Information Collection Request

Vulnerability Discovery Program

ICR 202002-1601-001 · OMB 1601-0028 · Active

Forms and Documents
DocumentTypeStatusAvailability
Vulnerability Disclosure Program, 20190725, PRIV Final.docx Supplementary Document Uploaded 2020-02-13 Available
PLAW-115publ390.pdf Supplementary Document Uploaded 2020-02-13 Available
Supporting Statement A VDP.docx Supporting Statement A Uploaded 2020-02-13 Available
30 Day FRN Vulnerability Discovery Program.pdf Supplementary Document Uploaded 2020-02-13 Available
60 Day FRN Vulnerability Discovery Program.pdf Supplementary Document Uploaded 2020-02-13 Available
IC Document Collections
IC IDCollectionTypeStatusForm
239958 Vulnerability Discovery Program Other-Mock Up New
ICR Details
1601-0028 202002-1601-001
Active
DHS/OS
Vulnerability Discovery Program
New collection (Request for a new OMB Control Number)   No
Regular
Approved without change 08/15/2020
Retrieve Notice of Action (NOA) 02/13/2020
OMB is approving this new form for one year. Prior to resubmitting the form for extension, the agency will again seek comment on all aspects of this form.
  Inventory as of this Action Requested Previously Approved
08/31/2021 36 Months From Approved
3,000 0 0
9,000 0 0
0 0 0

The collection of this information regarding to discovered security vulnerabilities by individuals, organizations, and companies is needed to fulfil the congressional mandate in Section 101 of the SECURE Technologies Act regarding a Vulnerability Disclosure Policy. In addition, without the ability to collect information on newly discovered security vulnerabilities in DHS information systems, the DHS will rely solely on the internal security personnel and or discovery through post occurrence of such a breach on security controls.

None
None

Not associated with rulemaking

  84 FR 45166 08/28/2019
84 FR 70561 12/23/2019
Yes

1
IC Title Form No. Form Name
Vulnerability Discovery Program

  Total Approved Previously Approved Change Due to New Statute Change Due to Agency Discretion Change Due to Adjustment in Estimate Change Due to Potential Violation of the PRA
Annual Number of Responses 3,000 0 0 3,000 0 0
Annual Time Burden (Hours) 9,000 0 0 9,000 0 0
Annual Cost Burden (Dollars) 0 0 0 0 0 0
Yes
Miscellaneous Actions
No
This is a new collection.

$863,730
No
    No
    Yes
No
No
No
No
Tyrone Huff 202 447-0106 [email protected]

  No

On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
 
 
 
 
 
 
 
    (i) Why the information is being collected;
    (ii) Use of information;
    (iii) Burden estimate;
    (iv) Nature of response (voluntary, required for a benefit, or mandatory);
    (v) Nature and extent of confidentiality; and
    (vi) Need to display currently valid OMB control number;
 
 
 
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.
02/13/2020