Loading chat...

DE SB283

Bill

Status

Introduced

6/16/2016

Primary Sponsor

Catherine Cloutier

Click for details

Origin

Senate

148th General Assembly

AI Summary

Senate Bill 283 Summary

  • Establishes a vulnerability coordination policy in Delaware Code Chapter 90C requiring software vendors to publicly publish procedures for receiving security vulnerability reports from researchers.

  • Requires vendors to enumerate their products and scope, list prohibited testing methods (such as denial of service attacks and destructive actions), and respond to vulnerability reports within two business days.

  • Provides legal immunity to security researchers who discover vulnerabilities in state software, provided they follow the policy terms and do not conduct prohibited testing methods.

  • Obligates security researchers to cooperate with vendors until disclosure, refrain from early public disclosure, and avoid extortion or sale of reported vulnerabilities.

  • Establishes a 90-day deadline for public disclosure of vulnerabilities, allowing disclosure only after a patch is released or 90 days have elapsed without a patch.

Legislative Description

An Act To Amend Title 29 Of The Delaware Code Relating To Vulnerability Coordination Policy

Last Action

Reported Out of Committee (ADMINISTRATIVE SERVICES/ELECTIONS) in Senate with 6 On Its Merits

6/22/2016

Committee Referrals

Administrative Services/Elections6/16/2016

Full Bill Text

No bill text available