Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Election Systems topic

No spam. Unsubscribe anytime.

Bill would create bug-reporting program for election systems; Secretary of State seeks ability to fix before public disclosure

2159543 · January 28, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Representative Donald McFarland proposed HB 626 to create a vulnerability disclosure program for election-related electronic systems. The Secretary of State's office said it supports the concept but asked for a provision allowing the office to remediate discovered vulnerabilities before public disclosure.

House Bill 626 would direct the Secretary of State to implement a vulnerability disclosure program for specified election-related electronic systems so security researchers can report vulnerabilities and the state can address them. Representative Donald McFarland said the measure is intended to bolster public trust by allowing researchers to assess and report potential flaws to the state.

Deputy Secretary Erin Hennessey told the committee the office supports the bill in concept and that the system is capable of accepting such reports, but asked for clarifying language. She recommended adding a provision that would let the Secretary’s office address discovered vulnerabilities before they are published so the state can remediate risks without exposing an unpatched problem to bad actors. Committee members discussed the need to balance transparency with the practical need to fix flaws first; Representative Toner volunteered to review statutory notice and breach-reporting requirements that might interact with the proposed disclosure program.

No committee vote on HB 626 was recorded during the hearing.