{"database": "press", "table": "releases", "rows": [["https://www.king.senate.gov/newsroom/press-releases/king-heinrich-urge-president-to-strengthen-cybersecurity-networks", "King, Heinrich Urge President to Strengthen Cybersecurity Networks", "2016-10-24", "2016", "2016-10", "Independent", "House", "ME", "Angus King", "K000383", "www.king.senate.gov", null, null, "legacy", "King, Heinrich Urge President to Strengthen Cybersecurity Networks\n\t\t\t\t\n\t\t\t\t\tIn a letter that comes days after complex cyber-attack, the Senators call on the President to adopt government-wide policies that will help detect vulnerabilities and communicate them to private sector\n\t\t\t\t\n\t\t\t\n\t\t\t\n\t\t\t\n\t\t\t\tMonday, October 24, 2016\n\t\t\t\n\t\t\t\n\t\n\t\t\t\n\t\t\tBRUNSWICK, ME \u2013 In the wake of a complex cyber-attack that disrupted service to Twitter, Spotify, The New York Times and other major websites, U.S. Senators Angus King (I-Maine) and Martin Heinrich (D-N.M.) today called on President Barack Obama to work with Congress to strengthen the federal government\u2019s ability to detect and repair cyber-vulnerabilities within U.S. networks. In a letter sent today, the two members of the Senate Intelligence Committee urged the President to help establish uniform policies across the government that would secure U.S. networks and establish a comprehensive process that would relay any detected vulnerabilities to private sector companies for repair.\r\n\u201cGiven the growing threat to our nation\u2019s networks and digital services, we write to urge you to work with us to establish enduring government policies for the discovery, review, and sharing of security vulnerabilities. The recent intrusions into United States networks and the controversy surrounding the Federal Bureau of Investigation\u2019s efforts to access the iPhone used in the San Bernardino attacks have underscored for us the need to establish more robust and accountable policies regarding security vulnerabilities,\u201d Senators King and Heinrich wrote in their letter.\r\nSenators King and Heinrich pointed specifically to the success of the Department of Defense\u2019s (DOD) \u201cBug Bounty\u201d program, which rewards so-called \u201cwhite hat\u201d hackers who detect and report security vulnerabilities within the DOD\u2019s networks. Of the 1,410 vetted U.S.-based hackers who registered for the Pentagon\u2019s program, 250 successfully found vulnerabilities and 138 submissions were found to be \u201clegitimate, unique and eligible for a bounty.\u201d\r\n\u201cWe believe such programs represent a cost-effective way to supplement and support the people who defend our government\u2019s IT systems \u2013 and these efforts should not be limited to the Pentagon\u2019s networks,\u201d the Senators wrote.\u00a0 \u201cAs such, we request that your administration work with us to establish standards and appropriate coordination platforms to build on the success of the Department\u2019s pilot and promote government-wide bug bounty programs.\u201d\r\nThe Senators also encouraged the President to continue to strengthen the Vulnerabilities Equities Process, otherwise known as VEP, which serves as the primary process for deciding whether a government entity must disclose to private companies\u2019 information about security vulnerabilities in their products, or whether the government may withhold the information for law enforcement or intelligence purposes. The Senators requested that the Administration establish a comprehensive policy that includes standard criteria for reporting vulnerabilities to the VEP, guidelines for making VEP determinations, clear time limits for each stage of the process, adequate participation of all relevant government agencies, and regular reporting to Congress.\r\n\u201cWe believe the VEP framework is vital to ensuring that security vulnerabilities are either disclosed immediately so the relevant companies can strengthen consumer security, or put through a robust, accountable, and expeditious review process in the exceptional circumstances when the government may wish to delay disclosure for a limited amount of time,\u201d they wrote.\r\nThe complete text of the letter can be read below:\r\n\r\n+++\r\n\r\nOctober 24, 2016\r\n\u00a0\r\nThe President\r\nThe White House\r\n1600 Pennsylvania Avenue, NW\r\nWashington, DC\u00a0 20500\r\n\u00a0\r\nDear Mr. President:\r\n\u00a0\r\nGiven the growing threat to our nation\u2019s networks and digital services, we write to urge you to work with us to establish enduring government policies for the discovery, review, and sharing of security vulnerabilities.\u00a0 \r\nThe recent intrusions into United States networks and the controversy surrounding the Federal Bureau of Investigation\u2019s efforts to access the iPhone used in the San Bernardino attacks have underscored for us the need to establish more robust and accountable policies regarding security vulnerabilities.\u00a0 Specifically, we are exploring whether legislation is needed to establish government-wide policies with respect to two lines of effort: \u201cbug bounty\u201d programs that would help secure government networks like those used by the Office of Personnel Management, and formalizing the vulnerabilities equities process, which notifies software and hardware manufacturers of vulnerabilities discovered in their products. \r\nBug Bounty Programs: The private sector has been using bug bounty programs for decades to reward people who report security vulnerabilities in companies\u2019 applications, websites, and networks.\u00a0 Earlier this year, the Department of Defense launched \u201cHack the Pentagon,\u201d the first cyber bug bounty program in the history of the federal government.\u00a0 Of the 1,410 vetted U.S.-based hackers who registered for the Pentagon\u2019s program, 250 successfully found vulnerabilities and 138 submissions were found to be \u201clegitimate, unique and eligible for a bounty.\u201d\u00a0 \r\nWe believe such programs represent a cost-effective way to supplement and support the people who defend our government\u2019s IT systems \u2013 and these efforts should not be limited to the Pentagon\u2019s networks.\u00a0 As such, we request that your administration work with us to establish standards and appropriate coordination platforms to build on the success of the Department\u2019s pilot and promote government-wide bug bounty programs.\u00a0\u00a0 \r\nVulnerabilities Equities Process (VEP): Over the last several years, your administration, led by White House Cybersecurity Coordinator Michael Daniel, has made progress in establishing the VEP as the primary process for deciding whether a government entity must disclose to private companies\u2019 information about security vulnerabilities in their products, or whether the government may withhold the information for law enforcement or intelligence purposes.\u00a0 We believe the VEP framework is vital to ensuring that security vulnerabilities are either disclosed immediately so the relevant companies can strengthen consumer security, or put through a robust, accountable, and expeditious review process in the exceptional circumstances when the government may wish to delay disclosure for a limited amount of time.\u00a0 \r\nDuring a Senate Armed Services Committee hearing on September 13th, Admiral Rogers said the NSA has utilized a \u201cvulnerability evaluation process\u201d since 2014 and that its \u201coverall disclosure rate [of vulnerabilities to companies] has been 93 percent or so.\u201d\u00a0 However, as of today, there is no legal obligation on government agencies to report the security vulnerabilities they discover or acquire to the White House-led VEP, nor is the VEP codified in law.\u00a0 In fact, it is unclear to us if all security vulnerabilities acquired by our government currently go through the VEP.\u00a0 \r\nTherefore, we request that your administration work with us to establish comprehensive and enduring policies governing the VEP process, including standard criteria for reporting vulnerabilities to the VEP, guidelines for making VEP determinations, clear time limits for each stage of the process, adequate participation of all relevant government agencies, and regular reporting to Congress.\r\nFinally, last year Congress passed, and you signed, the Cybersecurity Information Sharing Act of 2015 (CISA).\u00a0 We were early proponents of this legislation, which directs the federal government to increase its sharing of cyber information with the private sector to assist companies in protecting their systems, and provides clear authority and liability protection for private sector entities to share information with the government.\u00a0 We encourage your administration to use all of the authorities available under CISA to make progress on the lines of effort we have outlined above.\u00a0 \r\nThank you for your attention to these important issues.\u00a0 We look forward to working closely with your administration on these vital national security challenges in the weeks ahead. \r\n###", 1, "2026-03-30T12:14:52Z", "2026-03-30T12:14:52Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.king.senate.gov/newsroom/press-releases/king-heinrich-urge-president-to-strengthen-cybersecurity-networks"], "units": {}, "query_ms": 1.4953529462218285, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}