Sec. 632.
359 words·~2 min read·
/bill/116/hr/21/eh/section-632A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
None of the funds appropriated or otherwise made available under this Act may be used by departments and agencies funded in this Act to acquire telecommunications equipment produced by Huawei Technologies Company, ZTE Corporation or a high-impact or moderate-impact information system, as defined for security categorization in the National Institute of Standards and Technology’s
(NIST)Federal Information Processing Standard Publication 199, Standards for Security Categorization of Federal Information and Information Systems unless the agency has— reviewed the supply chain risk for the information systems against criteria developed by NIST to inform acquisition decisions for high-impact and moderate-impact information systems within the Federal Government; reviewed the supply chain risk from the presumptive awardee against available and relevant threat information provided by the Federal Bureau of Investigation and other appropriate agencies; and in consultation with the Federal Bureau of Investigation or other appropriate Federal entity, conducted an assessment of any risk of cyber-espionage or sabotage associated with the acquisition of such system, including any risk associated with such system being produced, manufactured, or assembled by one or more entities identified by the United States Government as posing a cyber threat, including but not limited to, those that may be owned, directed, or subsidized by the People’s Republic of China, the Islamic Republic of Iran, the Democratic People’s Republic of Korea, or the Russian Federation. None of the funds appropriated or otherwise made available under this Act may be used to acquire a high-impact or moderate impact information system reviewed and assessed under subsection
(a)unless the head of the assessing entity described in subsection
(a)has— developed, in consultation with NIST and supply chain risk management experts, a mitigation strategy for any identified risks; determined, in consultation with NIST and the Federal Bureau of Investigation, that the acquisition of such system is in the vital national security interest of the United States; and reported that determination to the Committees on Appropriations of the House of Representatives and the Senate in a manner that identifies the system intended for acquisition and a detailed description of the mitigation strategies identified in (1), provided that such report may include a classified annex as necessary.