Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Vulnerability Disclosure topic

No spam. Unsubscribe anytime.

Committee considers vulnerability disclosure program for state election systems; Secretary of State urges caution for voter database

2994065 · April 15, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A bill establishing a vulnerability disclosure program for state electronic systems was presented. Secretary of State David Scanlon said he supports an incremental program but urged excluding the new voter registration database from initial testing until implementation and stabilization are complete.

Representative (name on record) introduced a bill to establish a vulnerability disclosure program (a "bug‑reporting" framework) for state electronic systems, citing cybersecurity best practices recommended by CISA and other bodies. He said the bill had been amended in committee to address concerns raised by the Secretary of State and others.

Secretary of State David Scanlon testified he is “conceptually in support” of a vulnerability disclosure program but urged caution about including the voter registration database at this time. He told senators three states he reviewed (Iowa, Ohio and Minnesota) have programs that do not apply to voter registration databases because of sensitivity. Scanlon said New Hampshire recently implemented a replacement voter registration system that is not yet feature‑complete and that opening it to external testing could create operational risk until the system is finalized. He suggested an incremental approach: start with less sensitive systems and expand over time.

Representative McFarland (sponsor) said the House committee added language intended to provide the Secretary of State time to address any identified vulnerability before it is publicly disclosed and that the bill contemplates coordination with the Department of Information Technology and the Cybersecurity Oversight Committee. He noted the House report recommending passage and said he supports the amended language.

Committee members asked procedural questions about registry, disclosure timelines and whether the program would include a public registry of researchers and vulnerabilities after mitigations. The Secretary said other states require researcher registration, limit systems in scope, and allow remediation time before public disclosure.

The committee held the bill for further review to reconcile the Secretary’s operational concerns and the sponsor’s intent to require timely fixes and public reporting after remediation.