<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-MIR21770-0W1-RL-RRL"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S1691 IS: SBA Cyber Awareness Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-05-18</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 1691</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210518">May 18, 2021</action-date><action-desc><sponsor name-id="S350">Mr. Rubio</sponsor> (for himself, <cosponsor name-id="S323">Mr. Risch</cosponsor>, and <cosponsor name-id="S373">Mr. Cassidy</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSSB00">Committee on Small Business and Entrepreneurship</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require an annual report on the cybersecurity of the Small Business Administration, and for other purposes.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>SBA Cyber Awareness Act</short-title></quote>.</text></section><section id="idF768A7B1EF5C4C96913E977BFDEB6C97"><enum>2.</enum><header>Cybersecurity awareness reporting</header><text display-inline="no-display-inline">Section 10 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/639">15 U.S.C. 639</external-xref>) is amended by striking subsection (b) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id2EC2369D86764F8E8DE32E587A116FC8"><subsection id="id6AB5FA1606B54136911BCA213C430982"><enum>(b)</enum><header>Cybersecurity reports</header><paragraph id="id1570F55E66D94908B2EABC970FD2798D"><enum>(1)</enum><header>Definition</header><text>In this subsection, the term <term>appropriate congressional committees</term> means—</text><subparagraph id="idDDAA1406C4464BC485DB27BA5FBB39CA"><enum>(A)</enum><text>the Committee on Small Business and Entrepreneurship of the Senate; and</text></subparagraph><subparagraph id="id59879B8E8B2F469A83D84CD9EC7E9138"><enum>(B)</enum><text>the Committee on Small Business of the House of Representatives.</text></subparagraph></paragraph><paragraph id="idB1470BAFBA27466F9E1B5672FA12AEFC"><enum>(2)</enum><header>Annual report</header><text>Not later than 180 days after the date of enactment of the <short-title>SBA Cyber Awareness Act</short-title>, and every year thereafter, the Administration shall submit a report to the appropriate congressional committees that includes—</text><subparagraph id="id62A125E1AC2E46A0800C6C4F11207497"><enum>(A)</enum><text>an assessment of the information technology and cybersecurity of the Administration;</text></subparagraph><subparagraph id="id3A031429D6D54D27901CD68E27800430"><enum>(B)</enum><text>a strategy to increase the cybersecurity of the Administration;</text></subparagraph><subparagraph id="idB19956FA8C494C7A93076172E055563B"><enum>(C)</enum><text>a detailed account of any information technology component or system of the Administration that was manufactured by a company located in the People's Republic of China; and</text></subparagraph><subparagraph id="id77DB2FBD9DDF49F5BC6B3ACE8543507E"><enum>(D)</enum><text>an account of any cyber threat, breach, or cyber attack that occurred at the Administration during the 2-year period preceding the date on which the report is submitted, and any action taken by the Administration to respond to or remediate the cyber threat, breach, or cyber attack.</text></subparagraph></paragraph><paragraph id="id0397D6219A61455E857347575676FF0D"><enum>(3)</enum><header>Additional reports</header><text>If the Administration determines that there is a reasonable basis to conclude that a cyber threat, breach, or cyber attack occurred at the Administration, the Administration shall—</text><subparagraph id="idB9390B27C46A4C75B911D6C6B44219A5"><enum>(A)</enum><text>not later than 7 days after the date on which the Administration makes that determination, notify the appropriate congressional committees of the cyber threat, breach, or cyber attack; and</text></subparagraph><subparagraph id="id48D8A49153324800AE4A6BED1EA2EB59"><enum>(B)</enum><text>not later than 30 days after the date on which the Administration makes that determination, submit to the appropriate congressional committees a report that includes—</text><clause id="id6fc17b8380b94efe98d062b353e473be"><enum>(i)</enum><text>a summary of information about the cyber threat, breach, or cyber attack, including how the cyber threat, breach, or cyber attack occurred, based on information available to the Administration as of the date which the Administration submits the report;</text></clause><clause id="id338b75f21b18430b980bd20f1d65ded4"><enum>(ii)</enum><text>an estimate of the number of individuals and small entities affected by the cyber threat, breach, or cyber attack, including an assessment of the risk of harm to affected individuals and small entities based on information available to the Administration as of the date on which the Administration submits the report; and</text></clause><clause id="ide8415f021d6a4dfab1b6efaa0ab9c3a3"><enum>(iii)</enum><text>an estimate of when the Administration will provide notice to affected individuals and small entities.</text></clause></subparagraph></paragraph><paragraph id="idD782FD221A5041D892CB0F0E0D487836"><enum>(4)</enum><header>Rule of construction</header><text>Nothing in this subsection shall be construed to affect the reporting requirements of the Administration under <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44 United States Code, in particular the requirement to notify the Federal information security incident center under section 3554(b)(7)(C)(ii) of such title, or any other provision of law.</text></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></section></legis-body></bill>


