[Congressional Record Volume 164, Number 139 (Tuesday, August 21, 2018)]
[Senate]
[Page S5776]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 3854. Mr. RUBIO submitted an amendment intended to be proposed to 
amendment SA 3695 proposed by Mr. Shelby to the bill H.R. 6157, making 
appropriations for the Department of Defense for the fiscal year ending 
September 30, 2019, and for other purposes; which was ordered to lie on 
the table; as follows:

       At the appropriate place in division A, insert the 
     following:
       Sec. ____. (a) None of the funds appropriated or otherwise 
     made available in this Act may be used by a Federal agency 
     for which amounts are appropriated in this Act to acquire 
     telecommunications equipment produced by Huawei Technologies 
     Company or ZTE Corporation or a high-impact or moderate-
     impact information system, as defined for security 
     categorization in the National Institute of Standards and 
     Technology's (in this section referred to as ``NIST'') 
     Federal Information Processing Standard Publication 199, 
     ``Standards for Security Categorization of Federal 
     Information and Information Systems'', unless the agency 
     has--
       (1) reviewed the supply chain risk for the information 
     systems against criteria developed by NIST to inform 
     acquisition decisions for high-impact and moderate-impact 
     information systems within the Federal Government;
       (2) reviewed the supply chain risk from the presumptive 
     awardee against available and relevant threat information 
     provided by the Federal Bureau of Investigation and other 
     appropriate Federal agencies; and
       (3) in consultation with the Federal Bureau of 
     Investigation or other appropriate Federal agency, conducted 
     an assessment of any risk of cyber espionage or sabotage 
     associated with the acquisition of such system, including any 
     risk associated with such system being produced, 
     manufactured, or assembled by one or more entities identified 
     by the United States Government as posing a cyber threat, 
     including those that may be owned, directed, or subsidized by 
     the People's Republic of China, the Islamic Republic of Iran, 
     the Democratic People's Republic of Korea, or the Russian 
     Federation.
       (b)(1) None of the funds appropriated or otherwise made 
     available in this Act may be used to acquire a high-impact or 
     moderate-impact information system reviewed and assessed 
     under subsection (a) unless the head of the assessing entity 
     described in subsection (a) has--
       (A) developed, in consultation with NIST and supply chain 
     risk management experts, a mitigation strategy for any 
     identified risks;
       (B) determined, in consultation with NIST and the Federal 
     Bureau of Investigation, that the acquisition of such system 
     is in the vital national security interest of the United 
     States; and
       (C) reported that determination to the Committee on 
     Appropriations of the Senate and the Committee on 
     Appropriations of the House of Representatives in a manner 
     that identifies the system intended for acquisition and 
     includes a detailed description of the mitigation strategies 
     identified in (1).
       (2) The report required by paragraph (1)(C) shall be 
     submitted in unclassified form but may include a classified 
     annex.
                                 ______