Army\u2019s recruiting websites for weaknesses.\r\nWhile these efforts represent just one aspect of the federal government\u2019s effort to protect secret data more rigorously, Mr. Carter deserves credit for championing an unconventional approach.\r\n\u201cHack the Pentagon\u201d and \u201cHack the Army\u201d allows defense officials to draw from a talent pool that includes people who would not ordinarily feel at home in the military\u2019s hierarchical culture. It may well turn into an unconventional recruitment pipeline for an organization that always benefits from outside perspectives and carefully calibrated disruption.\r\nhttp://www.nytimes.com/2016/11/28/opinion/pentagon-looking-for-a-few-good-hackers.html?partner=rssnyt&amp;emc=rss&amp;_r=0\r\n+++\r\n\r\nKing, Heinrich Urge President to Strengthen Cybersecurity Networks\r\nIn a letter that comes days after complex cyber-attack, the Senators call on the President to adopt government-wide policies that will help detect vulnerabilities and communicate them to private sector\r\nBRUNSWICK, ME \u2013 In the wake of a complex cyber-attack that disrupted service to Twitter, Spotify, The New York Times and other major websites, U.S. Senators Angus King (I-Maine) and Martin Heinrich (D-N.M.) today called on President Barack Obama to work with Congress to strengthen the federal government\u2019s ability to detect and repair cyber-vulnerabilities within U.S. networks. In a letter sent today, the two members of the Senate Intelligence Committee urged the President to help establish uniform policies across the government that would secure U.S. networks and establish a comprehensive process that would relay any detected vulnerabilities to private sector companies for repair.\r\n\u201cGiven the growing threat to our nation\u2019s networks and digital services, we write to urge you to work with us to establish enduring government policies for the discovery, review, and sharing of security vulnerabilities. The recent intrusions into United States networks and the controversy surrounding the Federal Bureau of Investigation\u2019s efforts to access the iPhone used in the San Bernardino attacks have underscored for us the need to establish more robust and accountable policies regarding security vulnerabilities,\u201d Senators King and Heinrich wrote in their letter.\r\nSenators King and Heinrich pointed specifically to the success of the Department of Defense\u2019s (DOD) \u201cBug Bounty\u201d program, which rewards so-called \u201cwhite hat\u201d hackers who detect and report security vulnerabilities within the DOD\u2019s networks. Of the 1,410 vetted U.S.-based hackers who registered for the Pentagon\u2019s program, 250 successfully found vulnerabilities and 138 submissions were found to be \u201clegitimate, unique and eligible for a bounty.\u201d\r\n\u201cWe believe such programs represent a cost-effective way to supplement and support the people who defend our government\u2019s IT systems \u2013 and these efforts should not be limited to the Pentagon\u2019s networks,\u201d the Senators wrote.\u00a0 \u201cAs such, we request that your administration work with us to establish standards and appropriate coordination platforms to build on the success of the Department\u2019s pilot and promote government-wide bug bounty programs.\u201d\r\nThe Senators also encouraged the President to continue to strengthen the Vulnerabilities Equities Process, otherwise known as VEP, which serves as the primary process for deciding whether a government entity must disclose to private companies\u2019 information about security vulnerabilities in their products, or whether the government may withhold the information for law enforcement or intelligence purposes. The Senators requested that the Administration establish a comprehensive policy that includes standard criteria for reporting vulnerabilities to the VEP, guidelines for making VEP determinations, clear time limits for each stage of the process, adequate participation of all relevant government agencies, and regular reporting to Congress.\r\n\u201cWe believe the VEP framework is vital to ensuring that security vulnerabilities are either disclosed immediately so the relevant companies can strengthen consumer security, or put through a robust, accountable, and expeditious review process in the exceptional circumstances when the government may wish to delay disclosure for a limited amount of time,\u201d they wrote.\r\nThe complete text of the letter can be read below:\r\n+++\r\nOctober 24, 2016\r\n\r\nThe President\r\nThe White House\r\n1600 Pennsylvania Avenue, NW\r\nWashington, DC\u00a0 20500\r\n\u00a0\r\nDear Mr. President:\r\n\u00a0\r\nGiven the growing threat to our nation\u2019s networks and digital services, we write to urge you to work with us to establish enduring government policies for the discovery, review, and sharing of security vulnerabilities.\u00a0\r\nThe recent intrusions into United States networks and the controversy surrounding the Federal Bureau of Investigation\u2019s efforts to access the iPhone used in the San Bernardino attacks have underscored for us the need to establish more robust and accountable policies regarding security vulnerabilities.\u00a0 Specifically, we are exploring whether legislation is needed to establish government-wide policies with respect to two lines of effort: \u201cbug bounty\u201d programs that would help secure government networks like those used by the Office of Personnel Management, and formalizing the vulnerabilities equities process, which notifies software and hardware manufacturers of vulnerabilities discovered in their products.\r\nBug Bounty Programs: The private sector has been using bug bounty programs for decades to reward people who report security vulnerabilities in companies\u2019 applications, websites, and networks.\u00a0 Earlier this year, the Department of Defense launched \u201cHack the Pentagon,\u201d the first cyber bug bounty program in the history of the federal government.\u00a0 Of the 1,410 vetted U.S.-based hackers who registered for the Pentagon\u2019s program, 250 successfully found vulnerabilities and 138 submissions were found to be \u201clegitimate, unique and eligible for a bounty.\u201d\u00a0\r\nWe believe such programs represent a cost-effective way to supplement and support the people who defend our government\u2019s IT systems \u2013 and these efforts should not be limited to the Pentagon\u2019s networks.\u00a0 As such, we request that your administration work with us to establish standards and appropriate coordination platforms to build on the success of the Department\u2019s pilot and promote government-wide bug bounty programs.\u00a0\u00a0\r\nVulnerabilities Equities Process (VEP): Over the last several years, your administration, led by White House Cybersecurity Coordinator Michael Daniel, has made progress in establishing the VEP as the primary process for deciding whether a government entity must disclose to private companies\u2019 information about security vulnerabilities in their products, or whether the government may withhold the information for law enforcement or intelligence purposes.\u00a0 We believe the VEP framework is vital to ensuring that security vulnerabilities are either disclosed immediately so the relevant companies can strengthen consumer security, or put through a robust, accountable, and expeditious review process in the exceptional circumstances when the government may wish to delay disclosure for a limited amount of time.\u00a0\r\nDuring a Senate Armed Services Committee hearing on September 13th, Admiral Rogers said the NSA has utilized a \u201cvulnerability evaluation process\u201d since 2014 and that its \u201coverall disclosure rate [of vulnerabilities to companies] has been 93 percent or so.\u201d\u00a0 However, as of today, there is no legal obligation on government agencies to report the security vulnerabilities they discover or acquire to the White House-led VEP, nor is the VEP codified in law.\u00a0 In fact, it is unclear to us if all security vulnerabilities acquired by our government currently go through the VEP.\u00a0\r\nTherefore, we request that your administration work with us to establish comprehensive and enduring policies governing the VEP process, including standard criteria for reporting vulnerabilities to the VEP, guidelines for making VEP determinations, clear time limits for each stage of the process, adequate participation of all relevant government agencies, and regular reporting to Congress.\r\nFinally, last year Congress passed, and you signed, the Cybersecurity Information Sharing Act of 2015 (CISA).\u00a0 We were early proponents of this legislation, which directs the federal government to increase its sharing of cyber information with the private sector to assist companies in protecting their systems, and provides clear authority and liability protection for private sector entities to share information with the government.\u00a0 We encourage your administration to use all of the authorities available under CISA to make progress on the lines of effort we have outlined above.\u00a0\r\nThank you for your attention to these important issues.\u00a0 We look forward to working closely with your administration on these vital national security challenges in the weeks ahead.\r\n###", 1, "2026-03-30T12:14:52Z", "2026-03-30T12:14:52Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.king.senate.gov/newsroom/press-releases/icymi-nyts-editorial-applauds-pentagon-cyber-program-king-and-heinrich-want-expanded"], "units": {}, "query_ms": 1.427368028089404, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}