<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H61A03DD3DA8344CFBF8FE9B871665A0C" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 6106 IH: Bolstering America’s Defenses Against Potentially Perilous Software Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2023-10-26</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">118th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 6106</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20231026">October 26, 2023</action-date><action-desc><sponsor name-id="S001207">Ms. Sherrill</sponsor> (for herself, <cosponsor name-id="B001301">Mr. Bergman</cosponsor>, <cosponsor name-id="K000391">Mr. Krishnamoorthi</cosponsor>, <cosponsor name-id="H001091">Mrs. Hinson</cosponsor>, <cosponsor name-id="N000189">Mr. Newhouse</cosponsor>, <cosponsor name-id="G000559">Mr. Garamendi</cosponsor>, <cosponsor name-id="C001121">Mr. Crow</cosponsor>, <cosponsor name-id="F000475">Mr. Finstad</cosponsor>, <cosponsor name-id="C001072">Mr. Carson</cosponsor>, and <cosponsor name-id="T000487">Ms. Tokuda</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HAS00">Committee on Armed Services</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To create a risk framework to evaluate foreign mobile applications of concern, and for other purposes.</official-title></form><legis-body id="H76F9D00CA1A74677864BB4C97256FD5D" style="OLC"> 
<section id="H671BBEA8F67D4606A83E168B4A80DEC9" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Bolstering America’s Defenses Against Potentially Perilous Software Act</short-title></quote> or the <quote><short-title>BAD APPS Act</short-title></quote>.</text></section> <section id="H3724E7E87D2D4348A4B08664945CD273" section-type="subsequent-section"><enum>2.</enum><header>Risk framework for foreign mobile applications of concern</header> <subsection id="H4E0FC5A0656A43D9901E3E2F0B0074D7"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">The Secretary of Defense shall—</text> 
<paragraph id="HE53AF7ABAF2945DE8DBB057EB438E2A7"><enum>(1)</enum><text display-inline="yes-display-inline">create categorical definitions of foreign mobile applications of concern with respect to personnel or operations of the Department of Defense, distinguishing among categories such as applications for shopping, social media, entertainment, or health; and</text></paragraph> <paragraph id="H355603AC7B1A482B8F961FF076968EA4"><enum>(2)</enum><text display-inline="yes-display-inline">create a risk framework with respect to Department personnel or operations that assesses each foreign mobile application (or, if appropriate, grouping of similar such applications) that is from a country of concern for any potential impact on Departmental personnel and Departmental operations, incorporating considerations of—</text> 
<subparagraph id="HE9DD9824925E49FCA176E3EFD9D2DC32"><enum>(A)</enum><text>the manner and extent of data collection by the application;</text></subparagraph> <subparagraph id="HE31577878CEE435AA8DDCA2A65ECC888"><enum>(B)</enum><text display-inline="yes-display-inline">the ability of the application to influence the user with the applications content to the detriment of the United States;</text></subparagraph> 
<subparagraph id="H9876894A092846D6BB6DC16E976E6BA1"><enum>(C)</enum><text>the manner and extent of foreign ownership or control of the application or data collected by the application;</text></subparagraph> <subparagraph id="H35A4CC3F1F8540FEAFB3C4EA6EDD0975"><enum>(D)</enum><text>any foreign government interests associated with the applications;</text></subparagraph> 
<subparagraph id="HADB2A60BB8AA4A458876520B99069841"><enum>(E)</enum><text>a software bill of materials with a focus on known or assessed malicious software embedded in the application, including in prior versions of the application or in other applications created by the owners of such application;</text></subparagraph> <subparagraph id="H963E9F6A88C743A19C296A983817279A"><enum>(F)</enum><text display-inline="yes-display-inline">any known impact from prior use of the application to Department personnel or operations; and</text></subparagraph> 
<subparagraph id="H7CB925210D8745869872C73E4B5B975B" commented="no"><enum>(G)</enum><text display-inline="yes-display-inline">the foreign mobile application of concern residing on a United States Government device or a personally owned device while in proximity to Department operations or activities or in the personal custody of personnel during Department sanctioned activities.</text></subparagraph></paragraph></subsection> <subsection id="HB9569E0970234D279B881AE5C29EC653"><enum>(b)</enum><header>Considerations</header><text>In developing the categorical definitions and risk framework described in subsection (a), the Secretary of Defense—</text> 
<paragraph id="H054654A01E024A61B7A583E07B40E9FF"><enum>(1)</enum><text display-inline="yes-display-inline">shall include in the risk framework foreign mobile applications of concern—</text> <subparagraph id="HA7A706AB913747678FCDF2BF32DFEA4D"><enum>(A)</enum><text display-inline="yes-display-inline">from countries that the Secretary determines to be engaged in consistent, unauthorized conduct that is detrimental to the national security or foreign policy of the United States;</text></subparagraph> 
<subparagraph id="HDF024DCDED9744ABAA29C681AEC3B378"><enum>(B)</enum><text display-inline="yes-display-inline">that are accessible to be downloaded from major mobile device application marketplaces by Department personnel; and</text></subparagraph> <subparagraph id="HD3041BF92BF24972BE0D7005EAFD4A30"><enum>(C)</enum><text display-inline="yes-display-inline">originating from, authored in, owned by, or otherwise associated with countries or entities that are designated on the list maintained and set forth in Supplement No. 4 to part 744 of the Export Administration Regulations;</text></subparagraph></paragraph> 
<paragraph id="HA51AA8AA5CF44CEDB0636A7860CA0240"><enum>(2)</enum><text display-inline="yes-display-inline">may include additional countries or individual foreign mobile applications with malicious and banned capabilities from other countries to the extent the Secretary determines appropriate; and</text></paragraph> <paragraph id="HDAEE22F92CE44CAFB22B22C46734A668" commented="no"><enum>(3)</enum><text display-inline="yes-display-inline">shall consider distinguishing within the risk framework the particular interests of a country described in paragraph (1) or (2) in the use of a foreign mobile application of concern of such country (regardless of device or owner) by—</text> 
<subparagraph id="H332F35BED817489FB96416E0333F8A66" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">users located at facilities of the Department of Defense of varying levels of sensitivity;</text></subparagraph> <subparagraph id="H2352E7E920B641E4A059359572B0D9E6" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">users conducting authorized operations or movements of Department of Defense materiel; or</text></subparagraph> 
<subparagraph id="H32E6616D7826430FBD89DB1F91506B90" commented="no"><enum>(C)</enum><text display-inline="yes-display-inline">specific civilian employees of the Department or contractors whom the Secretary determines likely to be a target of a foreign actor.</text></subparagraph></paragraph></subsection> <subsection id="H73CDCBC8270C41F0B9A58C389B97FB2C"><enum>(c)</enum><header>Guidance and updates</header><text>The Secretary of Defense shall—</text> 
<paragraph id="H8B3994338FFA4B8EA2CD9B5BDD2CFF2C"><enum>(1)</enum><text>issue guidance to all Department personnel incorporating the categories of foreign mobile applications of concern and advising how to mitigate the risks identified by the risk framework with respect to such applications;</text></paragraph> <paragraph id="H06F64E0B98944E7E9161FB665DFEDA4E"><enum>(2)</enum><text>routinely update the categorical definitions and risk framework promulgated pursuant to subsection (a), at least on an annual basis; and</text></paragraph> 
<paragraph id="H8EAE132131F54133AA573C8A55723100" commented="no"><enum>(3)</enum><text display-inline="yes-display-inline">prescribe, if feasible, regulations that appropriately mitigate risks from applications on devices provided by the Department of Defense or on any device used during an activity described in subsection (b)(3)(B) or at locations described under (b)(3)(A).</text></paragraph></subsection></section> </legis-body></bill>

