41 C.F.R. § 201-1.101

Current through May 31, 2024
Section 201-1.101 - Definitions

For the purposes of this part:

Appropriate congressional committees and leadership means:

(1) The Committee on Homeland Security and Governmental Affairs, the Committee on the Judiciary, the Committee on Appropriations, the Committee on Armed Services, the Committee on Commerce, Science, and Transportation, the Select Committee on Intelligence, and the majority and minority leader of the Senate; and
(2) The Committee on Oversight and Government Reform, the Committee on the Judiciary, the Committee on Appropriations, the Committee on Homeland Security, the Committee on Armed Services, the Committee on Energy and Commerce, the Permanent Select Committee on Intelligence, and the Speaker and minority leader of the House of Representatives.

Council or FASC means the Federal Acquisition Security Council.

Covered article means any of the following:

(1) Information technology, as defined in 40 U.S.C. 11101 , including cloud computing services of all types;
(2) Telecommunications equipment or telecommunications service, as those terms are defined in section 3 of the Communications Act of 1934 (47 U.S.C. 153 );
(3) The processing of information on a Federal or non-Federal information system, subject to the requirements of the Controlled Unclassified Information program or subsequent U.S. Government program for controlling sensitive unclassified information; or
(4) Hardware, systems, devices, software, or services that include embedded or incidental information technology.

Covered procurement means:

(1) A source selection for a covered article involving either a performance specification, as provided in subsection (a)(3)(B) of 41 U.S.C. 3306 , or an evaluation factor, as provided in subsection (b)(1)(A) of 41 U.S.C. 3306 , relating to a supply chain risk, or where supply chain risk considerations are included in the executive agency's determination of whether a source is a responsible source;
(2) The consideration of proposals for and issuance of a task or delivery order for a covered article, as provided in 41 U.S.C. 4106(d)(3) , where the task or delivery order contract includes a contract clause establishing a requirement relating to a supply chain risk;
(3) Any contract action involving a contract for a covered article where the contract includes a clause establishing requirements relating to a supply chain risk; or
(4) Any other procurement in a category of procurements determined appropriate by the Federal Acquisition Regulatory Council, with the advice of the FASC.

Covered procurement action means any of the following actions, if the action takes place in the course of conducting a covered procurement:

(1) The exclusion of a source that fails to meet qualification requirements established under 41 U.S.C. 3311 , for the purpose of reducing supply chain risk in the acquisition or use of covered articles;
(2) The exclusion of a source that fails to achieve an acceptable rating with regard to an evaluation factor providing for the consideration of supply chain risk in the evaluation of proposals for the award of a contract or the issuance of a task or delivery order;
(3) The determination that a source is not a responsible source, based on considerations of supply chain risk; or
(4) The decision to withhold consent for a contractor to subcontract with a particular source or to direct a contractor to exclude a particular source from consideration for a subcontract under the contract.

Executive agency means:

(1) An executive department specified in 5 U.S.C. 101 ;
(2) A military department specified in 5 U.S.C. 102 ;
(3) An independent establishment as defined in 5 U.S.C. 104(1) ; and
(4) A wholly owned Government corporation fully subject to chapter 91 of title 31, United States Code.

Exclusion order means an order issued pursuant to 41 U.S.C. 1323(c)(5) that requires the exclusion of one or more sources or covered articles from executive agency procurement actions.

Information and communications technology means:

(1) Information technology as defined in 40 U.S.C. 11101 ;
(2) Information systems, as defined in 44 U.S.C. 3502 ; and
(3) Telecommunications equipment and telecommunications services, as those terms are defined in section 3 of the Communications Act of 1934 (47 U.S.C. 153 ).

Information technology has the definition provided in 40 U.S.C. 11101 .

Intelligence Community includes the following:

(1) The Office of the Director of National Intelligence;
(2) The Central Intelligence Agency;
(3) The National Security Agency;
(4) The Defense Intelligence Agency;
(5) The National Geospatial-Intelligence Agency;
(6) The National Reconnaissance Office;
(7) Other offices within the Department of Defense for the collection of specialized national intelligence through reconnaissance programs;
(8) The intelligence elements of the Army, the Navy, the Air Force, the Marine Corps, the Coast Guard, the Federal Bureau of Investigation, the Drug Enforcement Administration, and the Department of Energy;
(9) The Bureau of Intelligence and Research of the Department of State;
(10) The Office of Intelligence and Analysis of the Department of the Treasury;
(11) The Office of Intelligence and Analysis of the Department of Homeland Security;
(12) Such other elements of any department or agency as may be designated by the President, or designated jointly by the Director of National Intelligence and the head of the department or agency concerned, as an element of the Intelligence Community.

National security system has the definition provided in 44 U.S.C. 3552 .

Removal order means an order issued pursuant to 41 U.S.C. 1323(c)(5) that requires the removal of one or more covered articles from executive agency information systems.

Responsible source means a responsible prospective contractor and subcontractors, at any tier, as defined in part 9 of the Federal Acquisition Regulation (48 CFR part 9).

Source means a non-Federal supplier, or potential supplier, of products or services, at any tier.

Supply chain risk means the risk that any person may sabotage, maliciously introduce unwanted functionality, extract data, or otherwise manipulate the design, integrity, manufacturing, production, distribution, installation, operation, maintenance, disposition, or retirement of covered articles so as to surveil, deny, disrupt, or otherwise manipulate the function, use, or operation of the covered articles or information stored or transmitted by or through covered articles.

Supply chain risk information includes, but is not limited to, information that describes or identifies:

(1) Functionality and features of covered articles, including access to data and information system privileges;
(2) The user environment where a covered article is used or installed;
(3) The ability of a source to produce and deliver covered articles as expected;
(4) Foreign control of, or influence over, a source or covered article (e.g., foreign ownership, personal and professional ties between a source and any foreign entity, legal regime of any foreign country in which a source is headquartered or conducts operations);
(5) Implications to government mission(s) or assets, national security, homeland security, or critical functions associated with use of a source or covered article;
(6) Vulnerability of Federal systems, programs, or facilities;
(7) Market alternatives to the covered source;
(8) Potential impact or harm caused by the possible loss, damage, or compromise of a product, material, or service to an organization's operations or mission;
(9) Likelihood of a potential impact or harm, or the exploitability of a system;
(10) Security, authenticity, and integrity of covered articles and their supply and compilation chain;
(11) Capacity to mitigate risks identified;
(12) Factors that may reflect upon the reliability of other supply chain risk information; and
(13) Any other considerations that would factor into an analysis of the security, integrity, resilience, quality, trustworthiness, or authenticity of covered articles or sources.

41 C.F.R. §201-1.101

86 FR 47587, 9/27/2021