(a)
In general— With respect to newly constructed foreign cranes procured for use at a United States port determined by the Secretary to be of high risk to port security or maritime transportation security and that connect to the cybersecurity network of such port, the Secretary of Homeland Security shall, acting through the Cybersecurity and Infrastructure Security Agency, before such crane is placed into service at such port, inspect such crane for potential security vulnerabilities.
(b)
Security vulnerability assessments— Not later than 180 days after the date of enactment of this Act, the Secretary shall assess the threat posed by security vulnerabilities of any existing or newly constructed foreign cranes.
(c)
Report to Congress— Not later than 1 year after the date of enactment of this Act, the Secretary shall brief the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate regarding critical and high-risk foreign crane security vulnerabilities posed by existing or newly constructed foreign cranes within United States ports.
(d)
Definitions— In this section:
(1)
Covered foreign country— The term “covered foreign country” means a country that—
(A)
the intelligence community has identified as a foreign adversary in its most recent Annual Threat Assessment; or
(B)
the Secretary of Homeland Security, in coordination with the Director of National Intelligence, has identified as a foreign adversary that is not included in such Annual Threat Assessment.
(2)
Foreign crane— The term “foreign crane” means a crane for which any software or other technology in such crane that is connected into cyber infrastructure at a port located in the United States was, in whole or in part, manufactured by an entity that is owned or controlled by, is a subsidiary of, or is otherwise related legally or financially to a corporation based in a covered foreign country.