50 U.S.C. · War and National Defense
50 U.S.C. § 3242

Annual reports on certain cyber vulnerabilities procured by intelligence community and foreign commercial providers of cyber vulnerabilities

Ch. 44 — NATIONAL SECURITY
Title 50 U.S.C. ● ACTIVE Primary Source Ch. 44
Statutory Text

50 U.S.C. § 3242 — Annual reports on certain cyber vulnerabilities procured by intelligence community and foreign commercial providers of cyber vulnerabilities

U.S.C. Title 50 - WAR AND NATIONAL DEFENSE 50 U.S.C. United States Code, 2023 Edition Title 50 - WAR AND NATIONAL DEFENSE CHAPTER 44 - NATIONAL SECURITY SUBCHAPTER IX - ADDITIONAL MISCELLANEOUS PROVISIONS Sec. 3242 - Annual reports on certain cyber vulnerabilities procured by intelligence community and foreign commercial providers of cyber vulnerabilities From the U.S. Government Publishing Office, www.gpo.gov

§3242. Annual reports on certain cyber vulnerabilities procured by intelligence community and foreign commercial providers of cyber vulnerabilities

(a) Annual reports On an annual basis through 2026, the Director of the Central Intelligence Agency and the Director of the National Security Agency, in coordination with the Director of National Intelligence, shall jointly submit to the congressional intelligence committees a report containing information on foreign commercial providers and the cyber vulnerabilities procured by the intelligence community through foreign commercial providers. (b) Elements Each report under subsection (a) shall include, with respect to the period covered by the report, the following: (1) A description of each cyber vulnerability procured through a foreign commercial provider, including— (A) a description of the vulnerability; (B) the date of the procurement; (C) whether the procurement consisted of only that vulnerability or included other vulnerabilities; (D) the cost of the procurement; (E) the identity of the commercial provider and, if the commercial provider was not the original supplier of the vulnerability, a description of the original supplier; (F) the country of origin of the vulnerability; and (G) an assessment of the ability of the intelligence community to use the vulnerability, including whether such use will be operational or for research and development, and the approximate timeline for such use.

(2) An assessment of foreign commercial providers that— (A) pose a significant threat to the national security of the United States; or (B) have provided cyber vulnerabilities to any foreign government that— (i) has used the cyber vulnerabilities to target United States persons, the United States Government, journalists, or dissidents; or (ii) has an established pattern or practice of violating human rights or suppressing dissent.

(3) An assessment of whether the intelligence community has conducted business with the foreign commercial providers identified under paragraph (2) during the 5-year period preceding the date of the report. (c) Form Each report under subsection (a) may be submitted in classified form. (d) Definitions In this section: (1) Commercial provider The term "commercial provider" means any person that sells, or acts as a broker, for a cyber vulnerability. (2) Cyber vulnerability The term "cyber vulnerability" means any tool, exploit, vulnerability, or code that is intended to compromise a device, network, or system, including such a tool, exploit, vulnerability, or code procured by the intelligence community for purposes of research and development.

(July 26, 1947, ch. 343, title XI, §1112, as added Pub. L. 117–103, div. X, title VIII, §822(a), Mar. 15, 2022, 136 Stat. 1020.)

Statutory Notes and Related Subsidiaries First Report Pub. L. 117–103, div. X, title VIII, §822(b), Mar. 15, 2022, 136 Stat. 1021, provided that: "Not later than 90 days after the date of the enactment of this Act [Mar. 15, 2022], the Director of the Central Intelligence Agency and the Director of the National Security Agency shall jointly submit the first report required under section 1112 of the National Security Act of 1947 [50 U.S.C. 3242], as added by subsection (a)."

Source: uscode.house.gov — public domain Official Source ↗
Root-LD Entity Data
◈ Machine-Readable Provenance Record Root-LD v1.0 · boisestandard.org
Federation ID
BS-USC50-SEC-C5F2B2
Entity Class
STATUTE / FEDERAL-CODE-SECTION
Domain Signature
boisestandard.org
Citation
50 U.S.C. § 3242
Jurisdiction
Federal — United States
Status
✓ ACTIVE
Source
PRIMARY-SOURCE
Source Verified
✓ TRUE
Content Hash
34e47b3f7c3b57d6...
Semantic Edges
Pending — corpus passes queued
The statutory text of 50 U.S.C. § 3242 is reproduced from the official United States Code as published by the Office of the Law Revision Counsel of the U.S. House of Representatives (uscode.house.gov).
Navigate Corpus — Title 50
◈ Provenance
boisestandard.org United States Law U.S. Code Title 50 50 U.S.C. § 3242