Sec. 515.
155 words·~1 min read·
/bill/114/s/2837/pcs/section-515·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
None of the funds appropriated or otherwise made available under this Act may be used by the Departments of Commerce and Justice, the National Aeronautics and Space Administration, or the National Science Foundation to acquire a high-impact information system, as defined for security categorization in the National Institute of Standards and Technology's
(NIST)Federal Information Processing Standard Publication 199, Standards for Security Categorization of Federal Information and Information Systems unless the agency has— reviewed the supply chain risk for the information systems against criteria developed by NIST to inform acquisition decisions for high-impact information systems within the Federal Government and against international standards and guidelines, including those developed by NIST; reviewed the supply chain risk from the presumptive awardee against available and relevant threat information provided by the Federal Bureau of Investigation and other appropriate agencies; and developed, in consultation with NIST and supply chain risk management experts, a mitigation strategy for any identified risks.