<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE amendment-doc PUBLIC "-//US Congress//DTDs/amend.dtd//EN" "amend.dtd">
<amendment-doc amend-type="engrossed-amendment" amend-degree="first"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 3462 EAS: SBA Cyber Awareness Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2022-09-28</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<engrossed-amendment-form>
<congress display="no">117th CONGRESS</congress><session display="no">2d Session</session><legis-num display="no">H.R. 3462</legis-num><current-chamber display="yes">In the Senate of the United States,</current-chamber><action><action-date date="20220928">September 28, 2022.</action-date></action><legis-type display="yes">Amendment:</legis-type></engrossed-amendment-form><engrossed-amendment-body><section id="idf74b61a197314f568bdce18f6a0064cc" section-type="resolved"><text>That the bill from the House of Representatives (H.R. 3462) entitled <quote>An Act to require an annual report on the cybersecurity of the Small Business Administration, and for other purposes.</quote>, do pass with the following</text></section><amendment><amendment-instruction blank-lines-after="0"><text>Strike out all after the enacting clause and insert:</text></amendment-instruction><amendment-block blank-lines-after="1" changed="added" reported-display-style="italic"><section id="H9900F8D8B5FE4B30A13BD4A1E534BF35" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>SBA Cyber Awareness Act</short-title></quote>.</text></section><section id="H08197DDA09A04050B276377BFF72F365"><enum>2.</enum><header>Cybersecurity awareness reporting</header><subsection id="idA550D37BD4964467A648110C477C42A6"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Section 10 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/639">15 U.S.C. 639</external-xref>) is amended by inserting after subsection (a) the following:</text><quoted-block id="H4BE68B161E8E46C6B25CBC3651FCA2FE" display-inline="no-display-inline" style="OLC"><subsection id="HF0A4E430D68C4796BE4BBED8969D4D08"><enum>(b)</enum><header>Cybersecurity reports</header><paragraph id="HBB951CCCDC4348728980B5663E0F4138"><enum>(1)</enum><header>Annual report</header><text>Not later than 180 days after the date of enactment of this subsection, and every year thereafter, the Administrator shall submit a report to the appropriate congressional committees that includes—</text><subparagraph id="HC39A09005F224AF9BE5A75139705A039"><enum>(A)</enum><text display-inline="yes-display-inline">a strategy to increase the cybersecurity of information technology infrastructure of the Administration;</text></subparagraph><subparagraph id="id6691b247401a4467a99e16f245722e49"><enum>(B)</enum><text>a supply chain risk management strategy and an implementation plan to address the risks of foreign manufactured information technology equipment utilized by the Administration, including specific risk mitigation activities for components originating from entities with principal places of business located in the People’s Republic of China; and</text></subparagraph><subparagraph id="HFC86B65A35944369B97002F3EA2DDC75"><enum>(C)</enum><text display-inline="yes-display-inline">an account of—</text><clause id="idDDC3EB79DABA4FCB97B70C311C4971C0"><enum>(i)</enum><text display-inline="yes-display-inline">any incident that occurred at the Administration during the 2-year period preceding the date on which the first report is submitted, and, for subsequent reports, the 1-year period preceding the date of submission; and</text></clause><clause id="id1DC7698B69DC4960852F26B01C08D06B"><enum>(ii)</enum><text display-inline="yes-display-inline">any action taken by the Administrator to respond to or remediate any such incident.</text></clause></subparagraph></paragraph><paragraph id="id128942E98A15469DAED73B8B98041620"><enum>(2)</enum><header>FISMA reports</header><text>Each report required under paragraph (1) may be submitted as part of the report required under section 3554 of title 44, United States Code.</text></paragraph><paragraph id="H2C09409E62EC490997528430C5AAE391"><enum>(3)</enum><header>Rule of construction</header><text>Nothing in this subsection shall be construed to affect the reporting requirements of the Administrator under <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, in particular the requirement to notify the Federal information security incident center under section 3554(b)(7)(C)(ii) of such title, any guidance issued by the Office of Management and Budget, or any other provision of law or Federal policy.</text></paragraph><paragraph id="H20A8C0DB37144772A86296A06F5F6C2C"><enum>(4)</enum><header>Definitions</header><text>In this subsection:</text><subparagraph id="H965ED790A5854C1AA639F31FD0372A64"><enum>(A)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means—</text><clause id="HEE60528888B54831B64EC916E7C0441E"><enum>(i)</enum><text>the Committee on Small Business and Entrepreneurship of the Senate;</text></clause><clause id="id2D50A5258D794C27B95722664737DF86"><enum>(ii)</enum><text>the Committee on Homeland Security and Governmental Affairs of the Senate;</text></clause><clause id="H8A8DE95275604607B910E51CFD522B78"><enum>(iii)</enum><text>the Committee on Small Business of the House of Representatives; and</text></clause><clause id="idA7761E28BEA34EFAB18B6014A2CE59C3"><enum>(iv)</enum><text>the Committee on Oversight and Reform of the House of Representatives.</text></clause></subparagraph><subparagraph id="HCBCFB34FF4DB45CFBC920B539F095B93" commented="no" display-inline="no-display-inline"><enum>(B)</enum><header>Incident</header><text display-inline="yes-display-inline">The term <term>incident</term> has the meaning given the term in section 3552 of title 44, United States Code.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idA5B2608C63BA47EB8A76FEEFAB33B76C"><enum>(C)</enum><header>Information technology</header><text display-inline="yes-display-inline">The term <term>information technology</term> has the meaning given the term in section 3502 of title 44, United States Code.</text></subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="id4c5d49e9ab0148d0a88894311ce96d8d"><enum>(b)</enum><header>Report</header><text>Not later than 1 year after the date of enactment of this Act, the Administrator of the Small Business Administration shall, to the greatest extent practicable, provide to the Committee on Small Business and Entrepreneurship of the Senate, the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Small Business of the House of Representatives, and the Committee on Oversight and Reform of the House of Representatives a detailed account of information technology (as defined in section 3502 of title 44, United States Code) of the Small Business Administration that was manufactured by an entity that has its principal place of business located in the People’s Republic of China.</text></subsection></section></amendment-block></amendment></engrossed-amendment-body><attestation><attestation-group><attestor></attestor><role>Secretary</role></attestation-group></attestation><endorsement></endorsement></amendment-doc> 

