[Congressional Record Volume 164, Number 126 (Thursday, July 26, 2018)]
[Senate]
[Page S5431]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 3624. Mr. CRUZ submitted an amendment intended to be proposed to 
amendment SA 3399 proposed by Mr. Shelby to the bill H.R. 6147, making 
appropriations for the Department of the Interior, environment, and 
related agencies for the fiscal year ending September 30, 2019, and for 
other purposes; which was ordered to lie on the table; as follows:

       At the appropriate place, insert the following:
       Sec. __. (a) None of the funds appropriated or otherwise 
     made available under this Act may be obligated or expended by 
     the Department of the Interior, the Environmental Protection 
     Agency, the Forest Service, the Indian Health Service, the 
     Smithsonian Institution, or any Federal agency for which 
     amounts are appropriated by division B or D of this Act, to 
     acquire telecommunications or video surveillance equipment 
     produced by Huawei Technologies Company, ZTE Corporation, 
     Hytera Communications Corporation, Ltd., Hangzhou Hikvision 
     Digital Technology Company, Ltd., or Dahua Technology 
     Company, Ltd. (or any subsidiary or affiliate of any of such 
     entities), or a high-impact or moderate-impact information 
     system, as defined for security categorization in the 
     National Institute of Standards and Technology's (NIST) 
     Federal Information Processing Standard Publication 199, 
     ``Standards for Security Categorization of Federal 
     Information and Information Systems'', unless the agency 
     has--
       (1) reviewed the supply chain risk for the information 
     systems against criteria developed by NIST to inform 
     acquisition decisions for high-impact and moderate-impact 
     information systems within the Federal Government;
       (2) reviewed the supply chain risk from the presumptive 
     awardee against available and relevant threat information 
     provided by the Federal Bureau of Investigation and other 
     appropriate agencies; and
       (3) in consultation with the Federal Bureau of 
     Investigation or other appropriate Federal entity, conducted 
     an assessment of any risk of cyber-espionage or sabotage 
     associated with the acquisition of such system, including any 
     risk associated with such system being produced, 
     manufactured, or assembled by one or more entities identified 
     by the United States Government as posing a cyber threat, 
     including but not limited to, those that may be owned, 
     directed, or subsidized by the People's Republic of China, 
     the Islamic Republic of Iran, the Democratic People's 
     Republic of Korea, or the Russian Federation.
       (b) Section 432(a) of division A of this Act, section 
     632(a) of division B of this Act, and section 420(a) of 
     division D of this Act shall have no force or effect.
                                 ______