Learn About the Law
Get help with your legal needs
FindLaw’s Learn About the Law features thousands of informational articles to help you understand your options. And if you’re ready to hire an attorney, find one in your area who can help.
Current as of January 01, 2024 | Updated by FindLaw Staff
(a)Annual reports
On an annual basis through 2026, the Director of the Central Intelligence Agency and the Director of the National Security Agency, in coordination with the Director of National Intelligence, shall jointly submit to the congressional intelligence committees a report containing information on foreign commercial providers and the cyber vulnerabilities procured by the intelligence community through foreign commercial providers.
(b)Elements
Each report under subsection (a) shall include, with respect to the period covered by the report, the following:
(1) A description of each cyber vulnerability procured through a foreign commercial provider, including--
(A) a description of the vulnerability;
(B) the date of the procurement;
(C) whether the procurement consisted of only that vulnerability or included other vulnerabilities;
(D) the cost of the procurement;
(E) the identity of the commercial provider and, if the commercial provider was not the original supplier of the vulnerability, a description of the original supplier;
(F) the country of origin of the vulnerability; and
(G) an assessment of the ability of the intelligence community to use the vulnerability, including whether such use will be operational or for research and development, and the approximate timeline for such use.
(2) An assessment of foreign commercial providers that--
(A) pose a significant threat to the national security of the United States; or
(B) have provided cyber vulnerabilities to any foreign government that--
(i) has used the cyber vulnerabilities to target United States persons, the United States Government, journalists, or dissidents; or
(ii) has an established pattern or practice of violating human rights or suppressing dissent.
(3) An assessment of whether the intelligence community has conducted business with the foreign commercial providers identified under paragraph (2) during the 5-year period preceding the date of the report.
(c)Form
Each report under subsection (a) may be submitted in classified form.
(d)Definitions
In this section:
(1)Commercial provider
The term “commercial provider” means any person that sells, or acts as a broker, for a cyber vulnerability.
(2)Cyber vulnerability
The term “cyber vulnerability” means any tool, exploit, vulnerability, or code that is intended to compromise a device, network, or system, including such a tool, exploit, vulnerability, or code procured by the intelligence community for purposes of research and development.
Cite this article: FindLaw.com - 50 U.S.C. § 3242 - U.S. Code - Unannotated Title 50. War and National Defense § 3242. Annual reports on certain cyber vulnerabilities procured by intelligence community and foreign commercial providers of cyber vulnerabilities - last updated January 01, 2024 | https://codes.findlaw.com/us/title-50-war-and-national-defense/50-usc-sect-3242/
FindLaw Codes may not reflect the most recent version of the law in your jurisdiction. Please verify the status of the code you are researching with the state legislature or via Westlaw before relying on it for your legal needs.
A free source of state and federal court opinions, state laws, and the United States Code. For more information about the legal concepts addressed by these cases and statutes, visit FindLaw's Learn About the Law.
Get help with your legal needs
FindLaw’s Learn About the Law features thousands of informational articles to help you understand your options. And if you’re ready to hire an attorney, find one in your area who can help.
Search our directory by legal issue
Enter information in one or both fields (Required)