[Congressional Record Volume 164, Number 139 (Tuesday, August 21, 2018)]
[Senate]
[Page S5776]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 3854. Mr. RUBIO submitted an amendment intended to be proposed to
amendment SA 3695 proposed by Mr. Shelby to the bill H.R. 6157, making
appropriations for the Department of Defense for the fiscal year ending
September 30, 2019, and for other purposes; which was ordered to lie on
the table; as follows:
At the appropriate place in division A, insert the
following:
Sec. ____. (a) None of the funds appropriated or otherwise
made available in this Act may be used by a Federal agency
for which amounts are appropriated in this Act to acquire
telecommunications equipment produced by Huawei Technologies
Company or ZTE Corporation or a high-impact or moderate-
impact information system, as defined for security
categorization in the National Institute of Standards and
Technology's (in this section referred to as ``NIST'')
Federal Information Processing Standard Publication 199,
``Standards for Security Categorization of Federal
Information and Information Systems'', unless the agency
has--
(1) reviewed the supply chain risk for the information
systems against criteria developed by NIST to inform
acquisition decisions for high-impact and moderate-impact
information systems within the Federal Government;
(2) reviewed the supply chain risk from the presumptive
awardee against available and relevant threat information
provided by the Federal Bureau of Investigation and other
appropriate Federal agencies; and
(3) in consultation with the Federal Bureau of
Investigation or other appropriate Federal agency, conducted
an assessment of any risk of cyber espionage or sabotage
associated with the acquisition of such system, including any
risk associated with such system being produced,
manufactured, or assembled by one or more entities identified
by the United States Government as posing a cyber threat,
including those that may be owned, directed, or subsidized by
the People's Republic of China, the Islamic Republic of Iran,
the Democratic People's Republic of Korea, or the Russian
Federation.
(b)(1) None of the funds appropriated or otherwise made
available in this Act may be used to acquire a high-impact or
moderate-impact information system reviewed and assessed
under subsection (a) unless the head of the assessing entity
described in subsection (a) has--
(A) developed, in consultation with NIST and supply chain
risk management experts, a mitigation strategy for any
identified risks;
(B) determined, in consultation with NIST and the Federal
Bureau of Investigation, that the acquisition of such system
is in the vital national security interest of the United
States; and
(C) reported that determination to the Committee on
Appropriations of the Senate and the Committee on
Appropriations of the House of Representatives in a manner
that identifies the system intended for acquisition and
includes a detailed description of the mitigation strategies
identified in (1).
(2) The report required by paragraph (1)(C) shall be
submitted in unclassified form but may include a classified
annex.
______