The collection of this information regarding to discovered security vulnerabilities by individuals, organizations, and companies is needed
to fulfil the congressional mandate in Section 101 of the SECURE Technologies Act regarding a Vulnerability Disclosure Policy. In addition, without the ability to collect information on newly discovered security vulnerabilities in DHS information systems, the DHS will rely solely on the internal security personnel and or discovery through post occurrence of such a breach on security controls.
OMB approached the DHS Chief Information Officer (CIO) about utilizing the existing OMB approved collection across the government to ensure that the Department and Agencies meet an OMB and Cybersecurity and Infrastructure Security Agency (CISA) imposed deadline of March 1, 2021 to create vulnerability disclosure policies. On February 4, 2021, the CIO Program Council confirmed that the DHS CIO was amenable to this approach.
PL:
Pub.L. 115 - 390 101
Name of Law: Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure Technology Act
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.