<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-House" bill-type="olc" dms-id="H3EF4E9020E6746E795CB27841B30B420" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 1668 RH: Internet of Things Cybersecurity Improvement Act of 2019</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2020-09-14</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">IB</distribution-code><calendar display="yes">Union Calendar No. 402</calendar><congress display="yes">116th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 1668</legis-num><associated-doc role="report" display="yes">[Report No. 116–501, Part I]</associated-doc><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20190311">March 11, 2019</action-date><action-desc><sponsor name-id="K000385">Ms. Kelly of Illinois</sponsor> (for herself, <cosponsor name-id="H001073">Mr. Hurd of Texas</cosponsor>, <cosponsor name-id="K000389">Mr. Khanna</cosponsor>, <cosponsor name-id="B001305">Mr. Budd</cosponsor>, <cosponsor name-id="R000576">Mr. Ruppersberger</cosponsor>, <cosponsor name-id="M001198">Mr. Marshall</cosponsor>, <cosponsor name-id="L000582">Mr. Ted Lieu of California</cosponsor>, <cosponsor name-id="R000601">Mr. Ratcliffe</cosponsor>, <cosponsor name-id="M001187">Mr. Meadows</cosponsor>, <cosponsor name-id="S001200">Mr. Soto</cosponsor>, <cosponsor name-id="W000819">Mr. Walker</cosponsor>, <cosponsor name-id="C001078">Mr. Connolly</cosponsor>, <cosponsor name-id="F000454">Mr. Foster</cosponsor>, and <cosponsor name-id="B001307">Mr. Baird</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HGO00">Committee on Oversight and Reform</committee-name>, and in addition to the Committee on <committee-name committee-id="HSY00">Science, Space, and Technology</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc></action><action display="yes"><action-date date="20200914">September 14, 2020</action-date><action-desc>Additional sponsors: <cosponsor name-id="O000168">Mr. Olson</cosponsor>, <cosponsor name-id="H001087">Ms. Hill of California</cosponsor>, <cosponsor name-id="F000466">Mr. Fitzpatrick</cosponsor>, <cosponsor name-id="O000171">Mr. O'Halleran</cosponsor>, <cosponsor name-id="B001284">Mrs. Brooks of Indiana</cosponsor>, <cosponsor name-id="C001067">Ms. Clarke of New York</cosponsor>, <cosponsor name-id="S001215">Ms. Stevens</cosponsor>, <cosponsor name-id="H001090">Mr. Harder of California</cosponsor>, <cosponsor name-id="N000190">Mr. Norman</cosponsor>, <cosponsor name-id="R000616">Mr. Rouda</cosponsor>, <cosponsor name-id="G000560">Mr. Graves of Georgia</cosponsor>, <cosponsor name-id="W000797">Ms. Wasserman Schultz</cosponsor>, and <cosponsor name-id="D000617">Ms. DelBene</cosponsor></action-desc></action><action display="yes"><action-date date="20200914">September 14, 2020</action-date><action-desc>Reported from the <committee-name added-display-style="italic" committee-id="HGO00" deleted-display-style="strikethrough">Committee on Oversight and Reform</committee-name> with an amendment</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction></action><action><action-desc><pagebreak></pagebreak></action-desc></action><action display="yes"><action-date date="20200914">September 14, 2020</action-date><action-desc>Committee on <committee-name committee-id="HSY00">Science, Space, and Technology</committee-name> discharged; committed to the Committee of the Whole House on the State of the Union and ordered to be printed</action-desc><action-instruction>For text of introduced bill, see copy of bill as introduced on March 11, 2019</action-instruction></action><legis-type>A BILL</legis-type><official-title display="yes">To leverage Federal Government procurement power to encourage increased cybersecurity for Internet of Things devices, and for other purposes.<pagebreak></pagebreak></official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause" changed="added" style="OLC" committee-id="HGO00" reported-display-style="italic" id="H018BFDB2D13D4659985DAB996AE71C50"><section id="HC6A95C7D6C654D0390BE56BFD663C978" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Internet of Things Cybersecurity Improvement Act of 2019</short-title></quote> or the <quote><short-title>IoT Cybersecurity Improvement Act of 2019</short-title></quote>.</text></section><section id="H54FB75744F12412086AC99A5A922FAC6"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="H14C8671061A2473DBD72F78F39C7975B"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given such term in section 3502 of title 44, United States Code.</text></paragraph><paragraph id="H38BE2EC812754D05A6CCCF02D0686911"><enum>(2)</enum><header>Covered device</header><text>The term <term>covered device</term> means a physical object that—</text><subparagraph id="HF6002DEBBC0F43499C58B2A6B2725A8B"><enum>(A)</enum><text>is capable of being in regular connection with—</text><clause id="H1B7BC7E0B0364DBC9C85848AD49E37A0"><enum>(i)</enum><text>the Internet; or</text></clause><clause id="H1D5934C331344C729166E767B6A2D304"><enum>(ii)</enum><text>a network that is connected to the Internet on a recurring basis; </text></clause></subparagraph><subparagraph id="H628B7387264C4EBD91A891F4F951B82A"><enum>(B)</enum><text>has computer processing capabilities of collecting, sending, or receiving data; and </text></subparagraph><subparagraph id="H8FB6E3C5CABC4336AA2475A2607976BE"><enum>(C)</enum><text>is not a—</text><clause id="HE5673A61CFF94240930E0107CD6BC5CB"><enum>(i)</enum><text>general-purpose computing device;</text></clause><clause id="H446D22FCB0FA41EEA3C22A42F4DDEC16"><enum>(ii)</enum><text>personal computing system;</text></clause><clause id="H610A773A6D3A4ADA9CC228DBD977E5E8"><enum>(iii)</enum><text>smart mobile communications device;</text></clause><clause id="H510307061D364F91B3EDB85FC71E3E76"><enum>(iv)</enum><text>programmable logic controller with an industrial control system specifically not designed for connection to the internet;</text></clause><clause id="HD401A2ED50254C6A9CAA7935629FFDA4"><enum>(v)</enum><text>mainframe computing system; or</text></clause><clause id="HDAD47C9FDE70469DA816A1CBCA116CF7"><enum>(vi)</enum><text>subcomponent of a device.</text></clause></subparagraph></paragraph><paragraph id="HC1E2BC6A3FAE4BC2A78D79AF4C7CD7AB"><enum>(3)</enum><header>Director of OMB</header><text>The term <term>Director of OMB</term> means the Director of the Office of Management and Budget.</text></paragraph><paragraph id="H8A0BE3D7722D40C0A0DD5A397A3C821A"><enum>(4)</enum><header>Director of the Institute</header><text>The term <term>Director of the Institute</term> means the Director of the National Institute of Standards and Technology. </text></paragraph><paragraph id="H953C61093B5D4898B3EBA4E05B9EF7DB"><enum>(5)</enum><header>Security vulnerability</header><text>The term <term>security vulnerability</term> has the meaning given that term under section 102(17) of the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501(17)</external-xref>). </text></paragraph></section><section id="H9D51468C2AE34C29BF77A451B41459EB"><enum>3.</enum><header>Completion of ongoing efforts relating to considerations for managing Internet of things cybersecurity risks</header><text display-inline="no-display-inline">Not later than December 31, 2019, the Director of the National Institute of Standards and Technology shall complete the efforts of the Institute in effect on the date of the enactment of this Act regarding considerations for managing the security vulnerabilities of Internet of Things devices and examples of possible cybersecurity capabilities of such devices by publishing a report that includes, at a minimum, the following considerations for covered devices: </text><paragraph id="HE3F175936AC14EC99C83942675B4C4EA"><enum>(1)</enum><text display-inline="yes-display-inline">Secure development.</text></paragraph><paragraph id="H034EE464D5E946C7814E10D0C1478D5C"><enum>(2)</enum><text>Identity management.</text></paragraph><paragraph id="HDEAF6AEA46F543ABA1DBC4D47F9FC4F1"><enum>(3)</enum><text>Patching.</text></paragraph><paragraph id="HCBB515E7100D4487A22CD2741593DAA1"><enum>(4)</enum><text>Configuration management.</text></paragraph></section><section id="HCC8F04E728774EDBAC39DBA1F11172F4"><enum>4.</enum><header>Security standards for use of covered devices by the Federal Government</header><subsection id="HC642EA8D46024861BAD11FEE06C12AFE"><enum>(a)</enum><header>Guidelines required</header><paragraph id="H8D1B2B17DD084C8FBA19EB639B5354DA" commented="no"><enum>(1)</enum><header>Guidelines</header><text display-inline="yes-display-inline">Not later than 6 months after the date on which the report under section 3 is completed, the Director of the Institute shall develop under section 20 of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3">15 U.S.C. 278g-3</external-xref>), and submit to the Director of OMB, guidelines on—</text><subparagraph id="HFFFF4674B19447DFBD8490710227318E" commented="no"><enum>(A)</enum><text>the appropriate use and management by the agencies of covered devices owned or controlled by the agencies; and</text></subparagraph><subparagraph id="HD69D2BC19236417098EDBBCB98A1AABC" commented="no"><enum>(B)</enum><text>minimum information security requirements for managing security vulnerabilities associated with such devices. </text></subparagraph></paragraph><paragraph id="HB7C53819B8134F89B239DB97A060930D"><enum>(2)</enum><header>Development of guidelines</header><text display-inline="yes-display-inline">In developing the guidelines submitted under paragraph (1), the Director of the Institute shall—</text><subparagraph id="HC172E2C6B6A8460EA0582F0567F2814D"><enum>(A)</enum><text>consider relevant standards and best practices developed by the private sector, agencies, and public-private partnerships; and</text></subparagraph><subparagraph id="HC745744071434026AD937E6120640CC8"><enum>(B)</enum><text>ensure that such guidelines are consistent with the considerations published in the report described under section 3. </text></subparagraph></paragraph></subsection><subsection id="HF4B5659D5EA24CB1B19A364BD4BCAE51"><enum>(b)</enum><header>Promulgation of standards</header><paragraph id="H9210757E61454136BC6445F428347321" commented="no"><enum>(1)</enum><header>Standards</header><text display-inline="yes-display-inline">Not later than 180 days after the date on which the Director of the Institute completes the development of the guidelines required under subsection (a), the Director of OMB, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall—</text><subparagraph id="HE9CB4609013A4CF8B21AD07085A87CE3" commented="no"><enum>(A)</enum><text>promulgate standards on the basis of the guidelines submitted under subsection (a) pertaining to covered devices owned or controlled by agencies, except those considered national security systems as defined by section 3552(b)(6) of title 44, United States Code; and</text></subparagraph><subparagraph id="HCCDBD089B92C4E3C87F6B328291EBB7D" commented="no"><enum>(B)</enum><text>ensure such standards are consistent with the information security requirements under subchapter II of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code.</text></subparagraph></paragraph><paragraph id="H01CC1EE15AD846E08D6A8BC3612183C8"><enum>(2)</enum><header>Quinquennial review and revision</header><text display-inline="yes-display-inline">Not later than 5 years after the date on which the Director of OMB promulgates the standards under paragraph (1), and not less frequently than once every 5 years thereafter, the Director of OMB, in consultation with and the Director of the Institute and the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall—</text><subparagraph id="HCD0BE45EA23E43A8BDA852E3C763A254"><enum>(A)</enum><text>review such standards; and</text></subparagraph><subparagraph id="H3EA2182992DA42868C34645D4D3E4FC2"><enum>(B)</enum><text>revise such standards as appropriate.</text></subparagraph></paragraph></subsection><subsection id="HC3B01A0372EA4087A3C4C00AD32F2F90"><enum>(c)</enum><header>Revision of Federal Acquisition Regulation</header><text display-inline="yes-display-inline">The Federal Acquisition Regulation shall be revised to implement any standard promulgated under subsection (b). </text></subsection></section><section id="HBF7FDE97F74F4B4BA0CCAF3D18F761B4"><enum>5.</enum><header>Petition to exclude certain devices</header><subsection id="HA74453025ED743C8B38480081D9D6656"><enum>(a)</enum><header>Petition</header><text>The Director of OMB shall establish a process by which an interested party may petition the Director of OMB for a device described in section 2(2) to not be considered a covered device for the purpose of standards promulgated under section 4(b).</text></subsection><subsection id="H634313FE197D43C296D36E55EAFDE1DD" commented="no"><enum>(b)</enum><header>Grants of petition</header><text display-inline="yes-display-inline">The Director of OMB shall grant a petition under subsection (a)—</text><paragraph id="HD0167E407C5E4DC9B58F40B41B3887CE"><enum>(1)</enum><text>on a limited basis;</text></paragraph><paragraph id="HF4238C19F58846159961496BDD847692" commented="no"><enum>(2)</enum><text>in a timely manner; and</text></paragraph><paragraph id="H1D56B1DF9C60423DBA37921AF91425BE" commented="no"><enum>(3)</enum><text>only if the interested party demonstrates that— </text><subparagraph id="H541CCAC85B0D40759EBAF37EA5F1B2D7" commented="no"><enum>(A)</enum><text>the procurement of such a covered device with limited data processing and software functionality would be unfeasible; or</text></subparagraph><subparagraph id="HE4A39A92A8584EBE9A635DC0081705BA" commented="no"><enum>(B)</enum><text>the procurement of a covered device that does not meet the standards promulgated by the Director of OMB under this Act is necessary for national security or for research purposes.</text></subparagraph></paragraph></subsection><subsection id="H5264DF9661B74B4CBF2730C2FA999AB0"><enum>(c)</enum><header>Report</header><paragraph id="H49487A29ECA24678B98B23D61B72F133"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than one year after the date of the enactment of this Act, and annually thereafter for each of the following four years, the Director of OMB shall submit to the appropriate congressional committees a report on the process established by the Director of OMB for granting or denying waivers under this section.</text></paragraph><paragraph id="H2B8EF4CBA1AC4AA8B83F794CB24C16CC"><enum>(2)</enum><header>Assessment of implementation</header><text display-inline="yes-display-inline">The reports required under paragraph (1) shall include, at a minimum, the following:</text><subparagraph id="HE1FB96CFD42449FB89DE4035287A4A52"><enum>(A)</enum><text>An assessment of the waiver evaluation process.</text></subparagraph><subparagraph id="H25D0E70CA2C5401A9A75599DEAA8862D"><enum>(B)</enum><text>A description of the methods established to carry out such assessment.</text></subparagraph><subparagraph id="HC2E9D97134474FFBAD9D567E1A8A9E80"><enum>(C)</enum><text>A classified appendix listing the types and number of devices for each agency granted a waiver and the reasons for such waiver.</text></subparagraph></paragraph><paragraph id="HE0B014BDBC7F4E6692F5BF294151715B"><enum>(3)</enum><header>Appropriate congressional committees defined</header><text display-inline="yes-display-inline">In this subsection, the term <term>appropriate congressional committees</term> means the Committees on Oversight and Reform and Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate. </text></paragraph></subsection></section><section id="H7F20963F14474363B10766D06C633B1E"><enum>6.</enum><header>Coordinated disclosure of security vulnerabilities relating to covered devices</header><subsection id="HA4AE51D9F87844A0AFB46D4B4A46F9B1"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 180 days after the date of the enactment of this Act, the Director of the Institute, in consultation with the Director of Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall develop under section 20 of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3">15 U.S.C. 278g-3</external-xref>) and submit to the Director of OMB, guidelines—</text><paragraph id="H369B2ABC52F445C7AC2D3149D4948ACC"><enum>(1)</enum><text>for the reporting, coordinating, publishing, and receiving of information about—</text><subparagraph id="H68A5CE0478DC4036948E8E50317F8D7E"><enum>(A)</enum><text>a security vulnerability relating to a covered device owned or controlled by an agency; and</text></subparagraph><subparagraph id="H1F9C91A913244D719BA82C886F596CD1"><enum>(B)</enum><text>the resolution of such security vulnerability; </text></subparagraph></paragraph><paragraph id="H2ECF8BCD5F1F4FCCBA49E78E63FCF25E"><enum>(2)</enum><text>for contractors providing a covered device to the Federal Government, and any subcontractor thereof at any tier providing such device to such contractors on—</text><subparagraph id="H75FDE6E30DCB44A1B1C796C8C4E42D40"><enum>(A)</enum><text>receiving information about a potential security vulnerability relating to the covered device; and</text></subparagraph><subparagraph id="H924A1B5FB8C74A8885B469A7A202ABB5"><enum>(B)</enum><text>disseminating information about the resolution of a security vulnerability relating to the covered device; and </text></subparagraph></paragraph><paragraph id="HB7C8B91916F14E59A2A848FCAA65033C"><enum>(3)</enum><text display-inline="yes-display-inline">on the type of information about security vulnerabilities that should be reported to the Federal Government, including examples thereof.</text></paragraph></subsection><subsection id="HED227671F98F4AEFB12690D433F023A3"><enum>(b)</enum><header>Development of guidelines</header><text display-inline="yes-display-inline">In developing the guidelines under subsection (a), the Director of the Institute shall—</text><paragraph id="HA4C9716A7BC54BB5A23622840B1DF0D2"><enum>(1)</enum><text>consult with such cybersecurity researchers and private sector industry experts as the Director considers appropriate; </text></paragraph><paragraph id="H31CEDF06805D47E58B76E4D1CE2321D8"><enum>(2)</enum><text>to the maximum extent practicable, align such guidelines with Standards 29147 and 30111 of the International Standards Organization, or any successor standards thereof; and </text></paragraph><paragraph id="H2EEF7F3C42B749F09FBB8859E68FFEE6"><enum>(3)</enum><text display-inline="yes-display-inline">ensure such guidelines are consistent with the policies and procedures developed under section 2209(m) of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659(m)</external-xref>). </text></paragraph></subsection><subsection id="H1AAE9C521CB84C31BA10633426416A5C"><enum>(c)</enum><header>Promulgation of standards</header><paragraph id="HF2C69780A443471695B6AFA61BA4350B"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 180 days after the date on which the guidelines under subsection (a) are submitted, the Director of OMB, in consultation with the Administrator of General Services and the Secretary of Homeland Security, shall promulgate standards on the basis of such guidelines.</text></paragraph><paragraph id="HE778C4253895476488855F08771E26BD" commented="no"><enum>(2)</enum><header>Contract requirement for subcontracts</header><text display-inline="yes-display-inline">The standards promulgated under paragraph (1) shall include a requirement for any contract related to a covered device to include a clause that requires each contractor that provides a covered device under the contract to an agency to ensure that any covered device obtained through a subcontract, at any tier, complies with the standards and regulations promulgated under this section with respect to such covered device.</text></paragraph><paragraph id="H0D42825F7AF2407A8D6B2F6837086992"><enum>(3)</enum><header>Consistency with the Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure Technology Act</header><text display-inline="yes-display-inline">The Director of OMB shall ensure that the standards promulgated under paragraph (1) are consistent with section 101 of the Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/6/663">6 U.S.C. 663</external-xref> note; <external-xref legal-doc="public-law" parsable-cite="pl/115/390">Public Law 115–390</external-xref>).</text></paragraph></subsection><subsection id="H0CB4B3357D5C4A49A47B325A3A783C6C" commented="no"><enum>(d)</enum><header>Revision of Federal Acquisition Regulation</header><text>The Federal Acquisition Regulation shall be revised to implement the standards promulgated under subsection (c). </text></subsection></section><section id="H2C1B925BAE924EE297C58DA77BA17315" commented="no"><enum>7.</enum><header>Contractor compliance with standards and regulations</header><subsection id="H2C1FC49449E34172B9F779627D2E96E3" commented="no"><enum>(a)</enum><header>In general</header><paragraph id="H25BD951D10554B44B0BA611638930CC5" commented="no"><enum>(1)</enum><header>Determination</header><subparagraph id="H3938AD23A7DF4D5BB13551B901AE389A"><enum>(A)</enum><header>Compliance required</header><text display-inline="yes-display-inline">Before awarding a contract to an offeror for the procurement of a covered device, or renewing a contract to procure or obtain a covered device from a contractor, the agency Chief Information Officer shall determine if such offeror or contractor has complied with each standard promulgated under section 6(c) with respect to such covered device.</text></subparagraph><subparagraph id="H04FC7455D11040678B292A393E0B1F3C"><enum>(B)</enum><header>Simplified acquisition threshold</header><text display-inline="yes-display-inline">Notwithstanding section 1905 of title 41, United States Code, the requirements under subparagraph (A) shall apply to a contract or subcontract in amounts not greater than the simplified acquisition threshold.</text></subparagraph></paragraph><paragraph id="HDBABDD74D1C045E4A1B86C79917E2F95" commented="no"><enum>(2)</enum><header>Prohibition on use or procurement</header><text>The head of an agency may not procure or obtain, or renew a contract to procure or obtain, a covered device if the agency Chief Information Officer determines under paragraph (1)(A) that such offeror or contractor has not complied with a standard promulgated under section 6(c) with respect to such covered device. </text></paragraph></subsection><subsection id="HB09CF75916F14EAD88F8C59724150A93" commented="no"><enum>(b)</enum><header>Waiver</header><text display-inline="yes-display-inline">The head of an agency may waive the prohibition under subsection (a)(2) if the procurement of such covered device is necessary for national security or for research purposes.</text></subsection><subsection id="H30F15745357C46C4AA2F2770A69F21B5" commented="no"><enum>(c)</enum><header>Effective date</header><text display-inline="yes-display-inline">The prohibition under subsection (a) shall take effect one year after the date of the enactment of this Act. </text></subsection></section><section id="HC04E88F977A1446B9B4764DDC1482B0F"><enum>8.</enum><header>Institute report on cybersecurity considerations stemming from the convergence of information technology, internet of things, and operational technology devices, networks and systems</header><text display-inline="no-display-inline">Not later than 1 year after the date of the enactment of this Act, the Director of the Institute shall publish a report on the increasing convergence, including considerations for managing potential security vulnerabilities associated with such convergence, of traditional information technology devices, networks, and systems with—</text><paragraph id="H312DE1865AE840CD9541EF707EDEE80E"><enum>(1)</enum><text>covered devices, networks and systems; and</text></paragraph><paragraph id="H2DC4E34961B04885B70008CE306C126B"><enum>(2)</enum><text>operational technology devices, networks and systems.</text></paragraph></section></legis-body><endorsement display="yes"><action-date>September 14, 2020</action-date><action-desc>Reported from the <committee-name added-display-style="italic" committee-id="HGO00" deleted-display-style="strikethrough">Committee on Oversight and Reform</committee-name> with an amendment</action-desc><action-date>September 14, 2020</action-date><action-desc>Committee on <committee-name committee-id="HSY00">Science, Space, and Technology</committee-name> discharged; committed to the Committee of the Whole House on the State of the Union and ordered to be printed</action-desc></endorsement></bill> 

