<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Referred-in-Senate" bill-type="olc" dms-id="H294B039577DA4574A2F83311052FBDC1" public-private="public" stage-count="1">
	<form>
		<distribution-code display="yes">IIB</distribution-code>
		<congress>111th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 4098</legis-num>
		<current-chamber display="yes">IN THE SENATE OF THE UNITED
		  STATES</current-chamber>
		<action>
			<action-date date="20100325">March 25, 2010</action-date>
			<action-desc> Received; read twice and referred to the
			 <committee-name committee-id="SSGA00">Committee on Homeland Security and
			 Governmental Affairs</committee-name></action-desc>
		</action>
		<legis-type>AN ACT</legis-type>
		<official-title display="yes">To require the Director of the Office of
		  Management and Budget to issue guidance on the use of peer-to-peer file sharing
		  software to prohibit the personal use of such software by Government employees,
		  and for other purposes.</official-title>
	</form>
	<legis-body id="HAFFEDD92A701448DA7F98A3E5FFDF0F4" style="OLC">
		<section id="HF4461A9520054D96B6FF561E9F9BA3FD" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Secure Federal File Sharing
			 Act</short-title></quote>.</text>
		</section><section id="HED8161EEADF5494C8E9D56BA8E693751"><enum>2.</enum><header>Requirements</header>
			<subsection id="HA825B4BE513F453DA56CD07871F94BFB"><enum>(a)</enum><header>Updated guidance
			 on use of certain software programs</header><text>Not later than 90 days after
			 the date of the enactment of this Act, the Director of the Office of Management
			 and Budget, after consultation with the Federal Chief Information Officers
			 Council, shall issue guidance on the use of peer-to-peer file sharing
			 software—</text>
				<paragraph id="H162299937D8B42E4A8A8FE1D1FFE4AE3"><enum>(1)</enum><text>to prohibit the
			 download, installation, or use by Government employees and contractors of
			 open-network peer-to-peer file sharing software on all Federal computers,
			 computer systems, and networks, including those operated by contractors on the
			 Government’s behalf, unless such software is approved in accordance with
			 procedures under subsection (b); and</text>
				</paragraph><paragraph id="H6E314D052E2D471688E73DBD2927FA2D"><enum>(2)</enum><text display-inline="yes-display-inline">to address the download, installation, or
			 use by Government employees and contractors of such software on home or
			 personal computers as it relates to telework and remotely accessing Federal
			 computers, computer systems, and networks, including those operated by
			 contractors on the Government’s behalf.</text>
				</paragraph></subsection><subsection id="H680C5C44C9954E1AB56C68987C6C6BC8"><enum>(b)</enum><header>Approval process
			 for certain software programs</header><text>Not later than 90 days after the
			 date of the enactment of this Act, the Director of the Office of Management and
			 Budget shall develop a procedure by which the Director, in consultation with
			 the Chief Information Officer, may receive requests from heads of agencies or
			 chief information officers of agencies for approval for use by Government
			 employees and contractors of specific open-network peer-to-peer file sharing
			 software programs that are—</text>
				<paragraph id="HF2D1D52FA19D456BA811D90A79811693"><enum>(1)</enum><text>necessary for the
			 day-to-day business operations of the agency;</text>
				</paragraph><paragraph id="H7FB32E3FA90C4865B4EA508078B25301"><enum>(2)</enum><text>instrumental in
			 completing a particular task or project that directly supports the agency’s
			 overall mission;</text>
				</paragraph><paragraph id="HC88910EBE8A44A5D998506F4D0AF43DD"><enum>(3)</enum><text>necessary for use
			 between, among, or within Federal, State, or local government agencies in order
			 to perform official agency business; or</text>
				</paragraph><paragraph id="H3F295460DC4D402B9F6B24FE407A3AC2"><enum>(4)</enum><text>necessary for use
			 during the course of a law enforcement investigation.</text>
				</paragraph></subsection><subsection id="H593A6F4FD7B447F1A14141F2CD1BF053"><enum>(c)</enum><header>Agency
			 responsibilities</header><text display-inline="yes-display-inline">Not later
			 than 180 days after the date of enactment of this Act, the Director of the
			 Office of Management and Budget shall—</text>
				<paragraph id="HB9FC7B00D7CD4A7EB1A6D43B1EB072E4"><enum>(1)</enum><text>direct agencies to
			 establish or update personal use policies of the agency to be consistent with
			 the guidance issued pursuant to subsection (a);</text>
				</paragraph><paragraph id="H4C1DEF647B97453DA3AF39C216632236"><enum>(2)</enum><text>direct agencies to
			 require any contract awarded by the agency to include a requirement that the
			 contractor comply with the guidance issued pursuant to subsection (a) in the
			 performance of the contract;</text>
				</paragraph><paragraph id="H8442DFA96B1B4541BD5A00286BF002BF"><enum>(3)</enum><text>direct agencies to
			 update their information technology security or ethics training policies to
			 ensure that all employees, including those working for contractors on the
			 Government’s behalf, are aware of the requirements of the guidance required by
			 subsection (a) and the consequences of engaging in prohibited conduct;
			 and</text>
				</paragraph><paragraph id="HA016BDCF54394B609128F2453B79D39A"><enum>(4)</enum><text>direct agencies to
			 ensure that proper security controls are in place to prevent, detect, and
			 remove file sharing software that is prohibited by the guidance issued pursuant
			 to subsection (a) from all Federal computers, computer systems, and networks,
			 including those operated by contractors on the Government’s behalf.</text>
				</paragraph></subsection></section><section id="HA66D42BF3C29498AA55D2D4B8DF5E7A3"><enum>3.</enum><header>Annual
			 report</header><text display-inline="no-display-inline">Not later than 1 year
			 after the date of the enactment of this Act, and annually thereafter, the
			 Director of the Office of Management and Budget shall submit to the Committee
			 on Oversight and Government Reform of the House of Representatives and the
			 Committee on Homeland Security and Governmental Affairs of the Senate a report
			 on the implementation of this Act, including—</text>
			<paragraph id="HBDB94215DB114CBBBE23A6499976E7ED"><enum>(1)</enum><text>a
			 justification for each open-network peer-to-peer file sharing software program
			 that is approved pursuant to subsection (b); and</text>
			</paragraph><paragraph id="H5327954011B64977B13A6713600036B2"><enum>(2)</enum><text>an inventory of
			 the agencies where such programs are being used.</text>
			</paragraph></section><section id="H8006E0E8E33446BFB18B7D953F99A9B9"><enum>4.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
			<paragraph id="H970937A0EC604DC3A128C4079586896A"><enum>(1)</enum><header>Agency</header><text>The
			 term <quote>agency</quote> has the meaning provided the term <quote>Executive
			 agency</quote> by <external-xref legal-doc="usc" parsable-cite="usc/5/105">section 105</external-xref> of title 5, United States
			 Code.</text>
			</paragraph><paragraph id="HFA14CD467C9B4BECB9666637498499E5"><enum>(2)</enum><header>Open-network</header><text>The
			 term <quote>open-network</quote>, with respect to software, means a network in
			 which—</text>
				<subparagraph id="HF916963D8B064AD5AEE430884A5C45B1"><enum>(A)</enum><text>access is granted
			 freely, without limitation or restriction; or</text>
				</subparagraph><subparagraph id="HF8F29BEEB7A3400E9903F6387DD8DCFA"><enum>(B)</enum><text>there are little
			 or no security measures in place.</text>
				</subparagraph></paragraph><paragraph id="H11A479A4D2404D86AE88702A4E484ED6"><enum>(3)</enum><header>Peer-to-peer
			 file sharing software</header><text>The term <quote>peer-to-peer file sharing
			 software</quote>—</text>
				<subparagraph id="H46587270EA4E4905986BF1B62E2B6389"><enum>(A)</enum><text display-inline="yes-display-inline">means a program, application, or software
			 that is commercially marketed or distributed to the public and that
			 enables—</text>
					<clause id="HF955DEC18AED4916A5FB776B23FAB0E4"><enum>(i)</enum><text display-inline="yes-display-inline">a file or files on the computer on which
			 such program is installed to be designated as available for searching and
			 copying to one or more other computers;</text>
					</clause><clause id="H46EEDF9CA45B412C8A7C1A85503AD20D"><enum>(ii)</enum><text>the
			 searching of files on the computer on which such program is installed and the
			 copying of any such file to another computer—</text>
						<subclause id="HFB95C656E6504BDAAB899C749E4BCF6B"><enum>(I)</enum><text display-inline="yes-display-inline">at the initiative of such other computer
			 and without requiring any action by an owner or authorized user of the computer
			 on which such program is installed; and</text>
						</subclause><subclause id="HB571AD3A3D6D487595E0C30CA0FF9922"><enum>(II)</enum><text>without requiring
			 an owner or authorized user of the computer on which such program is installed
			 to have selected or designated another computer as the recipient of any such
			 file; and</text>
						</subclause></clause><clause id="HD154B67210E14C18A93245D5F7A592E1"><enum>(iii)</enum><text display-inline="yes-display-inline">an owner or authorized user of the computer
			 on which such program is installed to search files on one or more other
			 computers using the same or a compatible program, application, or software, and
			 copy such files to such owner or user’s computer; and</text>
					</clause></subparagraph><subparagraph id="H16E4ED0BABC3478893ADEF1E2AB7633B"><enum>(B)</enum><text display-inline="yes-display-inline">does not include a program, application, or
			 software designed primarily—</text>
					<clause id="H8CCF2B8A924A4838BCB27451C2234064"><enum>(i)</enum><text>to
			 operate as a server that is accessible over the Internet using the Internet
			 Domain Name system;</text>
					</clause><clause id="H78A702344C434E2E94A6AC934BFF6231"><enum>(ii)</enum><text>to
			 transmit or receive email messages, instant messaging, real-time audio or video
			 communications, or real-time voice communications; or</text>
					</clause><clause id="H98B50534B18A4079BA78A99A131A1D0D"><enum>(iii)</enum><text>to
			 provide network or computer security (including the detection or prevention of
			 fraudulent activities), network management, maintenance, diagnostics, or
			 technical support or repair.</text>
					</clause></subparagraph></paragraph><paragraph id="HF927E9ECACC9436696BDB16B44BBF87D"><enum>(4)</enum><header>Contractor</header><text>The
			 term <quote>contractor</quote> means a prime contractor or a subcontractor, as
			 defined by the Federal Acquisition Regulation.</text>
			</paragraph></section><section id="H2B88730F4D174D19AE4F3ED00EA32451"><enum>5.</enum><header>Budgetary effects
			 of PAYGO legislation for this Act</header><text display-inline="no-display-inline">The budgetary effects of this Act, for the
			 purpose of complying with the Statutory Pay-As-You-Go Act of 2010, shall be
			 determined by reference to the latest statement titled <quote>Budgetary Effects
			 of PAYGO Legislation</quote> for this Act, submitted for printing in the
			 Congressional Record by the Chairman of the House Budget Committee, provided
			 that such statement has been submitted prior to the vote on passage.</text>
		</section></legis-body>
	<attestation>
		<attestation-group>
			<attestation-date chamber="House" date="20100324">Passed the House of
			 Representatives March 24, 2010.</attestation-date>
			<attestor display="yes">Lorraine C. Miller,</attestor>
			<role>Clerk.</role>
		</attestation-group>
	</attestation>
</bill>
