<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Engrossed-in-House" dms-id="H4DDBF57A8B62481B83FE1F46883BFDF5" public-private="public" key="H" bill-type="olc" stage-count="1">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 21 EH: Federal Risk and Authorization Management Program Authorization Act of 2021</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date></dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="no">I</distribution-code>
<congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session>
<legis-num display="yes">H. R. 21</legis-num>
<current-chamber display="no">IN THE HOUSE OF REPRESENTATIVES</current-chamber>
<legis-type>AN ACT</legis-type>
<official-title display="yes">To enhance the innovation, security, and availability of cloud computing products and services used in the Federal Government by establishing the Federal Risk and Authorization Management Program within the General Services Administration and by establishing a risk management, authorization, and continuous monitoring process to enable the Federal Government to leverage cloud computing products and services using a risk-based approach consistent with the Federal Information Security Modernization Act of 2014 and cloud-based operations, and for other purposes.</official-title>
</form>
<legis-body id="H7FD50848E0134A77A2D5F162432C1AB5" style="OLC">
<section id="H4612CE3373814A0CAE0CF9F5EB2CC5FC" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Federal Risk and Authorization Management Program Authorization Act of 2021</short-title></quote> or the <quote><short-title>FedRAMP Authorization Act</short-title></quote>.</text></section> <section id="H1E7E9341B4A5476D9D6786CC02117B4C"><enum>2.</enum><header>Codification of the FedRAMP program</header> <subsection id="H2607927F436C4BE6A5C50F1D6C7056B4"><enum>(a)</enum><header>Amendment</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">Chapter 36</external-xref> of title 44, United States Code, is amended by adding at the end the following new sections:</text>
<quoted-block id="HAC7F3D38474445C5BADAA4D8FE120255" style="USC">
<section id="HEEA3EF2301DA4ACA8703C9DA1DCD0B73"><enum>3607.</enum><header>Federal Risk and Authorization Management Program</header>
<subsection id="H4C2C757D792F4040B27FFDDE7EF9F82A"><enum>(a)</enum><header>Establishment</header><text>There is established within the General Services Administration the Federal Risk and Authorization Management Program. The Administrator of General Services, in accordance with section 3612, shall establish a governmentwide program that provides the authoritative standardized approach to security assessment and authorization for cloud computing products and services that process unclassified information used by agencies.</text></subsection> <subsection id="H2150D537A18640ADAA28D1D0449B7A1A" commented="no"><enum>(b)</enum><header>Components of FedRAMP</header><text display-inline="yes-display-inline">The Joint Authorization Board and the FedRAMP Program Management Office are established as components of FedRAMP. </text></subsection></section>
<section id="HDF8D978FCB9E45B6BA5BB22708E1DC01"><enum>3608.</enum><header>FedRAMP Program Management Office</header>
<subsection id="HF3246CA3CBB245D589C3E1CE7C1AD79D"><enum>(a)</enum><header>GSA duties</header>
<paragraph id="HC3A88A592C114726899F9FCE33D25DB3"><enum>(1)</enum><header>Roles and responsibilities</header><text>The Administrator of General Services shall—</text> <subparagraph id="HB0D3C2B40F31458683C885C7AB7E1B22"><enum>(A)</enum><text display-inline="yes-display-inline">determine the categories and characteristics of cloud computing products and services that are within the jurisdiction of FedRAMP and that require a FedRAMP authorization or a FedRAMP provisional authorization;</text></subparagraph>
<subparagraph id="H040127ED61DD4ADDBCA3B5BCC4087AF3"><enum>(B)</enum><text display-inline="yes-display-inline">develop, coordinate, and implement a process for the FedRAMP Program Management Office, the Joint Authorization Board, and agencies to review security assessments of cloud computing products and services pursuant to subsections (b) and (c) of section 3611, and appropriate oversight of continuous monitoring of cloud computing products and services; and</text></subparagraph> <subparagraph id="H2968AA38EABA47288600D4D7856289E3" commented="no"><enum>(C)</enum><text>ensure the continuous improvement of FedRAMP. </text></subparagraph></paragraph>
<paragraph id="HFD2739F28D9D4654B8A8B8B76B26C973"><enum>(2)</enum><header>Implementation</header><text>The Administrator shall oversee the implementation of FedRAMP, including—</text> <subparagraph id="H806BA41657634AE2829F639325144E26"><enum>(A)</enum><text>appointing a Program Director to oversee the FedRAMP Program Management Office;</text></subparagraph>
<subparagraph id="H6C5517DD27FA49D79473EC653A3026B5"><enum>(B)</enum><text>hiring professional staff as may be necessary for the effective operation of the FedRAMP Program Management Office, and such other activities as are essential to properly perform critical functions;</text></subparagraph> <subparagraph id="HA3ED078045F944C39BB5658C321E25BA"><enum>(C)</enum><text>entering into interagency agreements to detail personnel on a reimbursable or non-reimbursable basis to assist the FedRAMP Program Management Office and the Joint Authorization Board in discharging the responsibilities of the Office under this section; and</text></subparagraph>
<subparagraph id="H6E3628D4A1F3440FAE5DCABC0AEFE0A0"><enum>(D)</enum><text>such other actions as the Administrator may determine necessary to carry out this section.</text></subparagraph></paragraph></subsection> <subsection id="HA7864F310833444C9C5655203478FA36"><enum>(b)</enum><header>Duties</header><text>The FedRAMP Program Management Office shall have the following duties:</text>
<paragraph id="HD7F19CBE0A5946AFB43DEC683AA2E3EC"><enum>(1)</enum><text>Provide guidance to independent assessment organizations, validate the independent assessments, and apply the requirements and guidelines adopted in section 3609(c)(5).</text></paragraph> <paragraph id="H43F64610A82D402D877B62E9BB27CA27" commented="no"><enum>(2)</enum><text>Oversee and issue guidelines regarding the necessary requirements for accreditation of third-party organizations seeking to be awarded accreditation as independent assessment organizations, including qualifications, roles, and responsibilities of independent assessment organizations.</text></paragraph>
<paragraph id="H411584DA27D342E0B2862F749A3F5344"><enum>(3)</enum><text display-inline="yes-display-inline">Develop templates and other materials to support the Joint Authorization Board and agencies in the authorization of cloud computing products and services to increase the speed, effectiveness, and transparency of the authorization process, consistent with standards defined by the National Institute of Standards and Technology.</text></paragraph> <paragraph id="HAC33F98AEAAC4EC99533A6C1446FA6AD"><enum>(4)</enum><text>Establish and maintain a public comment process for proposed guidance before the issuance of such guidance by FedRAMP.</text></paragraph>
<paragraph id="H7664446419B04A65980B5518A33C9931"><enum>(5)</enum><text display-inline="yes-display-inline">Review any authorization to operate issued by an agency to determine if the authorization meets the requirements and guidelines adopted in section 3609(c)(5).</text></paragraph> <paragraph id="H8A890334DEC3481EBE12968D8E9CC1B0"><enum>(6)</enum><text>Establish frameworks for agencies to use authorization packages processed by the FedRAMP Program Management Office and Joint Authorization Board.</text></paragraph>
<paragraph id="H8464752BECC94524A980B0A1A983FBE0"><enum>(7)</enum><text>Coordinate with the Secretary of Defense and the Secretary of Homeland Security to establish a framework for continuous monitoring under section 3553 and agency reports required under section 3554. </text></paragraph> <paragraph id="H54B7F300C1804409A922B70314A0E16B"><enum>(8)</enum><text>Establish a centralized and secure repository to collect and share necessary data, including security authorization packages, from the Joint Authorization Board and agencies to enable better sharing and reuse of such packages across agencies.</text></paragraph></subsection>
<subsection id="H6CC05FE2D5BB4593820B5C31ACEBD53E"><enum>(c)</enum><header>Evaluation of automation procedures</header>
<paragraph id="H3C2A83876B44404B92C39977805B0857"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The FedRAMP Program Management Office shall assess and evaluate available automation capabilities and procedures to improve the efficiency and effectiveness of the issuance of FedRAMP authorizations and FedRAMP provisional authorizations, including continuous monitoring of cloud computing products and services.</text></paragraph> <paragraph id="H34E6FDF3E8AF4D499D2CCCA3976A17D2"><enum>(2)</enum><header>Means for automation</header><text>Not later than 1 year after the date of the enactment of this section, and updated annually thereafter, the FedRAMP Program Management Office shall establish a means for the automation of security assessments and reviews.</text></paragraph></subsection>
<subsection id="HC1D030271DF8423EB1F5A5E29F1EC22E"><enum>(d)</enum><header>Metrics for authorization</header><text>The FedRAMP Program Management Office shall establish annual metrics regarding the time and quality of the assessments necessary for completion of a FedRAMP authorization process in a manner that can be consistently tracked over time in conjunction with the periodic testing and evaluation process pursuant to section 3554 in a manner that minimizes the agency reporting burden.</text></subsection></section> <section id="H30A3BFED5E1C4C558E77178293C93ADF"><enum>3609.</enum><header>Joint Authorization Board</header> <subsection id="HB9BD27ACEED545BAB71F54CEB1DA3A1B"><enum>(a)</enum><header>Establishment</header><text>The Joint Authorization Board shall consist of cloud computing experts, appointed by the Director in consultation with the Administrator, from each of the following:</text>
<paragraph id="H5648CD7D8DA942E7B3104413CEB2D3BB"><enum>(1)</enum><text>The Department of Defense.</text></paragraph> <paragraph id="H6C0750CDB5C84573AF4A6255CCB38F35"><enum>(2)</enum><text>The Department of Homeland Security.</text></paragraph>
<paragraph id="HEBA4314A49C645619D0F1DD72E58B27E"><enum>(3)</enum><text>The General Services Administration.</text></paragraph> <paragraph id="HCC9658461D04458B8E90DF12A7966F32"><enum>(4)</enum><text>Such other agencies as determined by the Director, in consultation with the Administrator.</text></paragraph></subsection>
<subsection id="H18AE131B6AD546759E633C33E93721C7"><enum>(b)</enum><header>Issuance of FedRAMP provisional authorizations</header><text display-inline="yes-display-inline">The Joint Authorization Board shall conduct security assessments of cloud computing products and services and issue FedRAMP provisional authorizations to cloud service providers that meet the requirements and guidelines established in subsection (c)(5).</text></subsection> <subsection id="HF5324D36652742D581DDE7855F5BA21C"><enum>(c)</enum><header>Duties</header><text>The Joint Authorization Board shall—</text>
<paragraph id="H43DCCA1AD920475995EE4CF0933B9639"><enum>(1)</enum><text display-inline="yes-display-inline">develop and make publicly available on a website, determined by the Administrator, criteria for prioritizing and selecting cloud computing products and services to be assessed by the Joint Authorization Board;</text></paragraph> <paragraph id="H0591C3BDBC2748598A863505B9C70902"><enum>(2)</enum><text display-inline="yes-display-inline">provide regular updates to applicant cloud service providers on the status of any cloud computing product or service during the assessment and authorization process of the Joint Authorization Board;</text></paragraph>
<paragraph id="H8E34EDB1D3864918A72FC251C769D831" commented="no"><enum>(3)</enum><text display-inline="yes-display-inline">review and validate cloud computing products and services and materials submitted by independent assessment organizations or any documentation determined to be necessary by the Joint Authorization Board to evaluate the system security of a cloud computing product or service;</text></paragraph> <paragraph id="H67FDA0E844FD490DB0E7D005C47969DE"><enum>(4)</enum><text>in consultation with the FedRAMP Program Management Office, serve as a resource for best practices to accelerate the process for obtaining a FedRAMP authorization or FedRAMP provisional authorization;</text></paragraph>
<paragraph id="H6349CE6D201F462ABE17C70E2E6C21D6"><enum>(5)</enum><text display-inline="yes-display-inline">establish requirements and guidelines for security assessments of cloud computing products and services, consistent with standards defined by the National Institute of Standards and Technology, to be used by the Joint Authorization Board and agencies;</text></paragraph> <paragraph id="HD178C939720B447B8626A413C75CE4C5"><enum>(6)</enum><text>perform such other roles and responsibilities as the Administrator may assign, in consultation with the FedRAMP Program Management Office and members of the Joint Authorization Board; and</text></paragraph>
<paragraph id="H99E7C1E900784E0BA8D5C87D451631FF"><enum>(7)</enum><text display-inline="yes-display-inline">establish metrics and goals for reviews and activities associated with issuing FedRAMP provisional authorizations and provide to the FedRAMP Program Management Office.</text></paragraph></subsection> <subsection id="H30176D5F99284ED385D876205E2BE754"><enum>(d)</enum><header>Determinations of demand for cloud computing products and services</header><text display-inline="yes-display-inline">The Joint Authorization Board shall consult with the Chief Information Officers Council established in section 3603 to establish a process, that shall be made available on a public website, for prioritizing and accepting the cloud computing products and services to be granted a FedRAMP provisional authorization.</text></subsection>
<subsection id="H98B88C2276184DF9BC0AB496650E82C0"><enum>(e)</enum><header>Detail of personnel</header><text>To assist the Joint Authorization Board in discharging the responsibilities under this section, personnel of agencies may be detailed to the Joint Authorization Board for the performance of duties described under subsection (c).</text></subsection></section> <section id="H3AFECC650E1F43D08504D4DA2A32BE9E" commented="no"><enum>3610.</enum><header>Independent assessment organizations</header> <subsection id="H455081841DD9442EB153754347B8D5B9" commented="no"><enum>(a)</enum><header>Requirements for accreditation</header><text>The Joint Authorization Board shall determine the requirements for the accreditation of a third-party organization seeking to be accredited as an independent assessment organization, ensuring adequate implementation of section 3609. Such requirements may include developing or requiring certification programs for individuals employed by the third-party organization seeking accreditation. The Program Director of the FedRAMP Program Management Office shall accredit any third-party organization that meets the requirements for accreditation. </text></subsection>
<subsection id="H250039D474764867BE74E4D73ADE04CB" commented="no"><enum>(b)</enum><header>Assessment</header><text>An independent assessment organization may assess, validate, and attest to the quality and compliance of security assessment materials provided by cloud service providers as part of the FedRAMP authorization or the FedRAMP provisional authorization process.</text></subsection></section> <section id="HAED2FA59FCF54E528811B4C76EC90434"><enum>3611.</enum><header>Roles and responsibilities of agencies</header> <subsection id="H94CC96493F0C4EBE8EF9F4B7EF75D258"><enum>(a)</enum><header>In general</header><text>In implementing the requirements of FedRAMP, the head of each agency shall, consistent with guidance issued by the Director pursuant to section 3612—</text>
<paragraph id="H2DEE77DAF5A54FD795450D35CA1DC8D8"><enum>(1)</enum><text display-inline="yes-display-inline">create policies to ensure cloud computing products and services used by the agency meet FedRAMP security requirements and other risk-based performance requirements as defined by the Director;</text></paragraph> <paragraph id="H6E1B2474CA3341F2A2FE429C73A1FD81"><enum>(2)</enum><text>issue agency-specific authorizations to operate for cloud computing services in compliance with section 3554;</text></paragraph>
<paragraph id="HF3F1B439913F4BC7A9663BBC95A6AB37" commented="no"><enum>(3)</enum><text display-inline="yes-display-inline">confirm whether there is a FedRAMP authorization or FedRAMP provisional authorization in the cloud security repository established under section 3608(b)(8) before beginning the process to award a FedRAMP authorization or a FedRAMP provisional authorization for a cloud computing product or service;</text></paragraph> <paragraph id="HE33FE14BAA704440B03A49462553F22F" commented="no"><enum>(4)</enum><text display-inline="yes-display-inline">to the extent practicable, for any cloud computing product or service the agency seeks to authorize that has received a FedRAMP authorization or FedRAMP provisional authorization, use the existing assessments of security controls and materials within the authorization package; and</text></paragraph>
<paragraph id="HF88F5DB6414645CE84476A98930F4CA4"><enum>(5)</enum><text>provide data and information required to the Director pursuant to section 3612 to determine how agencies are meeting metrics as defined by the FedRAMP Program Management Office.</text></paragraph></subsection> <subsection id="H4E7404E53FD5452284E2AB0566C58F1B"><enum>(b)</enum><header>Submission of policies required</header><text>Not later than 6 months after the date of the enactment of this section, the head of each agency shall submit to the Director the policies created pursuant to subsection (a)(1) for review and approval.</text></subsection>
<subsection id="HA56B13BE0F504D0896F0A7DB22365E85" commented="no"><enum>(c)</enum><header>Submission of authorizations To operate required</header><text display-inline="yes-display-inline">Upon issuance of an agency authorization to operate, the head of the agency shall provide a copy of the authorization to operate letter and any supplementary information required pursuant to section 3608(b) to the FedRAMP Program Management Office.</text></subsection> <subsection id="H65D52AA50A7448D1B7A6370CA73F4EDC"><enum>(d)</enum><header>Presumption of adequacy</header> <paragraph id="H882516C0B48844A3ACDD539174C18256" commented="no"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The assessment of security controls and materials within the authorization package for a FedRAMP authorization or FedRAMP provisional authorization shall be presumed adequate for use in an agency authorization to operate cloud computing products and services.</text></paragraph>
<paragraph id="HDD89416138E746FE80144E4B0ECD7D60"><enum>(2)</enum><header>Information security requirements</header><text>The presumption under paragraph (1) does not modify or alter the responsibility of any agency to ensure compliance with subchapter II of chapter 35 for any cloud computing products or services used by the agency.</text></paragraph></subsection></section> <section id="H389DE873DB6442C797FD5CADEA2B3A90"><enum>3612.</enum><header>Roles and responsibilities of the Office of Management and Budget</header><text display-inline="no-display-inline">The Director shall have the following duties:</text>
<paragraph id="HD7828FB2131F4F8F9755C8B000620C50" commented="no"><enum>(1)</enum><text display-inline="yes-display-inline">Issue guidance to ensure that an agency does not operate a Federal Government cloud computing product or service using Government data without an authorization to operate issued by the agency that meets the requirements of subchapter II of chapter 35 and the FedRAMP authorization or FedRAMP provisional authorization.</text></paragraph> <paragraph id="H1C797E98FB874EE288A5A4DD76223439"><enum>(2)</enum><text>Ensure agencies are in compliance with any guidance or other requirements issued related to FedRAMP.</text></paragraph>
<paragraph id="H9AC340DB30084364A120B996A0B3CBA9"><enum>(3)</enum><text>Review, analyze, and update guidance on the adoption, security, and use of cloud computing services used by agencies.</text></paragraph> <paragraph id="H7807D1FBC478418DB457405BE2121C29"><enum>(4)</enum><text>Ensure the Joint Authorization Board is in compliance with section 3609(c).</text></paragraph>
<paragraph id="H16DB08B5E6424CD7A9A65B6425F8340D" commented="no"><enum>(5)</enum><text>Adjudicate disagreements between the Joint Authorization Board and cloud service providers seeking a FedRAMP provisional authorization.</text></paragraph> <paragraph id="HDC39CC1C29F04FB7A72BA9E3B36B1599"><enum>(6)</enum><text display-inline="yes-display-inline">Promulgate regulations on the role of FedRAMP authorizations and FedRAMP provisional authorizations in agency acquisition of cloud computing products and services that process unclassified information.</text></paragraph></section>
<section id="H041C76628EA54B91AAAF8073CD205F8A"><enum>3613.</enum><header>Authorization of appropriations for FEDRAMP</header><text display-inline="no-display-inline">There is authorized to be appropriated $20,000,000 each year for the FedRAMP Program Management Office and the Joint Authorization Board.</text></section> <section id="H12224F3A1463434A8C3EA1C631E8F302"><enum>3614.</enum><header>Reports to Congress; GAO Report</header> <subsection id="H7BCE52AD7C604FCD9E56D667FC959F2D"><enum>(a)</enum><header>Reports to Congress</header><text display-inline="yes-display-inline">Not later than 12 months after the date of the enactment of this section, and annually thereafter, the Director shall submit to the Committee on Oversight and Reform of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report that includes the following:</text>
<paragraph id="HA029EE0C81F14D2CAFE47847337C52BF" commented="no"><enum>(1)</enum><text>The status, efficiency, and effectiveness of FedRAMP Program Management Office and agencies during the preceding year in supporting the speed, effectiveness, sharing, reuse, and security of authorizations to operate for cloud computing products and services, including progress towards meeting the metrics adopted by the FedRAMP Program Management Office pursuant to section 3608(d) and the Joint Authorization Board pursuant to section 3609(c)(5). </text></paragraph> <paragraph id="H42297EE6462640AA825079F8AFE7FA1C"><enum>(2)</enum><text display-inline="yes-display-inline">Data on FedRAMP authorizations and FedRAMP provisional authorizations.</text></paragraph>
<paragraph id="H925D9AB8AF344870A5E17B63B0B5CB7C"><enum>(3)</enum><text display-inline="yes-display-inline">The average length of time for the Joint Authorization Board to review applications for and issue FedRAMP provisional authorizations.</text></paragraph> <paragraph id="H13852BCE7C8048EC8C1BD6267DB8AE43"><enum>(4)</enum><text display-inline="yes-display-inline">The average length of time for the FedRAMP Program Management Office to review authorizations to operate.</text></paragraph>
<paragraph id="HD492934D86E24214938DC5FA74412581"><enum>(5)</enum><text display-inline="yes-display-inline">The number of FedRAMP authorizations and FedRAMP provisional authorizations issued for the previous year.</text></paragraph> <paragraph id="H4A23266287804373B19E65EE87E1849A"><enum>(6)</enum><text>A review of progress made during the preceding year in advancing automation techniques to securely automate FedRAMP processes and to accelerate reporting as described in this section.</text></paragraph>
<paragraph id="H87BF835F7ADA476AA15CBE9305C19216"><enum>(7)</enum><text>The number and characteristics of authorized cloud computing products and services in use at each agency consistent with guidance provided by the Director in section 3612.</text></paragraph> <paragraph id="HBDD162B9D9354E63BB8224D66ACDCEEA"><enum>(8)</enum><text display-inline="yes-display-inline">The cost incurred by agencies and cloud service providers related to the issuance of FedRAMP authorizations and FedRAMP provisional authorizations, including information responsive to the report required in subsection (b). </text></paragraph></subsection>
<subsection id="H92E16C8DB9E144AF805757574BB49216"><enum>(b)</enum><header>GAO report</header><text display-inline="yes-display-inline">Not later than 6 months after the date of the enactment of this section, the Comptroller General of the United States shall publish a report that includes an assessment of the cost incurred by agencies and cloud service providers related to the issuance of FedRAMP authorizations and FedRAMP provisional authorizations. </text></subsection></section> <section id="H32DA31361321406583CAC0A4CFBFEF34"><enum>3615.</enum><header>Federal Secure Cloud Advisory Committee</header> <subsection id="HE1E88B5549144EF59CFA11691E4334A5"><enum>(a)</enum><header>Establishment, purposes, and duties</header> <paragraph id="H1978EE456F1749B58D2A8646A42A97FB"><enum>(1)</enum><header>Establishment</header><text>There is established a Federal Secure Cloud Advisory Committee (referred to in this section as the <quote>Committee</quote>) to ensure effective and ongoing coordination of agency adoption, use, authorization, monitoring, acquisition, and security of cloud computing products and services to enable agency mission and administrative priorities.</text></paragraph>
<paragraph id="H3BBCD19DE47047EB8F94536E142D314E"><enum>(2)</enum><header>Purposes</header><text>The purposes of the Committee are the following:</text> <subparagraph id="H655A5266B4234641874704A9CE53807E"><enum>(A)</enum><text>To examine the operations of FedRAMP and determine ways that authorization processes can continuously be improved, including the following:</text>
<clause id="HFE8BFF62F382425BA5BC48C41A19E4A1"><enum>(i)</enum><text display-inline="yes-display-inline">Measures to increase agency re-use of FedRAMP provisional authorizations.</text></clause> <clause id="H63294776C901424CA691E456D03E0BD2"><enum>(ii)</enum><text display-inline="yes-display-inline">Proposed actions that can be adopted to reduce the cost of FedRAMP authorizations and FedRAMP provisional authorizations for cloud service providers.</text></clause>
<clause id="H62B758417976483D834B4FBE51ED4DB1"><enum>(iii)</enum><text display-inline="yes-display-inline">Measures to increase the number of FedRAMP authorizations and FedRAMP provisional authorizations for cloud computing services offered by small businesses (as defined by section 3(a) of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632(a)</external-xref>).</text></clause></subparagraph> <subparagraph id="H0C6CC58D7BF54ADDACFA230BB76FF68A"><enum>(B)</enum><text>Collect information and feedback on agency compliance with and implementation of FedRAMP requirements.</text></subparagraph>
<subparagraph id="HDD4AA6BBB2034939980FDAC5BA9EA5AE"><enum>(C)</enum><text>Serve as a forum that facilitates communication and collaboration among the FedRAMP stakeholder community.</text></subparagraph></paragraph> <paragraph id="HD8E030D57A684653BBF3AB88A0B8FFD5"><enum>(3)</enum><header>Duties</header><text display-inline="yes-display-inline">The duties of the Committee are, at a minimum, to provide advice and recommendations to the Administrator, the Joint Authorization Board, and to agencies on technical, financial, programmatic, and operational matters regarding secure adoption of cloud computing products and services.</text></paragraph></subsection>
<subsection id="HB5760D7FF4E040E6BD4829ABD28BAD8C"><enum>(b)</enum><header>Members</header>
<paragraph id="HAF44C6ABB6504EAB82005690E0D69E13"><enum>(1)</enum><header>Composition</header><text>The Committee shall be comprised of not more than 15 members who are qualified representatives from the public and private sectors, appointed by the Administrator, in consultation with the Administrator of the Office of Electronic Government, as follows:</text> <subparagraph id="HB606E8382A84452DA29C4A40427EEDFC"><enum>(A)</enum><text>The Administrator or the Administrator’s designee, who shall be the Chair of the Committee.</text></subparagraph>
<subparagraph id="HA0A73729811D4DA2872E23C49A591432"><enum>(B)</enum><text>At least one representative each from the Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology.</text></subparagraph> <subparagraph id="HA65737B2C7BB42058F8EF1272F033250"><enum>(C)</enum><text>At least two officials who serve as the Chief Information Security Officer within an agency, who shall be required to maintain such a position throughout the duration of their service on the Committee.</text></subparagraph>
<subparagraph id="H27680D9A08BF442F96B9EE6F8ED62158"><enum>(D)</enum><text>At least one official serving as Chief Procurement Officer (or equivalent) in an agency, who shall be required to maintain such a position throughout the duration of their service on the Committee.</text></subparagraph> <subparagraph id="H272B7A99B60A4280A6158FE136E36E53"><enum>(E)</enum><text>At least one individual representing an independent assessment organization.</text></subparagraph>
<subparagraph id="H5A5538FAF7F24F6F85B7EC8901F942D1"><enum>(F)</enum><text>No fewer than five representatives from unique businesses that primarily provide cloud computing services or products, including at least two representatives from a small business (as defined by section 3(a) of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632(a)</external-xref>)).</text></subparagraph> <subparagraph id="HE4DE46B57F244F79A8CF3E979A514E8E"><enum>(G)</enum><text display-inline="yes-display-inline">At least two other Government representatives as the Administrator determines to be necessary to provide sufficient balance, insights, or expertise to the Committee.</text></subparagraph></paragraph>
<paragraph id="H5BCDF00741704FB79E0A10C9674F36A0"><enum>(2)</enum><header>Deadline for appointment</header><text>Each member of the Committee shall be appointed not later than 30 days after the date of the enactment of this section.</text></paragraph> <paragraph id="HF28E820A97E949FFBC89E81F9071F122"><enum>(3)</enum><header>Period of appointment; vacancies</header> <subparagraph id="HE4A55F2C342A48768A809E7D3E303D55"><enum>(A)</enum><header>In general</header><text>Each non-Federal member of the Committee shall be appointed for a term of 3 years, except that the initial terms for members may be staggered 1-, 2-, or 3-year terms to establish a rotation in which one-third of the members are selected each year. Any such member may be appointed for not more than 2 consecutive terms.</text></subparagraph>
<subparagraph id="HA9F166491C6940649E781796A2E40642"><enum>(B)</enum><header>Vacancies</header><text>Any vacancy in the Committee shall not affect its powers, but shall be filled in the same manner in which the original appointment was made. Any member appointed to fill a vacancy occurring before the expiration of the term for which the member’s predecessor was appointed shall be appointed only for the remainder of that term. A member may serve after the expiration of that member’s term until a successor has taken office.</text></subparagraph></paragraph></subsection> <subsection id="H538DD1C5EF94453DBEB26FF0B036EA96"><enum>(c)</enum><header>Meetings and rules of procedures</header> <paragraph id="HFC028D3F103A4489AAD4C983B8A2C06A"><enum>(1)</enum><header>Meetings</header><text>The Committee shall hold not fewer than three meetings in a calendar year, at such time and place as determined by the Chair.</text></paragraph>
<paragraph id="H0E459D1B75D14466A8FF9845AF458782"><enum>(2)</enum><header>Initial meeting</header><text>Not later than 120 days after the date of the enactment of this section, the Committee shall meet and begin the operations of the Committee.</text></paragraph> <paragraph id="H8B725B4FD0D449B58C50212FB2FF84B1"><enum>(3)</enum><header>Rules of procedure</header><text>The Committee may establish rules for the conduct of the business of the Committee, if such rules are not inconsistent with this section or other applicable law.</text></paragraph></subsection>
<subsection id="HFA980A942C8F495B912CD7696B785CF2" commented="no"><enum>(d)</enum><header>Employee status</header>
<paragraph id="HB85B8ECE013A493DADE0FED7FAF12520" commented="no"><enum>(1)</enum><header>In general</header><text>A member of the Committee (other than a member who is appointed to the Committee in connection with another Federal appointment) shall not be considered an employee of the Federal Government by reason of any service as such a member, except for the purposes of section 5703 of title 5, relating to travel expenses.</text></paragraph> <paragraph id="HC21D6C6CD88244E3A4EFE9C050006426" commented="no"><enum>(2)</enum><header>Pay not permitted</header><text display-inline="yes-display-inline">A member of the Committee covered by paragraph (1) may not receive pay by reason of service on the Committee.</text></paragraph></subsection>
<subsection id="H9FD86DD77D3849DFBC3962A3A0928931" commented="no"><enum>(e)</enum><header>Applicability to the Federal Advisory Committee Act</header><text display-inline="yes-display-inline">Section 14 of the Federal Advisory Committee Act (5 U.S.C. App.) shall not apply to the Committee.</text></subsection> <subsection id="H8E1F1D1B0BD34E089ADDCE077E37230B"><enum>(f)</enum><header>Hearings and evidence</header><text>The Committee, or on the authority of the Committee, any subcommittee, may, for the purposes of carrying out this section, hold hearings, sit and act at such times and places, take testimony, receive evidence, and administer oaths.</text></subsection>
<subsection id="HD8DC882F6B984FA3B2757066F4FF9AF7"><enum>(g)</enum><header>Contracting</header><text>The Committee, may, to such extent and in such amounts as are provided in appropriation Acts, enter into contracts to enable the Committee to discharge its duties under this section.</text></subsection> <subsection id="H83E291E984384625A578493CB0B14C84"><enum>(h)</enum><header>Information from Federal agencies</header> <paragraph id="H53A0BDC6A0AF4690945B8108317DB258"><enum>(1)</enum><header>In general</header><text>The Committee is authorized to secure directly from any executive department, bureau, agency, board, commission, office, independent establishment, or instrumentality of the Government, information, suggestions, estimates, and statistics for the purposes of the Committee. Each department, bureau, agency, board, commission, office, independent establishment, or instrumentality shall, to the extent authorized by law, furnish such information, suggestions, estimates, and statistics directly to the Committee, upon request made by the Chair, the Chair of any subcommittee created by a majority of the Committee, or any member designated by a majority of the Committee.</text></paragraph>
<paragraph id="H2807697D18F74E489B942392E5A21A5B"><enum>(2)</enum><header>Receipt, handling, storage, and dissemination</header><text>Information may only be received, handled, stored, and disseminated by members of the Committee and its staff consistent with all applicable statutes, regulations, and Executive orders.</text></paragraph></subsection> <subsection id="H12D3BE88A7FD45BEA0B1F84340FB9C07"><enum>(i)</enum><header>Detail of employees</header><text>Any Federal Government employee may be detailed to the Committee without reimbursement from the Committee, and such detailee shall retain the rights, status, and privileges of his or her regular employment without interruption.</text></subsection>
<subsection id="H870A64DCC099440198840A1580064BF6"><enum>(j)</enum><header>Postal services</header><text>The Committee may use the United States mails in the same manner and under the same conditions as agencies.</text></subsection> <subsection id="H9ECCC68738134DBA801683AAC4B3BF94"><enum>(k)</enum><header>Expert and consultant services</header><text>The Committee is authorized to procure the services of experts and consultants in accordance with section 3109 of title 5, but at rates not to exceed the daily rate paid a person occupying a position at Level IV of the Executive Schedule under section 5315 of title 5.</text></subsection>
<subsection id="H93A065C505C44C4D92B45EA80E14726D"><enum>(l)</enum><header>Reports</header>
<paragraph id="H90AF5E4CDA9249E7892436E3DF205B66"><enum>(1)</enum><header>Interim reports</header><text>The Committee may submit to the Administrator and Congress interim reports containing such findings, conclusions, and recommendations as have been agreed to by the Committee.</text></paragraph> <paragraph id="HC8590A26BA0E4C4299BAA26BCAAD1FB7"><enum>(2)</enum><header>Annual reports</header><text>Not later than 18 months after the date of the enactment of this section, and annually thereafter, the Committee shall submit to the Administrator and Congress a final report containing such findings, conclusions, and recommendations as have been agreed to by the Committee.</text></paragraph></subsection></section>
<section id="H48A9020D92554871AB2E575F3A7ABF6F"><enum>3616.</enum><header>Definitions</header>
<subsection id="H8D6E8C1E911242A2BABBB5A2B609BF91"><enum>(a)</enum><header>In general</header><text>Except as provided under subsection (b), the definitions under sections 3502 and 3552 apply to sections 3607 through this section.</text></subsection> <subsection id="H8549F459877B462DA8636E15E965EF6A"><enum>(b)</enum><header>Additional definitions</header><text>In sections 3607 through this section:</text>
<paragraph id="H8EE403B7C40248239A6967B8E52E7EF3"><enum>(1)</enum><header>Administrator</header><text>The term <term>Administrator</term> means the Administrator of General Services.</text></paragraph> <paragraph id="H0796D227E8854B969A6848F28B135859"><enum>(2)</enum><header>Authorization package</header><text>The term <term>authorization package</term>—</text>
<subparagraph id="H9BBF533816C24C6AA7675EF6CFDC4BE7"><enum>(A)</enum><text>means the essential information used to determine whether to authorize the operation of an information system or the use of a designated set of common controls; and</text></subparagraph> <subparagraph id="HE1E6B675A8A248E89311CA99535B6797"><enum>(B)</enum><text>at a minimum, includes the information system security plan, privacy plan, security control assessment, privacy control assessment, and any relevant plans of action and milestones.</text></subparagraph></paragraph>
<paragraph id="HD0E81C1FC32C4A6D810085B5C507B3AF"><enum>(3)</enum><header>Cloud computing</header><text>The term <term>cloud computing</term> has the meaning given that term by the National Institutes of Standards and Technology in NIST Special Publication 800–145 and any amendatory or superseding document thereto.</text></paragraph> <paragraph id="HE82C215F6E3247E7A301F0AA320D1CBE"><enum>(4)</enum><header>Cloud service provider</header><text>The term <term>cloud service provider</term> means an entity offering cloud computing products or services to agencies.</text></paragraph>
<paragraph id="H805A336A26C34435B8F9DDC2E417C136"><enum>(5)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the Office of Management and Budget.</text></paragraph> <paragraph id="H1CF83329C4F8437FAD3F5D73151586B6"><enum>(6)</enum><header>FedRAMP</header><text>The term <term>FedRAMP</term> means the Federal Risk and Authorization Management Program established under section 3607(a).</text></paragraph>
<paragraph id="H4E65348956624BB8823D23F10D264DBC" commented="no"><enum>(7)</enum><header>FedRAMP authorization</header><text display-inline="yes-display-inline">The term <term>FedRAMP authorization</term> means a certification that a cloud computing product or service received from an agency that provides an authorization to operate and the FedRAMP Program Management Office has determined the product or service has completed the FedRAMP authorization process.</text></paragraph> <paragraph id="H8B57A796787C4E059F15CF7A06C3AF9F" commented="no"><enum>(8)</enum><header>FedRAMP program management office</header><text>The term <term>FedRAMP Program Management Office</term> means the office that administers FedRAMP established under section 3607(b).</text></paragraph>
<paragraph id="H3E840B41C0344FCCB48F91C2C80844D2" commented="no"><enum>(9)</enum><header>FedRAMP provisional authorization</header><text>The term <term>FedRAMP provisional authorization</term> means a certification that a cloud computing product or service has received from the Joint Authorization Board that approves a provisional authorization to operate.</text></paragraph> <paragraph id="HFF74308FFD4D4C989EB031D03535AA71" commented="no"><enum>(10)</enum><header>Independent assessment organization</header><text>The term <term>independent assessment organization</term> means a third-party organization accredited by the Program Director of the FedRAMP Program Management Office to undertake conformity assessments of cloud service providers and their products or services.</text></paragraph>
<paragraph id="HAD2B869AED334553A5B53CEA1D064468" commented="no"><enum>(11)</enum><header>Joint Authorization Board</header><text>The term <term>Joint Authorization Board</term> means the Joint Authorization Board established under section 3607(b).</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection> <subsection id="HC6A9194F20B440E5B6A7E24F52573CC5"><enum>(b)</enum><header>Technical and conforming amendment</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">chapter 36</external-xref> of title 44, United States Code, is amended by adding at the end the following new items:</text>
<quoted-block style="USC" id="H774EB033E57241D3A0C9FC1B627A47FA" display-inline="no-display-inline">
<toc regeneration="yes-regeneration">
<toc-entry idref="HEEA3EF2301DA4ACA8703C9DA1DCD0B73" level="section">3607. Federal Risk and Authorization Management Program. </toc-entry>
<toc-entry idref="HDF8D978FCB9E45B6BA5BB22708E1DC01" level="section">3608. FedRAMP Program Management Office. </toc-entry>
<toc-entry idref="H30A3BFED5E1C4C558E77178293C93ADF" level="section">3609. Joint Authorization Board. </toc-entry>
<toc-entry idref="H3AFECC650E1F43D08504D4DA2A32BE9E" level="section">3610. Independent assessment organizations. </toc-entry>
<toc-entry idref="HAED2FA59FCF54E528811B4C76EC90434" level="section">3611. Roles and responsibilities of agencies. </toc-entry>
<toc-entry idref="H389DE873DB6442C797FD5CADEA2B3A90" level="section">3612. Roles and responsibilities of the Office of Management and Budget. </toc-entry>
<toc-entry idref="H041C76628EA54B91AAAF8073CD205F8A" level="section">3613. Authorization of appropriations for FEDRAMP. </toc-entry>
<toc-entry idref="H12224F3A1463434A8C3EA1C631E8F302" level="section">3614. Reports to Congress. </toc-entry>
<toc-entry idref="H32DA31361321406583CAC0A4CFBFEF34" level="section">3615. Federal Secure Cloud Advisory Committee. </toc-entry>
<toc-entry idref="H48A9020D92554871AB2E575F3A7ABF6F" level="section">3616. Definitions.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection>
<subsection id="H91E119E653EB43DE8E79F06D0C13559E"><enum>(c)</enum><header>Sunset</header><text>This Act and any amendment made by this Act shall be repealed on the date that is 10 years after the date of the enactment of this Act.</text></subsection> <subsection id="H86A3271FD3994B16BC98697B44757B70"><enum>(d)</enum><header>Rule of construction</header><text display-inline="yes-display-inline">Nothing in this Act or any amendment made by this Act shall be construed as altering or impairing the authorities of the Director of the Office of Management and Budget or the Secretary of Homeland Security under subchapter II of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code.</text></subsection></section>
</legis-body><attestation><attestation-group><attestation-date date="20210105" chamber="House">Passed the House of Representatives January 5, 2021.</attestation-date><attestor display="no">Cheryl L. Johnson,</attestor><role>Clerk.</role></attestation-group></attestation>
<endorsement display="yes"></endorsement>
</bill> 


