§1321. Definitions — Inbound Citations
41 U.S.C. § 1321
Cited by 81 provisions in release 119-102.
Citations to §1321(1)
-
(D) not later than 7 days after completion of the charter, submitting the charter to the appropriate congressional committees and leadership.
-
(B) provide classified or unclassified notice of the exclusion or removal order to the appropriate congressional committees and leadership; and
-
(b) Not later than 7 calendar days after completion of the strategic plan required by subsection (a), the Chairperson of the Council shall submit the plan to the appropriate congressional committees and leadership.
-
Not later than December 31 of each year, the Chairperson of the Council shall submit to the appropriate congressional committees and leadership a report on the activities of the Council during the preceding 12-month period.
Citations to §1321(2)
-
(a) There is established in the executive branch a Federal Acquisition Security Council.
-
(1) The following agencies shall be represented on the Council:(A) The Office of Management and Budget.(B) The General Services Administration.(C) The Department of Homeland Security, including the Cybersecurity and Infrastructure Security Agency.(D) The Office of the Director of National Intelligence, including the National Counterintelligence and Security Center.(E) The Department of Justice, including the Federal Bureau of Investigation.(F) The Department of Defense, including the National Security Agency.(G) The Department of Commerce, including the National Institute of Standards and Technology.(H) Such other executive agencies as determined by the Chairperson of the Council.
-
(H) Such other executive agencies as determined by the Chairperson of the Council.
-
(B) The lead representative of an agency designated under subparagraph (A) shall ensure that appropriate personnel, including leadership and subject matter experts of the agency, are aware of the business of the Council.
-
(A) subject to subsection (d), developing a schedule for meetings of the Council;
-
(B) designating executive agencies to be represented on the Council under subsection (b)(1)(H);
-
(d) The Council shall meet not later than 60 days after the date of the enactment of the Federal Acquisition Supply Chain Security Act of 2018 and not less frequently than quarterly thereafter.
-
(a) The Council shall perform functions that include the following:(1) Identifying and recommending development by the National Institute of Standards and Technology of supply chain risk management standards, guidelines, and practices for executive agencies to use when assessing and developing mitigation strategies to address supply chain risks, particularly in the acquisition and use of covered articles under section 1326(a) of this title.(2) Identifying or developing criteria for sharing information with executive agencies, other Federal entities, and non-Federal entities with respect to supply chain risk, including information related to the exercise of authorities provided under this section and sections 1326 and 4713 of this title. At a minimum, such criteria shall address—(A) the content to be shared;(B) the circumstances under which sharing is mandated or voluntary; and(C) the circumstances under which it is appropriate for an executive agency to rely on information made available through such sharing in exercising the responsibilities and authorities provided under this section and section 4713 of this title.(3) Identifying an appropriate executive agency to—(A) accept information submitted by executive agencies based on the criteria established under paragraph (2);(B) facilitate the sharing of information received under subparagraph (A) to support supply chain risk analyses under section 1326 of this title, recommendations under this section, and covered procurement actions under section 4713 of this title;(C) share with the Council information regarding covered procurement actions by executive agencies taken under section 4713 of this title; and(D) inform the Council of orders issued under this section.(4) Identifying, as appropriate, executive agencies to provide—(A) shared services, such as support for making risk assessments, validation of products that may be suitable for acquisition, and mitigation activities; and(B) common contract solutions to support supply chain risk management activities, such as subscription services or machine-learning-enhanced analysis applications to support informed decision making.(5) Identifying and issuing guidance on additional steps that may be necessary to address supply chain risks arising in the course of executive agencies providing shared services, common contract solutions, acquisitions vehicles, or assisted acquisitions.(6) Engaging with the private sector and other nongovernmental stakeholders in performing the functions described in paragraphs (1) and (2) and on issues relating to the management of supply chain risks posed by the acquisition of covered articles.(7) Carrying out such other actions, as determined by the Council, that are necessary to reduce the supply chain risks posed by acquisitions and use of covered articles.
-
(C) share with the Council information regarding covered procurement actions by executive agencies taken under section 4713 of this title; and
-
(D) inform the Council of orders issued under this section.
-
(7) Carrying out such other actions, as determined by the Council, that are necessary to reduce the supply chain risks posed by acquisitions and use of covered articles.
-
(1) To reduce supply chain risk, the Council shall establish criteria and procedures for—(A) recommending orders applicable to executive agencies requiring the exclusion of sources or covered articles from executive agency procurement actions (in this section referred to as “exclusion orders”);(B) recommending orders applicable to executive agencies requiring the removal of covered articles from executive agency information systems (in this section referred to as “removal orders”);(C) requesting and approving exceptions to an issued exclusion or removal order when warranted by circumstances, including alternative mitigation actions or other findings relating to the national interest, including national security reviews, national security investigations, or national security agreements; and(D) ensuring that recommended orders do not conflict with standards and guidelines issued under section 11331 of title 40 and that the Council consults with the Director of the National Institute of Standards and Technology regarding any recommended orders that would implement standards and guidelines developed by the National Institute of Standards and Technology.
-
(D) ensuring that recommended orders do not conflict with standards and guidelines issued under section 11331 of title 40 and that the Council consults with the Director of the National Institute of Standards and Technology regarding any recommended orders that would implement standards and guidelines developed by the National Institute of Standards and Technology.
-
(2) The Council shall use the criteria established under paragraph (1), information made available under subsection (a)(3), and any other information the Council determines appropriate to issue recommendations, for application to executive agencies or any subset thereof, regarding the exclusion of sources or covered articles from any executive agency procurement action, including source selection and consent for a contractor to subcontract, or the removal of covered articles from executive agency information systems. Such recommendations shall include—(A) information necessary to positively identify the sources or covered articles recommended for exclusion or removal;(B) information regarding the scope and applicability of the recommended exclusion or removal order;(C) a summary of any risk assessment reviewed or conducted in support of the recommended exclusion or removal order;(D) a summary of the basis for the recommendation, including a discussion of less intrusive measures that were considered and why such measures were not reasonably available to reduce supply chain risk;(E) a description of the actions necessary to implement the recommended exclusion or removal order; and
-
(3) A notice of the Council’s recommendation under paragraph (2) shall be issued to any source named in the recommendation advising—(A) that a recommendation has been made;(B) of the criteria the Council relied upon under paragraph (1) and, to the extent consistent with national security and law enforcement interests, of information that forms the basis for the recommendation;(C) that, within 30 days after receipt of notice, the source may submit information and argument in opposition to the recommendation;(D) of the procedures governing the review and possible issuance of an exclusion or removal order pursuant to paragraph (5); and
-
(B) of the criteria the Council relied upon under paragraph (1) and, to the extent consistent with national security and law enforcement interests, of information that forms the basis for the recommendation;
-
(A) Recommendations of the Council under paragraph (2), together with any information submitted by a source under paragraph (3) related to such a recommendation, shall be reviewed by the following officials, who may issue exclusion and removal orders based upon such recommendations:(i) The Secretary of Homeland Security, for exclusion and removal orders applicable to civilian agencies, to the extent not covered by clause (ii) or (iii).(ii) The Secretary of Defense, for exclusion and removal orders applicable to the Department of Defense and national security systems other than sensitive compartmented information systems.(iii) The Director of National Intelligence, for exclusion and removal orders applicable to the intelligence community and sensitive compartmented information systems, to the extent not covered by clause (ii).
-
(D) The officials identified under this paragraph shall review all exclusion and removal orders issued under subparagraph (A) not less frequently than annually pursuant to procedures established by the Council.
-
(e) The Council shall consult and coordinate, as appropriate, with other relevant councils and interagency committees, including the Chief Information Officers Council, the Chief Acquisition Officers Council, the Federal Acquisition Regulatory Council, and the Committee on Foreign Investment in the United States, with respect to supply chain risks posed by the acquisition and use of covered articles.
-
(a) Not later than 180 days after the date of the enactment of the Federal Acquisition Supply Chain Security Act of 2018, the Council shall develop a strategic plan for addressing supply chain risks posed by the acquisition of covered articles and for managing such risks that includes—(1) the criteria and processes required under section 1323(a) of this title, including a threshold and requirements for sharing relevant information about such risks with all executive agencies and, as appropriate, with other Federal entities and non-Federal entities;(2) an identification of existing authorities for addressing such risks;(3) an identification and promulgation of best practices and procedures and available resources for executive agencies to assess and mitigate such risks;(4) recommendations for any legislative, regulatory, or other policy changes to improve efforts to address such risks;(5) recommendations for any legislative, regulatory, or other policy changes to incentivize the adoption of best practices for supply chain risk management by the private sector;(6) an evaluation of the effect of implementing new policies or procedures on existing contracts and the procurement process;(7) a plan for engaging with executive agencies, the private sector, and other nongovernmental stakeholders to address such risks;(8) a plan for identification, assessment, mitigation, and vetting of supply chain risks from existing and prospective information and communications technology made available by executive agencies to other executive agencies through common contract solutions, shared services, acquisition vehicles, or other assisted acquisition services; and(9) plans to strengthen the capacity of all executive agencies to conduct assessments of—(A) the supply chain risk posed by the acquisition of covered articles; and(B) compliance with the requirements of this subchapter.
-
(b) Not later than 7 calendar days after completion of the strategic plan required by subsection (a), the Chairperson of the Council shall submit the plan to the appropriate congressional committees and leadership.
-
Not later than December 31 of each year, the Chairperson of the Council shall submit to the appropriate congressional committees and leadership a report on the activities of the Council during the preceding 12-month period.
-
(1) assessing the supply chain risk posed by the acquisition and use of covered articles and avoiding, mitigating, accepting, or transferring that risk, as appropriate and consistent with the standards, guidelines, and practices identified by the Council under section 1323(a)(1); and
-
(4) sharing relevant information with other executive agencies as determined appropriate by the Council in a manner consistent with section 1323(a) of this title;
-
(5) reporting on progress and effectiveness of the agency’s supply chain risk management consistent with guidance issued by the Office of Management and Budget and the Council; and
Citations to §1321(3)
-
(1) Identifying and recommending development by the National Institute of Standards and Technology of supply chain risk management standards, guidelines, and practices for executive agencies to use when assessing and developing mitigation strategies to address supply chain risks, particularly in the acquisition and use of covered articles under section 1326(a) of this title.
-
(6) Engaging with the private sector and other nongovernmental stakeholders in performing the functions described in paragraphs (1) and (2) and on issues relating to the management of supply chain risks posed by the acquisition of covered articles.
-
(7) Carrying out such other actions, as determined by the Council, that are necessary to reduce the supply chain risks posed by acquisitions and use of covered articles.
-
(A) recommending orders applicable to executive agencies requiring the exclusion of sources or covered articles from executive agency procurement actions (in this section referred to as “exclusion orders”);
-
(B) recommending orders applicable to executive agencies requiring the removal of covered articles from executive agency information systems (in this section referred to as “removal orders”);
-
(2) The Council shall use the criteria established under paragraph (1), information made available under subsection (a)(3), and any other information the Council determines appropriate to issue recommendations, for application to executive agencies or any subset thereof, regarding the exclusion of sources or covered articles from any executive agency procurement action, including source selection and consent for a contractor to subcontract, or the removal of covered articles from executive agency information systems. Such recommendations shall include—(A) information necessary to positively identify the sources or covered articles recommended for exclusion or removal;(B) information regarding the scope and applicability of the recommended exclusion or removal order;(C) a summary of any risk assessment reviewed or conducted in support of the recommended exclusion or removal order;(D) a summary of the basis for the recommendation, including a discussion of less intrusive measures that were considered and why such measures were not reasonably available to reduce supply chain risk;(E) a description of the actions necessary to implement the recommended exclusion or removal order; and
-
(A) information necessary to positively identify the sources or covered articles recommended for exclusion or removal;
-
(C) If officials identified under this paragraph from the Department of Homeland Security, the Department of Defense, and the Office of the Director of National Intelligence issue orders collectively resulting in a governmentwide exclusion, the Administrator for General Services and officials at other executive agencies responsible for management of the Federal Supply Schedules, governmentwide acquisition contracts and multi-agency contracts shall help facilitate implementation of such orders by removing the covered articles or sources identified in the orders from such contracts.
-
(e) The Council shall consult and coordinate, as appropriate, with other relevant councils and interagency committees, including the Chief Information Officers Council, the Chief Acquisition Officers Council, the Federal Acquisition Regulatory Council, and the Committee on Foreign Investment in the United States, with respect to supply chain risks posed by the acquisition and use of covered articles.
-
(a) Not later than 180 days after the date of the enactment of the Federal Acquisition Supply Chain Security Act of 2018, the Council shall develop a strategic plan for addressing supply chain risks posed by the acquisition of covered articles and for managing such risks that includes—(1) the criteria and processes required under section 1323(a) of this title, including a threshold and requirements for sharing relevant information about such risks with all executive agencies and, as appropriate, with other Federal entities and non-Federal entities;(2) an identification of existing authorities for addressing such risks;(3) an identification and promulgation of best practices and procedures and available resources for executive agencies to assess and mitigate such risks;(4) recommendations for any legislative, regulatory, or other policy changes to improve efforts to address such risks;(5) recommendations for any legislative, regulatory, or other policy changes to incentivize the adoption of best practices for supply chain risk management by the private sector;(6) an evaluation of the effect of implementing new policies or procedures on existing contracts and the procurement process;(7) a plan for engaging with executive agencies, the private sector, and other nongovernmental stakeholders to address such risks;(8) a plan for identification, assessment, mitigation, and vetting of supply chain risks from existing and prospective information and communications technology made available by executive agencies to other executive agencies through common contract solutions, shared services, acquisition vehicles, or other assisted acquisition services; and(9) plans to strengthen the capacity of all executive agencies to conduct assessments of—(A) the supply chain risk posed by the acquisition of covered articles; and(B) compliance with the requirements of this subchapter.
-
(A) the supply chain risk posed by the acquisition of covered articles; and
-
(1) assessing the supply chain risk posed by the acquisition and use of covered articles and avoiding, mitigating, accepting, or transferring that risk, as appropriate and consistent with the standards, guidelines, and practices identified by the Council under section 1323(a)(1); and
-
(6) ensuring that all relevant information, including classified information, with respect to acquisitions of covered articles that may pose a supply chain risk, consistent with section 1323(a) of this title, is incorporated into existing processes of the agency for conducting assessments described in subsection (a) and ongoing management of acquisition programs, including any identification, investigation, mitigation, or remediation needs.
-
(1) Except as provided in paragraph (2), in the case of an interagency acquisition, subsection (a) shall be carried out by the head of the executive agency whose funds are being used to procure the covered article.
Citations to §1321(4)
-
(B) facilitate the sharing of information received under subparagraph (A) to support supply chain risk analyses under section 1326 of this title, recommendations under this section, and covered procurement actions under section 4713 of this title;
-
(C) share with the Council information regarding covered procurement actions by executive agencies taken under section 4713 of this title; and
-
(1) Not later than 60 days after a party is notified of an exclusion or removal order under section 1323(c)(6) of this title or a covered procurement action under section 4713 of this title, the party may file a petition for judicial review in the United States Court of Appeals for the District of Columbia Circuit claiming that the issuance of the exclusion or removal order or covered procurement action is unlawful.
-
(i) The United States shall file with the court an administrative record, which shall consist of the information that the appropriate official relied upon in issuing an exclusion or removal order under section 1323(c)(5) or a covered procurement action under section 4713 of this title.
Citations to §1321(5)
-
(ii) The representative of an agency designated under clause (i) shall have expertise in supply chain risk management, acquisitions, or information and communications technology.
-
(8) a plan for identification, assessment, mitigation, and vetting of supply chain risks from existing and prospective information and communications technology made available by executive agencies to other executive agencies through common contract solutions, shared services, acquisition vehicles, or other assisted acquisition services; and
-
(1) assist executive agencies in conducting risk assessments described in subsection (a) and implementing mitigation requirements for information and communications technology; and
Citations to §1321(6)
-
(iii) The Director of National Intelligence, for exclusion and removal orders applicable to the intelligence community and sensitive compartmented information systems, to the extent not covered by clause (ii).
Citations to §1321(7)
-
(ii) The Secretary of Defense, for exclusion and removal orders applicable to the Department of Defense and national security systems other than sensitive compartmented information systems.
Citations to §1321(8)
-
(ii) The representative of an agency designated under clause (i) shall have expertise in supply chain risk management, acquisitions, or information and communications technology.
-
(1) Identifying and recommending development by the National Institute of Standards and Technology of supply chain risk management standards, guidelines, and practices for executive agencies to use when assessing and developing mitigation strategies to address supply chain risks, particularly in the acquisition and use of covered articles under section 1326(a) of this title.
-
(2) Identifying or developing criteria for sharing information with executive agencies, other Federal entities, and non-Federal entities with respect to supply chain risk, including information related to the exercise of authorities provided under this section and sections 1326 and 4713 of this title. At a minimum, such criteria shall address—(A) the content to be shared;(B) the circumstances under which sharing is mandated or voluntary; and(C) the circumstances under which it is appropriate for an executive agency to rely on information made available through such sharing in exercising the responsibilities and authorities provided under this section and section 4713 of this title.
-
(B) facilitate the sharing of information received under subparagraph (A) to support supply chain risk analyses under section 1326 of this title, recommendations under this section, and covered procurement actions under section 4713 of this title;
-
(B) common contract solutions to support supply chain risk management activities, such as subscription services or machine-learning-enhanced analysis applications to support informed decision making.
-
(5) Identifying and issuing guidance on additional steps that may be necessary to address supply chain risks arising in the course of executive agencies providing shared services, common contract solutions, acquisitions vehicles, or assisted acquisitions.
-
(6) Engaging with the private sector and other nongovernmental stakeholders in performing the functions described in paragraphs (1) and (2) and on issues relating to the management of supply chain risks posed by the acquisition of covered articles.
-
(7) Carrying out such other actions, as determined by the Council, that are necessary to reduce the supply chain risks posed by acquisitions and use of covered articles.
-
(1) To reduce supply chain risk, the Council shall establish criteria and procedures for—(A) recommending orders applicable to executive agencies requiring the exclusion of sources or covered articles from executive agency procurement actions (in this section referred to as “exclusion orders”);(B) recommending orders applicable to executive agencies requiring the removal of covered articles from executive agency information systems (in this section referred to as “removal orders”);(C) requesting and approving exceptions to an issued exclusion or removal order when warranted by circumstances, including alternative mitigation actions or other findings relating to the national interest, including national security reviews, national security investigations, or national security agreements; and(D) ensuring that recommended orders do not conflict with standards and guidelines issued under section 11331 of title 40 and that the Council consults with the Director of the National Institute of Standards and Technology regarding any recommended orders that would implement standards and guidelines developed by the National Institute of Standards and Technology.
-
(D) a summary of the basis for the recommendation, including a discussion of less intrusive measures that were considered and why such measures were not reasonably available to reduce supply chain risk;
-
(e) The Council shall consult and coordinate, as appropriate, with other relevant councils and interagency committees, including the Chief Information Officers Council, the Chief Acquisition Officers Council, the Federal Acquisition Regulatory Council, and the Committee on Foreign Investment in the United States, with respect to supply chain risks posed by the acquisition and use of covered articles.
-
(a) Not later than 180 days after the date of the enactment of the Federal Acquisition Supply Chain Security Act of 2018, the Council shall develop a strategic plan for addressing supply chain risks posed by the acquisition of covered articles and for managing such risks that includes—(1) the criteria and processes required under section 1323(a) of this title, including a threshold and requirements for sharing relevant information about such risks with all executive agencies and, as appropriate, with other Federal entities and non-Federal entities;(2) an identification of existing authorities for addressing such risks;(3) an identification and promulgation of best practices and procedures and available resources for executive agencies to assess and mitigate such risks;(4) recommendations for any legislative, regulatory, or other policy changes to improve efforts to address such risks;(5) recommendations for any legislative, regulatory, or other policy changes to incentivize the adoption of best practices for supply chain risk management by the private sector;(6) an evaluation of the effect of implementing new policies or procedures on existing contracts and the procurement process;(7) a plan for engaging with executive agencies, the private sector, and other nongovernmental stakeholders to address such risks;(8) a plan for identification, assessment, mitigation, and vetting of supply chain risks from existing and prospective information and communications technology made available by executive agencies to other executive agencies through common contract solutions, shared services, acquisition vehicles, or other assisted acquisition services; and(9) plans to strengthen the capacity of all executive agencies to conduct assessments of—(A) the supply chain risk posed by the acquisition of covered articles; and(B) compliance with the requirements of this subchapter.
-
(5) recommendations for any legislative, regulatory, or other policy changes to incentivize the adoption of best practices for supply chain risk management by the private sector;
-
(8) a plan for identification, assessment, mitigation, and vetting of supply chain risks from existing and prospective information and communications technology made available by executive agencies to other executive agencies through common contract solutions, shared services, acquisition vehicles, or other assisted acquisition services; and
-
(A) the supply chain risk posed by the acquisition of covered articles; and
-
(1) assessing the supply chain risk posed by the acquisition and use of covered articles and avoiding, mitigating, accepting, or transferring that risk, as appropriate and consistent with the standards, guidelines, and practices identified by the Council under section 1323(a)(1); and
-
(2) prioritizing supply chain risk assessments conducted under paragraph (1) based on the criticality of the mission, system, component, service, or asset.
-
(b) The responsibility for assessing supply chain risk described in subsection (a) includes—(1) developing an overall supply chain risk management strategy and implementation plan and policies and processes to guide and govern supply chain risk management activities;(2) integrating supply chain risk management practices throughout the life cycle of the system, component, service, or asset;(3) limiting, avoiding, mitigating, accepting, or transferring any identified risk;(4) sharing relevant information with other executive agencies as determined appropriate by the Council in a manner consistent with section 1323(a) of this title;(5) reporting on progress and effectiveness of the agency’s supply chain risk management consistent with guidance issued by the Office of Management and Budget and the Council; and(6) ensuring that all relevant information, including classified information, with respect to acquisitions of covered articles that may pose a supply chain risk, consistent with section 1323(a) of this title, is incorporated into existing processes of the agency for conducting assessments described in subsection (a) and ongoing management of acquisition programs, including any identification, investigation, mitigation, or remediation needs.
-
(1) developing an overall supply chain risk management strategy and implementation plan and policies and processes to guide and govern supply chain risk management activities;
-
(2) integrating supply chain risk management practices throughout the life cycle of the system, component, service, or asset;
-
(5) reporting on progress and effectiveness of the agency’s supply chain risk management consistent with guidance issued by the Office of Management and Budget and the Council; and
-
(6) ensuring that all relevant information, including classified information, with respect to acquisitions of covered articles that may pose a supply chain risk, consistent with section 1323(a) of this title, is incorporated into existing processes of the agency for conducting assessments described in subsection (a) and ongoing management of acquisition programs, including any identification, investigation, mitigation, or remediation needs.