Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
Calendar No. 52
116TH CONGRESS
1ST SESSION
S. 772
To require an annual report on the cybersecurity of the Small Business
Administration, and for other purposes.
IN THE SENATE OF THE UNITED STATES
MARCH 13, 2019
Mr. RUBIO (for himself, Mr. CARDIN, Mr. RISCH, and Mr. HAWLEY) intro-
duced the following bill; which was read twice and referred to the Com-
mittee on Small Business and Entrepreneurship
APRIL 1, 2019
Reported by Mr. RUBIO, with an amendment
[Strike out all after the enacting clause and insert the part printed in italic]
A BILL
To require an annual report on the cybersecurity of the
Small Business Administration, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘SBA Cyber Awareness
4
Act’’.
5
VerDate Sep 11 2014
23:17 Apr 01, 2019
Jkt 089200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6401
E:\BILLS\S772.RS
S772
pamtmann on DSKBFK8HB2PROD with BILLS
2
•S 772 RS
SEC. 2. CYBERSECURITY AWARENESS REPORTING.
1
Section 10 of the Small Business Act (15 U.S.C. 639)
2
is amended by striking subsection (b) and inserting the
3
following:
4
‘‘(b) CYBERSECURITY REPORTS.—
5
‘‘(1) DEFINITION.—In this subsection, the term
6
‘appropriate congressional committees’ means—
7
‘‘(A) the Committee on Small Business
8
and Entrepreneurship of the Senate; and
9
‘‘(B) the Committee on Small Business of
10
the House of Representatives.
11
‘‘(2) ANNUAL
REPORT.—Not later than 180
12
days after the date of enactment of the SBA Cyber
13
Awareness Act, and every year thereafter, the Ad-
14
ministration shall submit a report to the appropriate
15
congressional committees that includes—
16
‘‘(A) an assessment of the information
17
technology and cybersecurity of the Administra-
18
tion;
19
‘‘(B) a strategy to increase the cybersecu-
20
rity of the Administration;
21
‘‘(C) a detailed account of any information
22
technology component or system of the Admin-
23
istration that was manufactured by a company
24
located in the People’s Republic of China; and
25
VerDate Sep 11 2014
23:17 Apr 01, 2019
Jkt 089200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6401
E:\BILLS\S772.RS
S772
pamtmann on DSKBFK8HB2PROD with BILLS
3
•S 772 RS
‘‘(D) an account of any cyber threat,
1
breach, or cyber attack that occurred at the Ad-
2
ministration during the 2-year period preceding
3
the date on which the report is submitted, and
4
any action taken by the Administration to re-
5
spond to or remediate the cyber threat, breach,
6
or cyber attack.
7
‘‘(3) ADDITIONAL REPORTS.—If the Adminis-
8
tration determines that there is a reasonable basis to
9
conclude that a cyber threat, breach, or cyber attack
10
occurred at the Administration, the Administration
11
shall—
12
‘‘(A) not later than 7 days after the date
13
on which the Administration makes that deter-
14
mination, notify the appropriate congressional
15
committees of the cyber threat, breach, or cyber
16
attack; and
17
‘‘(B) not later than 30 days after the date
18
on which the Administration makes that deter-
19
mination, submit to the appropriate congres-
20
sional committees a report that includes—
21
‘‘(i) a summary of information about
22
the cyber threat, breach, or cyber attack,
23
including how the cyber threat, breach, or
24
cyber attack occurred, based on informa-
25
VerDate Sep 11 2014
23:17 Apr 01, 2019
Jkt 089200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6401
E:\BILLS\S772.RS
S772
pamtmann on DSKBFK8HB2PROD with BILLS
4
•S 772 RS
tion available to the Administration as of
1
the date which the Administration submits
2
the report;
3
‘‘(ii) an estimate of the number of in-
4
dividuals and small entities affected by the
5
cyber threat, breach, or cyber attack, in-
6
cluding an assessment of the risk of harm
7
to affected individuals and small entities
8
based on information available to the Ad-
9
ministration as of the date on which the
10
Administration submits the report; and
11
‘‘(iii) an estimate of when the Admin-
12
istration will provide notice to affected in-
13
dividuals and small entities.
14
‘‘(4) RULE
OF
CONSTRUCTION.—Nothing in
15
this subsection shall be construed to affect the re-
16
porting requirements of the Administration under
17
chapter 35 of title 44 United States Code, in par-
18
ticular the requirement to notify the Federal infor-
19
mation
security
incident
center
under
section
20
3554(b)(7)(C)(ii) of such title, or any other provi-
21
sion of law.’’.
22
SECTION 1. SHORT TITLE.
23
This Act may be cited as the ‘‘SBA Cyber Awareness
24
Act’’.
25
VerDate Sep 11 2014
23:17 Apr 01, 2019
Jkt 089200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6203
E:\BILLS\S772.RS
S772
pamtmann on DSKBFK8HB2PROD with BILLS
5
•S 772 RS
SEC. 2. CYBERSECURITY AWARENESS REPORTING.
1
Section 10 of the Small Business Act (15 U.S.C. 639)
2
is amended by inserting after subsection (a) the following:
3
‘‘(b) CYBERSECURITY REPORTS.—
4
‘‘(1) DEFINITIONS.—In this subsection—
5
‘‘(A) the term ‘appropriate congressional
6
committees’ means—
7
‘‘(i) the Committee on Small Business
8
and Entrepreneurship of the Senate; and
9
‘‘(ii) the Committee on Small Business
10
of the House of Representatives; and
11
‘‘(B) the term ‘major incident’ has the
12
meaning given the term in the Office of Manage-
13
ment and Budget Memorandum on Federal In-
14
formation Security and Privacy Management
15
Requirements, dated October 16, 2017 (M–18–
16
02), or any successor memorandum.
17
‘‘(2) ANNUAL REPORT.—Not later than 180 days
18
after the date of enactment of the SBA Cyber Aware-
19
ness Act, and every year thereafter, the Administra-
20
tion shall submit to the appropriate congressional
21
committees a report that includes—
22
‘‘(A) an assessment of the information tech-
23
nology and cybersecurity of the Administration;
24
‘‘(B) a strategy to increase the cybersecurity
25
of the Administration;
26
VerDate Sep 11 2014
23:17 Apr 01, 2019
Jkt 089200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6203
E:\BILLS\S772.RS
S772
pamtmann on DSKBFK8HB2PROD with BILLS
6
•S 772 RS
‘‘(C) a detailed account of any information
1
technology component or system of the Adminis-
2
tration that was manufactured by a company lo-
3
cated in the People’s Republic of China; and
4
‘‘(D) an account of any major incident that
5
occurred at the Administration during the 2-
6
year period preceding the date on which the re-
7
port is submitted, and any action taken by the
8
Administration to respond to or remediate the
9
major incident.
10
‘‘(3) ADDITIONAL REPORTS.—If the Administra-
11
tion determines that there is a reasonable basis to
12
conclude that a major incident occurred at the Ad-
13
ministration, the Administration shall—
14
‘‘(A) not later than 7 days after the date on
15
which the Administration makes that determina-
16
tion, notify the appropriate congressional com-
17
mittees of the major incident; and
18
‘‘(B) not later than 30 days after the date
19
on which the Administration makes that deter-
20
mination, submit to the appropriate congres-
21
sional committees a report that includes—
22
‘‘(i) a summary of information about
23
the major incident, including how the major
24
incident occurred, based on information
25
VerDate Sep 11 2014
23:17 Apr 01, 2019
Jkt 089200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6203
E:\BILLS\S772.RS
S772
pamtmann on DSKBFK8HB2PROD with BILLS
7
•S 772 RS
available to the Administration as of the
1
date which the Administration submits the
2
report;
3
‘‘(ii) an estimate of the number of in-
4
dividuals and small entities affected by the
5
major incident, including an assessment of
6
the risk of harm to affected individuals and
7
small entities based on information avail-
8
able to the Administration as of the date on
9
which the Administration submits the re-
10
port; and
11
‘‘(iii) an estimate of when the Admin-
12
istration will provide notice to affected in-
13
dividuals and small entities.
14
‘‘(4) RULE OF CONSTRUCTION.—Nothing in this
15
subsection shall be construed to affect the reporting re-
16
quirements of the Administration under chapter 35 of
17
title 44 United States Code, in particular the require-
18
ment to notify the Federal information security inci-
19
dent center under section 3554(b)(7)(C)(ii) of such
20
title, or any other provision of law.’’.
21
VerDate Sep 11 2014
23:17 Apr 01, 2019
Jkt 089200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6203
E:\BILLS\S772.RS
S772
pamtmann on DSKBFK8HB2PROD with BILLS
Calendar No. 52
116TH CONGRESS
1ST SESSION
S. 772
A BILL
To require an annual report on the cybersecurity of
the Small Business Administration, and for other
purposes.
APRIL 1, 2019
Reported with an amendment
VerDate Sep 11 2014
23:17 Apr 01, 2019
Jkt 089200
PO 00000
Frm 00008
Fmt 6651
Sfmt 6651
E:\BILLS\S772.RS
S772
pamtmann on DSKBFK8HB2PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.