Definitions
Vulnerabilities Equities Policy and Process document
The term “Vulnerabilities Equities Policy and Process document” means the executive branch document entitled “Vulnerabilities Equities Policy and Process” dated .
Vulnerabilities Equities Process
The term “Vulnerabilities Equities Process” means the interagency review of vulnerabilities, pursuant to the Vulnerabilities Equities Policy and Process document or any successor document.
Vulnerability
The term “vulnerability” means a weakness in an information system or its components (for example, system security procedures, hardware design, and internal controls) that could be exploited or could affect confidentiality, integrity, or availability of information.
Reports on process and criteria under Vulnerabilities Equities Policy and Process
In general
Changes to process or criteria
Not later than 30 days after any significant change is made to the process and criteria used by any element of the intelligence community for determining whether to submit a vulnerability for review under the Vulnerabilities Equities Process, such element shall submit to the congressional intelligence committees a report describing such change.
Form of reports
Each report submitted under this subsection shall be submitted in unclassified form, but may include a classified annex.
Annual reports
In general
Unclassified information
Nonduplication
The Director of National Intelligence may forgo submission of an annual report required under this subsection for a calendar year, if the Director notifies the intelligence committees in writing that, with respect to the same calendar year, an annual report required by paragraph 4.3 of the Vulnerabilities Equities Policy and Process document already has been submitted to Congress, and such annual report contains the information that would otherwise be required to be included in an annual report under this subsection.
Publication
The Director of National Intelligence shall make available to the public each unclassified appendix submitted with a report under paragraph (1) pursuant to paragraph (2).
Pub. L. 116–92, div. E, title LXVII, § 6720133 Stat. 2230Pub. L. 117–103, div. X, title III, § 307136 Stat. 966(, , ; , , .)
Editorial Notes
Amendments
Pub. L. 117–1032022—Subsec. (c)(4). added par. (4).
Statutory Notes and Related Subsidiaries
Definitions
section 5003 of div. E of Pub. L. 116–92section 3003 of this titleFor definitions of “congressional intelligence committees” and “intelligence community” as used in this section, see , set out as a note under .