Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
Calendar No. 151
116TH CONGRESS
1ST SESSION H. R. 2331
IN THE SENATE OF THE UNITED STATES
JULY 16, 2019
Received; read twice and placed on the calendar
AN ACT
To require an annual report on the cybersecurity of the
Small Business Administration, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘SBA Cyber Awareness
4
Act’’.
5
SEC. 2. CYBERSECURITY AWARENESS REPORTING.
6
Section 10 of the Small Business Act (15 U.S.C. 639)
7
is amended by inserting after subsection (a) the following:
8
‘‘(b) CYBERSECURITY REPORTS.—
9
‘‘(1) ANNUAL
REPORT.—Not later than 180
10
days after the date of enactment of this subsection,
11
VerDate Sep 11 2014
22:40 Jul 16, 2019
Jkt 089200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\H2331.PCS
H2331
pamtmann on DSKBFK8HB2PROD with BILLS
2
HR 2331 PCS
and every year thereafter, the Administrator shall
1
submit a report to the appropriate congressional
2
committees that includes—
3
‘‘(A) an assessment of the information
4
technology (as defined in section 11101 of title
5
40, United States Code) and cybersecurity in-
6
frastructure of the Administration;
7
‘‘(B) a strategy to increase the cybersecuri-
8
ty infrastructure of the Administration;
9
‘‘(C) a detailed account of any information
10
technology equipment or interconnected system
11
or subsystem of equipment of the Administra-
12
tion that was manufactured by an entity that
13
has its principal place of business located in the
14
People’s Republic of China; and
15
‘‘(D) an account of any cybersecurity risk
16
or incident that occurred at the Administration
17
during the 2-year period preceding the date on
18
which the report is submitted, and any action
19
taken by the Administrator to respond to or re-
20
mediate any such cybersecurity risk or incident.
21
‘‘(2) ADDITIONAL REPORTS.—If the Adminis-
22
trator determines that there is a reasonable basis to
23
conclude that a cybersecurity risk or incident oc-
24
VerDate Sep 11 2014
22:40 Jul 16, 2019
Jkt 089200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H2331.PCS
H2331
pamtmann on DSKBFK8HB2PROD with BILLS
3
HR 2331 PCS
curred at the Administration, the Administrator
1
shall—
2
‘‘(A) not later than 7 days after the date
3
on which the Administrator makes that deter-
4
mination, notify the appropriate congressional
5
committees of the cybersecurity risk or incident;
6
and
7
‘‘(B) not later than 30 days after the date
8
on which the Administrator makes a determina-
9
tion under subparagraph (A)—
10
‘‘(i) provide notice to individuals and
11
small business concerns affected by the cy-
12
bersecurity risk or incident; and
13
‘‘(ii) submit to the appropriate con-
14
gressional committees a report, based on
15
information available to the Administrator
16
as of the date which the Administrator
17
submits the report, that includes—
18
‘‘(I) a summary of information
19
about the cybersecurity risk or inci-
20
dent, including how the cybersecurity
21
risk or incident occurred; and
22
‘‘(II) an estimate of the number
23
of individuals and small business con-
24
cerns affected by the cybersecurity
25
VerDate Sep 11 2014
22:40 Jul 16, 2019
Jkt 089200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H2331.PCS
H2331
pamtmann on DSKBFK8HB2PROD with BILLS
4
HR 2331 PCS
risk or incident, including an assess-
1
ment of the risk of harm to affected
2
individuals and small business con-
3
cerns.
4
‘‘(3) RULE
OF
CONSTRUCTION.—Nothing in
5
this subsection shall be construed to affect the re-
6
porting requirements of the Administrator under
7
chapter 35 of title 44, United States Code, in par-
8
ticular the requirement to notify the Federal infor-
9
mation security incident center under section
10
3554(b)(7)(C)(ii) of such title, or any other provi-
11
sion of law.
12
‘‘(4) DEFINITIONS.—In this subsection:
13
‘‘(A) APPROPRIATE CONGRESSIONAL COM-
14
MITTEES.—The term ‘appropriate congressional
15
committees’ means—
16
‘‘(i) the Committee on Small Business
17
and Entrepreneurship of the Senate; and
18
‘‘(ii) the Committee on Small Busi-
19
ness of the House of Representatives.
20
‘‘(B) CYBERSECURITY RISK; INCIDENT.—
21
The terms ‘cybersecurity risk’ and ‘incident’
22
have the meanings given such terms, respec-
23
VerDate Sep 11 2014
22:40 Jul 16, 2019
Jkt 089200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H2331.PCS
H2331
pamtmann on DSKBFK8HB2PROD with BILLS
5
HR 2331 PCS
tively, under section 2209(a) of the Homeland
1
Security Act of 2002.’’.
2
Passed the House of Representatives July 15, 2019.
Attest:
CHERYL L. JOHNSON,
Clerk.
VerDate Sep 11 2014
22:40 Jul 16, 2019
Jkt 089200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H2331.PCS
H2331
pamtmann on DSKBFK8HB2PROD with BILLS
Calendar No. 151
116TH CONGRESS
1ST SESSION
H. R. 2331
AN ACT
To require an annual report on the cybersecurity of
the Small Business Administration, and for other
purposes.
JULY 16, 2019
Received; read twice and placed on the calendar
VerDate Sep 11 2014
22:40 Jul 16, 2019
Jkt 089200
PO 00000
Frm 00006
Fmt 6651
Sfmt 6651
E:\BILLS\H2331.PCS
H2331
pamtmann on DSKBFK8HB2PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.