Us Congress 2023-2024 Regular Session

Us Congress House Bill HB6106 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 I
22 118THCONGRESS
33 1
44 STSESSION H. R. 6106
55 To create a risk framework to evaluate foreign mobile applications of concern,
66 and for other purposes.
77 IN THE HOUSE OF REPRESENTATIVES
88 OCTOBER26, 2023
99 Ms. S
1010 HERRILL(for herself, Mr. BERGMAN, Mr. KRISHNAMOORTHI, Mrs.
1111 H
1212 INSON, Mr. NEWHOUSE, Mr. GARAMENDI, Mr. CROW, Mr. FINSTAD,
1313 Mr. C
1414 ARSON, and Ms. TOKUDA) introduced the following bill; which was
1515 referred to the Committee on Armed Services
1616 A BILL
1717 To create a risk framework to evaluate foreign mobile
1818 applications of concern, and for other purposes.
1919 Be it enacted by the Senate and House of Representa-1
2020 tives of the United States of America in Congress assembled, 2
2121 SECTION 1. SHORT TITLE. 3
2222 This Act may be cited as the ‘‘Bolstering America’s 4
2323 Defenses Against Potentially Perilous Software Act’’ or 5
2424 the ‘‘BAD APPS Act’’. 6
2525 SEC. 2. RISK FRAMEWORK FOR FOREIGN MOBILE APPLICA-7
2626 TIONS OF CONCERN. 8
2727 (a) I
2828 NGENERAL.—The Secretary of Defense shall— 9
2929 VerDate Sep 11 2014 20:19 Oct 28, 2023 Jkt 049200 PO 00000 Frm 00001 Fmt 6652 Sfmt 6201 E:\BILLS\H6106.IH H6106
3030 ssavage on DSKBC07HB2PROD with BILLS 2
3131 •HR 6106 IH
3232 (1) create categorical definitions of foreign mo-1
3333 bile applications of concern with respect to personnel 2
3434 or operations of the Department of Defense, distin-3
3535 guishing among categories such as applications for 4
3636 shopping, social media, entertainment, or health; 5
3737 and 6
3838 (2) create a risk framework with respect to De-7
3939 partment personnel or operations that assesses each 8
4040 foreign mobile application (or, if appropriate, group-9
4141 ing of similar such applications) that is from a coun-10
4242 try of concern for any potential impact on Depart-11
4343 mental personnel and Departmental operations, in-12
4444 corporating considerations of— 13
4545 (A) the manner and extent of data collec-14
4646 tion by the application; 15
4747 (B) the ability of the application to influ-16
4848 ence the user with the applications content to 17
4949 the detriment of the United States; 18
5050 (C) the manner and extent of foreign own-19
5151 ership or control of the application or data col-20
5252 lected by the application; 21
5353 (D) any foreign government interests asso-22
5454 ciated with the applications; 23
5555 (E) a software bill of materials with a 24
5656 focus on known or assessed malicious software 25
5757 VerDate Sep 11 2014 20:19 Oct 28, 2023 Jkt 049200 PO 00000 Frm 00002 Fmt 6652 Sfmt 6201 E:\BILLS\H6106.IH H6106
5858 ssavage on DSKBC07HB2PROD with BILLS 3
5959 •HR 6106 IH
6060 embedded in the application, including in prior 1
6161 versions of the application or in other applica-2
6262 tions created by the owners of such application; 3
6363 (F) any known impact from prior use of 4
6464 the application to Department personnel or op-5
6565 erations; and 6
6666 (G) the foreign mobile application of con-7
6767 cern residing on a United States Government 8
6868 device or a personally owned device while in 9
6969 proximity to Department operations or activi-10
7070 ties or in the personal custody of personnel dur-11
7171 ing Department sanctioned activities. 12
7272 (b) C
7373 ONSIDERATIONS.—In developing the categorical 13
7474 definitions and risk framework described in subsection (a), 14
7575 the Secretary of Defense— 15
7676 (1) shall include in the risk framework foreign 16
7777 mobile applications of concern— 17
7878 (A) from countries that the Secretary de-18
7979 termines to be engaged in consistent, unauthor-19
8080 ized conduct that is detrimental to the national 20
8181 security or foreign policy of the United States; 21
8282 (B) that are accessible to be downloaded 22
8383 from major mobile device application market-23
8484 places by Department personnel; and 24
8585 VerDate Sep 11 2014 20:19 Oct 28, 2023 Jkt 049200 PO 00000 Frm 00003 Fmt 6652 Sfmt 6201 E:\BILLS\H6106.IH H6106
8686 ssavage on DSKBC07HB2PROD with BILLS 4
8787 •HR 6106 IH
8888 (C) originating from, authored in, owned 1
8989 by, or otherwise associated with countries or en-2
9090 tities that are designated on the list maintained 3
9191 and set forth in Supplement No. 4 to part 744 4
9292 of the Export Administration Regulations; 5
9393 (2) may include additional countries or indi-6
9494 vidual foreign mobile applications with malicious and 7
9595 banned capabilities from other countries to the ex-8
9696 tent the Secretary determines appropriate; and 9
9797 (3) shall consider distinguishing within the risk 10
9898 framework the particular interests of a country de-11
9999 scribed in paragraph (1) or (2) in the use of a for-12
100100 eign mobile application of concern of such country 13
101101 (regardless of device or owner) by— 14
102102 (A) users located at facilities of the De-15
103103 partment of Defense of varying levels of sensi-16
104104 tivity; 17
105105 (B) users conducting authorized operations 18
106106 or movements of Department of Defense mate-19
107107 riel; or 20
108108 (C) specific civilian employees of the De-21
109109 partment or contractors whom the Secretary 22
110110 determines likely to be a target of a foreign 23
111111 actor. 24
112112 VerDate Sep 11 2014 20:19 Oct 28, 2023 Jkt 049200 PO 00000 Frm 00004 Fmt 6652 Sfmt 6201 E:\BILLS\H6106.IH H6106
113113 ssavage on DSKBC07HB2PROD with BILLS 5
114114 •HR 6106 IH
115115 (c) GUIDANCE ANDUPDATES.—The Secretary of De-1
116116 fense shall— 2
117117 (1) issue guidance to all Department personnel 3
118118 incorporating the categories of foreign mobile appli-4
119119 cations of concern and advising how to mitigate the 5
120120 risks identified by the risk framework with respect 6
121121 to such applications; 7
122122 (2) routinely update the categorical definitions 8
123123 and risk framework promulgated pursuant to sub-9
124124 section (a), at least on an annual basis; and 10
125125 (3) prescribe, if feasible, regulations that appro-11
126126 priately mitigate risks from applications on devices 12
127127 provided by the Department of Defense or on any 13
128128 device used during an activity described in sub-14
129129 section (b)(3)(B) or at locations described under 15
130130 (b)(3)(A). 16
131131 Æ
132132 VerDate Sep 11 2014 20:19 Oct 28, 2023 Jkt 049200 PO 00000 Frm 00005 Fmt 6652 Sfmt 6301 E:\BILLS\H6106.IH H6106
133133 ssavage on DSKBC07HB2PROD with BILLS