<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" dms-id="A1" public-private="public" slc-id="S1-DUN21A22-8JD-1J-059"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S3099 RS: Federal Secure Cloud Improvement and Jobs Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-10-28</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 383</calendar><congress>117th CONGRESS</congress><session>2d Session</session><legis-num>S. 3099</legis-num><associated-doc role="report">[Report No. 117–115]</associated-doc><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20211028">October 28, 2021</action-date><action-desc><sponsor name-id="S380">Mr. Peters</sponsor> (for himself, <cosponsor name-id="S388">Ms. Hassan</cosponsor>, <cosponsor name-id="S399">Mr. Hawley</cosponsor>, and <cosponsor name-id="S375">Mr. Daines</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00" added-display-style="italic" deleted-display-style="strikethrough">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date>May 24, 2022</action-date><action-desc>Reported by <sponsor name-id="S380">Mr. Peters</sponsor>, with an amendment</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction></action><legis-type>A BILL</legis-type><official-title>To amend title 44, United States Code, to establish the Federal Risk and Authorization Management Program within the General Services Administration, and for other purposes.</official-title></form><legis-body style="OLC"><section id="S1" commented="no" display-inline="no-display-inline" section-type="section-one" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>1.</enum><header display-inline="yes-display-inline">Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Federal Secure Cloud Improvement and Jobs Act of 2021</short-title></quote>.</text></section><section display-inline="no-display-inline" commented="no" id="id28CB345E52554DFBA4E3B4F85E1BD3E5" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds the following:</text><paragraph id="idf64b3a05b56a4a9a8f136debda5555f1"><enum>(1)</enum><text>Ensuring that the Federal Government can securely leverage cloud computing products and services is key to expediting the modernization of legacy information technology systems, increasing cybersecurity within and across departments and agencies, and supporting the continued leadership of the United States in technology innovation and job creation.</text></paragraph><paragraph id="idc37f3d077a594755a5b0a02124c01b19"><enum>(2)</enum><text>According to independent analysis, as of calendar year 2019, the size of the cloud computing market had tripled since 2004, enabling more than 2,000,000 jobs and adding more than $200,000,000,000 to the gross domestic product of the United States.</text></paragraph><paragraph id="id80c2e5d1923c44909edc456ff35f93f2"><enum>(3)</enum><text>The Federal Government, across multiple presidential administrations and Congresses, has continued to support the ability of agencies to move to the cloud, including through—</text><subparagraph id="idCB2138B68E4F4A829A3FA5C87865532F"><enum>(A)</enum><text>President Barack Obama’s <quote>Cloud First Strategy</quote>;</text></subparagraph><subparagraph id="id42EE6E5E90504444A42D32BCCF69BF64"><enum>(B)</enum><text>President Donald Trump’s <quote>Cloud Smart Strategy</quote>;</text></subparagraph><subparagraph id="id1B3B340D110A454F97817F5614D649AB"><enum>(C)</enum><text>the prioritization of cloud security in Executive Order 14208 (86 Fed. Reg. 26633; relating to improving the Nation’s cybersecurity), which was issued by President Joe Biden; and</text></subparagraph><subparagraph id="idC83F433295A2421D830FEBA804DC07D1"><enum>(D)</enum><text>more than a decade of appropriations and authorization legislation that provides agencies with relevant authorities and appropriations to modernize on-premises information technology systems and more readily adopt cloud computing products and services.</text></subparagraph></paragraph><paragraph id="id90cd53d0c9ea4ed5897689c465adb4ea"><enum>(4)</enum><text>Since it was created in 2011, the Federal Risk and Authorization Management Program (referred to in this section as <quote>FedRAMP</quote>) at the General Services Administration has made steady and sustained improvements in supporting the secure authorization and reuse of cloud computing products and services within the Federal Government, including by reducing the costs and burdens on both agencies and cloud companies to quickly and securely enter the Federal market.</text></paragraph><paragraph id="idaf5f6a3778a4476f9567b2e722ccc0b5"><enum>(5)</enum><text>According to data from the General Services Administration, as of the end of fiscal year 2021, there were 239 cloud providers with FedRAMP authorizations, and those authorizations had been reused more than 2,700 times across various agencies.</text></paragraph><paragraph id="id4f5298a235da47eea4554de47205e2e4"><enum>(6)</enum><text>Providing a legislative framework for FedRAMP and new authorities to the General Services Administration, the Office of Management and Budget, and Federal agencies will—</text><subparagraph id="id9697E073DAAC4E8AA14A97109A0B671A"><enum>(A)</enum><text>improve the speed at which new cloud computing products and services can be securely authorized;</text></subparagraph><subparagraph id="idA49AF430A7F94CF3958ADE4FABE2B81D"><enum>(B)</enum><text>enhance the ability of agencies to effectively evaluate FedRAMP authorized providers for reuse;</text></subparagraph><subparagraph id="id729AB649FF5F4572B3263FF45524EFBA"><enum>(C)</enum><text>reduce the costs and burdens to cloud providers seeking a FedRAMP authorization; and</text></subparagraph><subparagraph id="id56A7A38803A448D1AA792C1E0100D17F"><enum>(D)</enum><text>provide for more robust transparency and dialogue between industry and the Federal Government to drive stronger adoption of secure cloud capabilities, create jobs, and reduce wasteful legacy information technology.</text></subparagraph></paragraph></section><section display-inline="no-display-inline" commented="no" id="id4DF768962CAD4BCABDBE97300A759B6A" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>3.</enum><header>Title 44 amendments</header><subsection id="id1ECAACC384BC408FBDEED604F66A3593" commented="no" display-inline="no-display-inline"><enum>(a)</enum><header>Amendment</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">Chapter 36</external-xref> of title 44, United States Code, is amended by adding at the end the following:</text><quoted-block id="H4009CE15AD374AD6843B6726A45B370A" style="USC" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><section id="HFA102159A1FB4B709D48A640E5F21F36"><enum>3607.</enum><header>Definitions</header><subsection id="idE077C879A12E4997A48A5484BFFE8631"><enum>(a)</enum><header>In general</header><text>Except as provided under subsection (b), the definitions under sections 3502 and 3552 apply to this section through section 3616.</text></subsection><subsection id="id840BE41D9B1B4749A2FEB80B5E57A2B0"><enum>(b)</enum><header>Additional definitions</header><text>In this section through section 3616:</text><paragraph id="id5A13CC0018004D338024E94820DE36A6"><enum>(1)</enum><header>Cloud computing</header><text>The term <term>cloud computing</term> has the meaning given the term in Special Publication 800–145 of the National Institute of Standards and Technology.</text></paragraph><paragraph id="id00DA9C62F09E4FFB8479D241672CA715"><enum>(2)</enum><header>Cloud service provider</header><text>The term <term>cloud service provider</term> means an entity offering cloud computing products or services to agencies.</text></paragraph><paragraph id="id7601CE155C0D497BA95B11464AF2D2D7"><enum>(3)</enum><header>FedRAMP</header><text>The term <term>FedRAMP</term> means the Federal Risk and Authorization Management Program established under section 3608.</text></paragraph><paragraph id="idBE0653BA29EE491AB3F1DEF715FE952E"><enum>(4)</enum><header>FedRAMP authorization</header><text display-inline="yes-display-inline">The term <term>FedRAMP authorization</term> means a certification that a cloud computing product or service has—</text><subparagraph id="id84122B0FFF6147FEB2FE5528255B6B76"><enum>(A)</enum><text display-inline="yes-display-inline">completed a FedRAMP authorization process, as determined by the Administrator of General Services; or</text></subparagraph><subparagraph id="id8180CB16FFB14137A83C5BADC520CFC1"><enum>(B)</enum><text display-inline="yes-display-inline">received a FedRAMP provisional authorization to operate, as determined by the FedRAMP Board.</text></subparagraph></paragraph><paragraph id="id966D10E91B864C2C88E840986E440D87"><enum>(5)</enum><header>FedRAMP authorization package</header><text>The term <term>FedRAMP authorization package</term> means the essential information that can be used by an agency to determine whether to authorize the operation of an information system or the use of a designated set of common controls for all cloud computing products and services authorized by FedRAMP.</text></paragraph><paragraph id="id28DD0D947AE6406FB50F01E7DD6916E3" commented="no" display-inline="no-display-inline"><enum>(6)</enum><header display-inline="yes-display-inline">FedRAMP Board</header><text display-inline="yes-display-inline">The term <term>FedRAMP Board</term> means the board established under section 3610. </text></paragraph><paragraph id="idDFCC65BF38A549FC88A91E976799CEA1"><enum>(7)</enum><header>Independent assessment organization</header><text>The term <term>independent assessment organization</term> means a third-party organization accredited by the Administrator of General Services to undertake conformity assessments of cloud service providers and their products or services.</text></paragraph><paragraph id="id8FD951816CF64BE0B651D0E2FC55C00E" commented="no" display-inline="no-display-inline"><enum>(8)</enum><header display-inline="yes-display-inline">Secretary</header><text display-inline="yes-display-inline">The term <term>Secretary</term> means the Secretary of Homeland Security. </text></paragraph></subsection></section><section id="idBD4CB57249B24692A9A750E2946B59CC"><enum>3608.</enum><header>Federal Risk and Authorization Management Program</header><text display-inline="no-display-inline">There is established within the General Services Administration the Federal Risk and Authorization Management Program. The Administrator of General Services, subject to section 3613, shall establish a Government-wide program that provides a standardized, reusable approach to security assessment and authorization for cloud computing products and services that process unclassified information used by agencies.</text></section><section id="H6DFB8D07285E487388B60D2E20A059E9"><enum>3609.</enum><header>Roles and responsibilities of the General Services Administration</header><subsection id="H83B7EA6C1A744018AA1D37BEBB480F35"><enum>(a)</enum><header>Roles and responsibilities</header><text>The Administrator of General Services shall—</text><paragraph id="HB5EF5E72D0F04092B33CA288C7D5FDB9"><enum>(1)</enum><text>in consultation with the Secretary, develop, coordinate, and implement a process to support agency review, reuse, and standardization, where appropriate, of security assessments of cloud computing products and services, including, as appropriate, oversight of continuous monitoring of cloud computing products and services, pursuant to guidance issued by the Director pursuant to section 3613;</text></paragraph><paragraph id="H140E884F8625453ABDC905AD25329679"><enum>(2)</enum><text display-inline="yes-display-inline">establish processes and identify criteria consistent with guidance issued by the Director under section 3613 to make a cloud computing product or service eligible for a FedRAMP authorization and validate whether a cloud computing product or service has a FedRAMP authorization;</text></paragraph><paragraph id="H6849D542A8A44D749D528F0146FC2EEC"><enum>(3)</enum><text>develop and publish templates, best practices, technical assistance, and other materials to support the authorization of cloud computing products and services and increase the speed, effectiveness, and transparency of the authorization process, consistent with standards established by the Director of the National Institute of Standards and Technology and relevant statutes;</text></paragraph><paragraph id="H58516F6B626D490F85C126D47B541727"><enum>(4)</enum><text>grant FedRAMP authorizations to cloud computing products and services consistent with the guidance and direction of the FedRAMP Board;</text></paragraph><paragraph id="H13AF75BE55B74BD88D1019004570F526"><enum>(5)</enum><text display-inline="yes-display-inline">establish and maintain a public comment process for proposed guidance and other FedRAMP directives that may have a direct impact on cloud service providers and agencies before the issuance of such guidance or other FedRAMP directives;</text></paragraph><paragraph id="HFD28AEF038AE41199059F488F351F26F"><enum>(6)</enum><text display-inline="yes-display-inline">coordinate with the FedRAMP Board, the Director of the Cybersecurity and Infrastructure Security Agency, and other entities identified by the Administrator of General Services, with the concurrence of the Director and the Secretary, to establish and regularly update a framework for continuous monitoring under section 3553;</text></paragraph><paragraph id="H529272671C5441788D1B4B6C09F1B775"><enum>(7)</enum><text>provide a secure mechanism for storing and sharing necessary data, including FedRAMP authorization packages, to enable better reuse of such packages across agencies, including making available any information and data necessary for agencies to fulfill the requirements of section 3612;</text></paragraph><paragraph id="H597F94F760964364A7C1E370362FCC5E"><enum>(8)</enum><text display-inline="yes-display-inline">provide regular updates to applicant cloud service providers on the status of any cloud computing product or service during an assessment process;</text></paragraph><paragraph id="H12130B2FAB764F188E29EE8765AD2157"><enum>(9)</enum><text display-inline="yes-display-inline">regularly review, in consultation with the FedRAMP Board, the costs associated with the independent assessment services of the third-party organizations described in section 3611; </text></paragraph><paragraph id="HC037CD25317A46519E02291B6E195557"><enum>(10)</enum><text>support the Federal Secure Cloud Advisory Committee established pursuant to section 3616; and</text></paragraph><paragraph id="HA6E5B378BB7E4D92B36E799FE10E9E75"><enum>(11)</enum><text>take such other actions as the Administrator of General Services may determine necessary to carry out FedRAMP.</text></paragraph></subsection><subsection id="H531C041D1F264F3791F4FBF30BBFC527"><enum>(b)</enum><header>Website</header><paragraph id="HD6D25C47252E42B6ACA0CABDE72FF6B3"><enum>(1)</enum><header>In general</header><text>The Administrator of General Services shall maintain a public website to serve as the authoritative repository for FedRAMP, including the timely publication and updates for all relevant information, guidance, determinations, and other materials required under subsection (a).</text></paragraph><paragraph id="H3DC8EAFBAA2E4065815F6BA3CA550BA7"><enum>(2)</enum><header>Criteria and process for FedRAMP authorization priorities</header><text display-inline="yes-display-inline">The Administrator of General Services shall develop and make publicly available on the website described in paragraph (1) the criteria and process for prioritizing and selecting cloud computing products and services that will receive a FedRAMP authorization, in consultation with the FedRAMP Board and the Chief Information Officers Council. </text></paragraph></subsection><subsection id="HAE55FED6B5284821B615F3FAC97B07EB"><enum>(c)</enum><header>Evaluation of automation procedures</header><paragraph id="H23AC972679D440A9956278A7F60930C6"><enum>(1)</enum><header>In general</header><text>The Administrator of General Services, in coordination with the Secretary, shall assess and evaluate available automation capabilities and procedures to improve the efficiency and effectiveness of the issuance of FedRAMP authorizations, including continuous monitoring of cloud computing products and services.</text></paragraph><paragraph id="HC7ECB53E4FC94922965E5F450A9CDD9E"><enum>(2)</enum><header>Means for automation</header><text>Not later than 1 year after the date of enactment of this section, and updated regularly thereafter, the Administrator of General Services shall establish a means for the automation of security assessments and reviews.</text></paragraph></subsection><subsection id="H9991E7EFE3A94E6D8DC61E871C140D59"><enum>(d)</enum><header>Metrics for authorization</header><text>The Administrator of General Services shall establish annual metrics regarding the time and quality of the assessments necessary for completion of a FedRAMP authorization process in a manner that can be consistently tracked over time in conjunction with the periodic testing and evaluation process pursuant to section 3554 in a manner that minimizes the agency reporting burden.</text></subsection></section><section id="H87DD247AFC274804BF9F009CFB2A9568"><enum>3610.</enum><header>FedRAMP Board</header><subsection id="HAA3BE8DCEEAE4ED4B23EBF19D1802999"><enum>(a)</enum><header>Establishment</header><text>There is established a FedRAMP Board to provide input and recommendations to the Administrator of General Services regarding the requirements and guidelines for, and the prioritization of, security assessments of cloud computing products and services.</text></subsection><subsection id="H2A68F866F5D84C3280E5C021C1B218F4"><enum>(b)</enum><header>Membership</header><text>The FedRAMP Board shall consist of not more than 7 senior officials or experts from agencies appointed by the Director, in consultation with the Administrator of General Services, from each of the following:</text><paragraph id="HA42E131566884346A87FBD4FE361517C"><enum>(1)</enum><text>The Department of Defense.</text></paragraph><paragraph id="HCB0059913F234326A2D482932223C84F"><enum>(2)</enum><text>The Department of Homeland Security.</text></paragraph><paragraph id="HB07AE56F7154416BB49C6A48E5A18E4E"><enum>(3)</enum><text>The General Services Administration.</text></paragraph><paragraph id="H8B065373C63E465594ED57D7E754004B"><enum>(4)</enum><text>Such other agencies as determined by the Director, in consultation with the Administrator of General Services.</text></paragraph></subsection><subsection id="H6A85BCAAE87A48C59167342CCA58A57A"><enum>(c)</enum><header>Qualifications</header><text>Members of the FedRAMP Board appointed under subsection (b) shall have technical expertise in domains relevant to FedRAMP, such as—</text><paragraph id="HE606B2A10D7E411B8809E30206F258C8"><enum>(1)</enum><text>cloud computing;</text></paragraph><paragraph id="HF9FEF6876B794022A9CBF0FE07D5E14A"><enum>(2)</enum><text>cybersecurity;</text></paragraph><paragraph id="H37B704D039E44281A5C4E32C437D393E"><enum>(3)</enum><text>privacy;</text></paragraph><paragraph id="H5892D4DFC6214F72B2769F94CFC93218"><enum>(4)</enum><text>risk management; and</text></paragraph><paragraph id="H2BE0060CFE1A4D979B712472A1564B80"><enum>(5)</enum><text>other competencies identified by the Director to support the secure authorization of cloud services and products.</text></paragraph></subsection><subsection id="H2E6DC0C38706438DBDEC6724C80C9E90"><enum>(d)</enum><header>Duties</header><text>The FedRAMP Board shall—</text><paragraph id="HCAE774896FA441B8B3E6DD7A684BAF90"><enum>(1)</enum><text>in consultation with the Administrator of General Services, serve as a resource for best practices to accelerate the process for obtaining a FedRAMP authorization;</text></paragraph><paragraph id="H1B20274D1AA849B3B8BC560EA9BDE0C8"><enum>(2)</enum><text display-inline="yes-display-inline">establish and regularly update requirements and guidelines for security authorizations of cloud computing products and services, consistent with standards established by the Director of the National Institute of Standards and Technology, to be used in the determination of FedRAMP authorizations;</text></paragraph><paragraph id="H68BADC53546840D092CA70F7B635C648"><enum>(3)</enum><text display-inline="yes-display-inline">monitor and oversee, to the greatest extent practicable, the processes and procedures by which agencies determine and validate requirements for a FedRAMP authorization, including periodic review of the agency determinations described in section 3612(b);</text></paragraph><paragraph id="id78A2BF701EBD4603AA86D1F45073A8D5"><enum>(4)</enum><text display-inline="yes-display-inline">ensure consistency and transparency between agencies and cloud service providers in a manner that minimizes confusion and engenders trust; and</text></paragraph><paragraph id="HC11F390E820646FCA67B0C2CCF8858E4"><enum>(5)</enum><text>perform such other roles and responsibilities as the Director may assign, with concurrence from the Administrator of General Services.</text></paragraph></subsection><subsection id="H9512703D32BD43BE9F31CA369F98A893"><enum>(e)</enum><header>Determinations of demand for cloud computing products and services</header><text>The FedRAMP Board may consult with the Chief Information Officers Council to establish a process, which may be made available on the website maintained under section 3609(b), for prioritizing and accepting the cloud computing products and services to be granted a FedRAMP authorization.</text></subsection></section><section id="H256821EC52254F72A5B302F8BA523AC0"><enum>3611.</enum><header>Independent assessment organizations</header><subsection id="HFA0B5E89937A41778A3F4129F1481D7E"><enum>(a)</enum><header>Requirements for accreditation</header><text display-inline="yes-display-inline">The Administrator of General Services may, consistent with guidance issued by the Director, determine the requirements for accreditation of a third-party organization to perform independent assessments and other activities that will improve the overall performance of FedRAMP and reduce the cost of FedRAMP authorizations for cloud service providers. Such requirements may include developing or requiring certification programs for individuals employed by the third-party organization seeking accreditation.</text></subsection><subsection id="HC9880259BD704970A98AE54DC8A45224"><enum>(b)</enum><header>Certification</header><text>The Administrator of General Services may accredit any third-party organization that meets the requirements for accreditation determined under subsection (a). If accredited pursuant to the requirements determined under subsection (a), a certified independent assessment organization may assess, validate, and attest to the quality and compliance of security assessment materials provided by cloud service providers.</text></subsection></section><section id="HAB60205D0D8A439A956A85C0E84DA3F9"><enum>3612.</enum><header>Roles and responsibilities of agencies</header><subsection id="H112D140D62D5491DBA60A951D32BAE7E"><enum>(a)</enum><header>In general</header><text>In implementing the requirements of FedRAMP, the head of each agency shall, consistent with guidance issued by the Director pursuant to section 3613—</text><paragraph id="H8313341B17C04DFFBA8078FA4F6516AA"><enum>(1)</enum><text>promote the use of cloud computing products and services that meet FedRAMP security requirements and other risk-based performance requirements as determined by the Director, in consultation with the Secretary;</text></paragraph><paragraph id="HDE94F4EB3D8F4BBB825CAA29BCF74983"><enum>(2)</enum><text>confirm whether there is a FedRAMP authorization in the secure mechanism provided under section 3609(a)(7) before beginning the process of granting a FedRAMP authorization for a cloud computing product or service;</text></paragraph><paragraph id="H4EA42A6630CD499A936958491855CD4A"><enum>(3)</enum><text>to the extent practicable, for any cloud computing product or service the agency seeks to authorize that has received a FedRAMP authorization, use the existing assessments of security controls and materials within the FedRAMP authorization package; and</text></paragraph><paragraph id="HFB69BDC5FBAD4C308A39A189680F711A"><enum>(4)</enum><text>provide data and information required to the Director pursuant to section 3613 to determine how agencies are meeting metrics established by the Administrator of General Services.</text></paragraph></subsection><subsection id="HF287091A5A21411D8FBE71A945C77C77"><enum>(b)</enum><header>Attestation</header><text display-inline="yes-display-inline">Upon completing an assessment or authorization activity with respect to a particular cloud computing product or service, if an agency determines that the information and data the agency has reviewed under paragraph (2) or (3) of subsection (a) is wholly or substantially deficient for the purposes of performing an authorization of the cloud computing product or service, the head of the agency shall document as part of the resulting FedRAMP authorization package the reasons for this determination.</text></subsection><subsection id="HB3E939B113D24B1785615DF400FCC9BD"><enum>(c)</enum><header>Submission of authorizations To operate required</header><text>Upon issuance of an agency authorization to operate based on a FedRAMP authorization, the head of the agency shall provide a copy of its authorization to operate letter and any supplementary information required pursuant to section 3609(a) to the Administrator of General Services.</text></subsection><subsection id="HE70BDE4969FF4DE1A13AADBFEC17FBA2"><enum>(d)</enum><header>Submission of policies required</header><text display-inline="yes-display-inline">Not later than 180 days after the date on which the Director issues guidance in accordance with section 3613, the head of each agency, acting through the agency chief information officer of the agency, shall submit to the Director all agency policies relating to the authorization of cloud computing products and services.</text></subsection><subsection id="H835CE44B5A0947B191BA573EBB7059D6"><enum>(e)</enum><header>Presumption of adequacy</header><paragraph id="H99B649BE01C14997A19D58066792346B"><enum>(1)</enum><header>In general</header><text>The assessment of security controls and materials within the authorization package for a FedRAMP authorization shall be presumed adequate for use in an agency authorization to operate cloud computing products and services.</text></paragraph><paragraph id="HB911D7BE6DFE4E3DB3EF6F513A8E2C0D"><enum>(2)</enum><header>Information security requirements</header><text>The presumption under paragraph (1) does not modify or alter—</text><subparagraph id="id1FD66A8F3FB841718796204D150D435B"><enum>(A)</enum><text>the responsibility of any agency to ensure compliance with subchapter II of chapter 35 for any cloud computing products or services used by the agency; or</text></subparagraph><subparagraph id="id0395CFD2E7834500B022C70CF3137EF3"><enum>(B)</enum><text>the authority of the head of any agency to make a determination that there is a demonstrable need for additional security requirements beyond the security requirements included in a FedRAMP authorization for a particular control implementation.</text></subparagraph></paragraph></subsection></section><section id="H6105A69102CA482D8A06885FCC833A8C"><enum>3613.</enum><header>Roles and responsibilities of the Office of Management and Budget</header><subsection id="HDBA483E22E294F038F33FC829D51C8BF"><enum>(a)</enum><header>Roles and responsibilities</header><text>The Director shall—</text><paragraph id="H7CC120785B5142ED9C63097ED156B8D8"><enum>(1)</enum><text display-inline="yes-display-inline">in consultation with the Administrator of General Services and the Secretary, issue guidance that—</text><subparagraph id="id881FBE09F6874A8B85F58C2768EE88BE"><enum>(A)</enum><text display-inline="yes-display-inline">specifies the categories or characteristics of cloud computing products and services that are within the scope of FedRAMP;</text></subparagraph><subparagraph id="id9C3E5E1BC8D145A290EE189574F97FDA"><enum>(B)</enum><text display-inline="yes-display-inline"> includes requirements for agencies to obtain a FedRAMP authorization when operating a cloud computing product or service described in subparagraph (A) as a Federal information system; and</text></subparagraph><subparagraph id="id1752D308B3F446399AFC6080BB98762F"><enum>(C)</enum><text display-inline="yes-display-inline">encompasses, to the greatest extent practicable, all necessary and appropriate cloud computing products and services;</text></subparagraph></paragraph><paragraph id="H4B35212BA7E84263A8139EE60EEF4302"><enum>(2)</enum><text>issue guidance describing additional responsibilities of FedRAMP and the FedRAMP Board to accelerate the adoption of secure cloud computing services by the Federal Government;</text></paragraph><paragraph id="HD77AEC55992F406B9F6D97A996A57644"><enum>(3)</enum><text>oversee the effectiveness of FedRAMP and the FedRAMP Board, including the compliance by the FedRAMP Board with the duties described in section 3610(d); and</text></paragraph><paragraph id="HE014BEF5B5A74EC5A34F5CB2B89C4ED9"><enum>(4)</enum><text>to the greatest extent practicable, encourage and promote consistency of the assessment, authorization, adoption, and use of cloud computing products and services within and across agencies.</text></paragraph></subsection></section><section id="HFB95F5092ACD47E6BC7A53F20E0E12DC"><enum>3614.</enum><header>Authorization of appropriations for FedRAMP</header><text display-inline="no-display-inline">There is authorized to be appropriated to the Administrator of General Services $20,000,000 for each fiscal year for FedRAMP and the FedRAMP Board.</text></section><section id="H31F9A6DCF6B04F3B9B5A6388FACB250A"><enum>3615.</enum><header>Reports to congress; GAO report</header><subsection id="H72F62E4543BF48CE944D1AF6C3FCD76D"><enum>(a)</enum><header>Reports to congress</header><text>Not later than 1 year after the date of enactment of this section, and annually thereafter, the Director shall submit to the Committee on Oversight and Reform of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report that includes the following:</text><paragraph id="H8BDE7ED811324B9E98B8D0816130D43F"><enum>(1)</enum><text>During the preceding year, the status, efficiency, and effectiveness of the General Services Administration under section 3609 and agencies under section 3612 and in supporting the speed, effectiveness, sharing, reuse, and security of authorizations to operate for cloud computing products and services.</text></paragraph><paragraph id="H11A339C205BE4B0898EFC17E90CC8BE7"><enum>(2)</enum><text>Progress towards meeting the metrics required under section 3609(d).</text></paragraph><paragraph id="H03CD5BA5A9854B1BACA660F7A76D8D12"><enum>(3)</enum><text>Data on FedRAMP authorizations.</text></paragraph><paragraph id="H8A933F0C590A41458064784C7B7CE834"><enum>(4)</enum><text>The average length of time to issue FedRAMP authorizations.</text></paragraph><paragraph id="H67E80954F0AE445E9FA3D6FBB311AE68"><enum>(5)</enum><text>The number of FedRAMP authorizations submitted, issued, and denied for the preceding year.</text></paragraph><paragraph id="HA25549BDC8FA42B5A3AF6AD20C3B25A0"><enum>(6)</enum><text>A review of progress made during the preceding year in advancing automation techniques to securely automate FedRAMP processes and to accelerate reporting under this section.</text></paragraph><paragraph id="H55844A6F5B9F4290B94031E8B55B2CDD"><enum>(7)</enum><text>The number and characteristics of authorized cloud computing products and services in use at each agency consistent with guidance provided by the Director under section 3613.</text></paragraph></subsection><subsection id="H1AF414C8777945EE9E0EC57F98FD7B4A"><enum>(b)</enum><header>GAO report</header><text>Not later than 180 days after the date of enactment of this section, the Comptroller General of the United States shall publish a report that includes an assessment of the following:</text><paragraph id="id967DE4D7A2404166A1DFA6479FEA7E1F"><enum>(1)</enum><text>The costs incurred by agencies and cloud service providers relating to the issuance of FedRAMP authorizations.</text></paragraph><paragraph id="idD2F9156E8DE343A99D00E00281528B3F"><enum>(2)</enum><text>The extent to which agencies have processes in place to continuously monitor cloud computing products and services operating as Federal information systems.</text></paragraph><paragraph id="id49CBC35DA0424C2FB276960AFA01B17C"><enum>(3)</enum><text>How often and for which categories of products agencies use FedRAMP authorizations.</text></paragraph><paragraph id="id00BCF8A86DEE4E5089C5FD1B406B3455"><enum>(4)</enum><text>The unique costs and potential burdens incurred by cloud computing companies that are small business concerns (as defined in section 3(a) of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632(a)</external-xref>)) as a part of the FedRAMP authorization process.</text></paragraph></subsection></section><section id="H3BA670C2FE0C4CCFA64E6905CEE5DC40"><enum>3616.</enum><header>Federal Secure Cloud Advisory Committee</header><subsection id="H66769B6FACE14D16BC78E58A8E641B5D"><enum>(a)</enum><header>Establishment, purposes, and duties</header><paragraph id="HEBA6963E7A5B4D2B9BEEF4624CD39300"><enum>(1)</enum><header>Establishment</header><text>There is established a Federal Secure Cloud Advisory Committee (referred to in this section as the <quote>Committee</quote>) to ensure effective and ongoing coordination of agency adoption, use, authorization, monitoring, acquisition, and security of cloud computing products and services to enable agency mission and administrative priorities.</text></paragraph><paragraph id="HD0434224CAEA42DA83646B0FCFAF2076"><enum>(2)</enum><header>Purposes</header><text>The purposes of the Committee are the following:</text><subparagraph id="HDBE327F3DA7349A5AB369CC8E9D2AE32"><enum>(A)</enum><text>To examine the operations of FedRAMP and determine ways that authorization processes can continuously be improved, including the following:</text><clause id="HBCD9CDCE35F9432BBC0A297E1888EC1D"><enum>(i)</enum><text>Measures to increase agency reuse of FedRAMP authorizations.</text></clause><clause id="H9F3EA80699184D38B43996F494D5075F"><enum>(ii)</enum><text display-inline="yes-display-inline">Proposed actions that can be adopted to reduce the burden, confusion, and cost associated with FedRAMP authorizations for cloud service providers.</text></clause><clause id="HE07CB7082C7D4BC1AA76071DD133B750"><enum>(iii)</enum><text>Measures to increase the number of FedRAMP authorizations for cloud computing services offered by small businesses concerns (as defined by section 3(a) of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632(a)</external-xref>)).</text></clause><clause id="H84E5BC3814804A468E6DC4E3FA0910BA"><enum>(iv)</enum><text display-inline="yes-display-inline">Proposed actions that can be adopted to reduce the burden and cost of FedRAMP authorizations for agencies.</text></clause></subparagraph><subparagraph id="HEAF6FCEE50FC437B83E228EAA480B81E"><enum>(B)</enum><text>Collect information and feedback on agency compliance with and implementation of FedRAMP requirements.</text></subparagraph><subparagraph id="H628A12D135E04A01B5068D55E4AF766D"><enum>(C)</enum><text>Serve as a forum that facilitates communication and collaboration among the FedRAMP stakeholder community.</text></subparagraph></paragraph><paragraph id="H73AC4BFF65DF4837A60B14BB78B13CEB"><enum>(3)</enum><header>Duties</header><text>The duties of the Committee include providing advice and recommendations to the Administrator of General Services, the FedRAMP Board, and agencies on technical, financial, programmatic, and operational matters regarding secure adoption of cloud computing products and services.</text></paragraph></subsection><subsection id="H0ADF7375A83C4D2EAC8610377219C076"><enum>(b)</enum><header>Members</header><paragraph id="H4F7DC7153CB54EC0835A62728A6B7939"><enum>(1)</enum><header>Composition</header><text>The Committee shall be comprised of not more than 15 members who are qualified representatives from the public and private sectors, appointed by the Administrator of General Services, in consultation with the Director, as follows:</text><subparagraph id="HD2AFEC82ADC54E099B65EA2CE0C32733"><enum>(A)</enum><text>The Administrator of General Services or the Administrator of General Services’s designee, who shall be the Chair of the Committee.</text></subparagraph><subparagraph id="H18E491D11AFF4D608C5A27842D250B7D"><enum>(B)</enum><text>At least 1 representative each from the Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology.</text></subparagraph><subparagraph id="HCB14C039D15F457C935301D588C1CB21"><enum>(C)</enum><text>At least 2 officials who serve as the Chief Information Security Officer within an agency, who shall be required to maintain such a position throughout the duration of their service on the Committee.</text></subparagraph><subparagraph id="H642DEF14E9D84918B56688F5E74DE413"><enum>(D)</enum><text>At least 1 official serving as Chief Procurement Officer (or equivalent) in an agency, who shall be required to maintain such a position throughout the duration of their service on the Committee.</text></subparagraph><subparagraph id="H0A7A1ACC81D6436596CDDB956935B4FE"><enum>(E)</enum><text>At least 1 individual representing an independent assessment organization.</text></subparagraph><subparagraph id="H2C9513494DC74AA79764FA78F950E865"><enum>(F)</enum><text>No fewer than 5 representatives from unique businesses that primarily provide cloud computing services or products, including at least two representatives from a small business concern (as defined by section 3(a) of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632(a)</external-xref>)).</text></subparagraph><subparagraph id="H857C345C43404B3F92588BC35AA8B4F9"><enum>(G)</enum><text>At least 2 other representatives of the Federal Government as the Administrator of General Services determines necessary to provide sufficient balance, insights, or expertise to the Committee.</text></subparagraph></paragraph><paragraph id="H32780DC1049A4BF7AE0476A54C69312F"><enum>(2)</enum><header>Deadline for appointment</header><text>Each member of the Committee shall be appointed not later than 90 days after the date of enactment of this section.</text></paragraph><paragraph id="HD2A54655E8F441CB9757706D5E9694A9"><enum>(3)</enum><header>Period of appointment; vacancies</header><subparagraph id="HABAA2EF83B3E4F7E8FFA020E9349D526"><enum>(A)</enum><header>In general</header><text>Each non-Federal member of the Committee shall be appointed for a term of 3 years, except that the initial terms for members may be staggered 1-, 2-, or 3-year terms to establish a rotation in which one-third of the members are selected each year. Any such member may be appointed for not more than 2 consecutive terms.</text></subparagraph><subparagraph id="H2950A18931E846F8B8D4FE49339AD17C"><enum>(B)</enum><header>Vacancies</header><text>Any vacancy in the Committee shall not affect its powers, but shall be filled in the same manner in which the original appointment was made. Any member appointed to fill a vacancy occurring before the expiration of the term for which the member’s predecessor was appointed shall be appointed only for the remainder of that term. A member may serve after the expiration of that member’s term until a successor has taken office.</text></subparagraph></paragraph></subsection><subsection id="HFEC54E9031C84EE49609B8FB89D55C27"><enum>(c)</enum><header>Meetings and rules of procedures</header><paragraph id="HEFAF0B1928EC4D149844D48F7CEA1018"><enum>(1)</enum><header>Meetings</header><text>The Committee shall hold not fewer than 3 meetings in a calendar year, at such time and place as determined by the Chair.</text></paragraph><paragraph id="H114F98A563064D7C8045217EC052125C"><enum>(2)</enum><header>Initial meeting</header><text>Not later than 120 days after the date of enactment of this section, the Committee shall meet and begin the operations of the Committee.</text></paragraph><paragraph id="H5348D52E1DF946BA9F5172618FA6A52C"><enum>(3)</enum><header>Rules of procedure</header><text>The Committee may establish rules for the conduct of the business of the Committee if such rules are not inconsistent with this section or other applicable law.</text></paragraph></subsection><subsection id="H64828C79E99C44B48D48132026AEF235"><enum>(d)</enum><header>Employee status</header><paragraph id="HCE3DDFDDBF9F4C748F83A7CB4446B34D"><enum>(1)</enum><header>In general</header><text>A member of the Committee (other than a member who is appointed to the Committee in connection with another Federal appointment) shall not be considered an employee of the Federal Government by reason of any service as such a member, except for the purposes of section 5703 of title 5, relating to travel expenses.</text></paragraph><paragraph id="H477C70CAF1FD43189E45CF701AFE5BE9"><enum>(2)</enum><header>Pay not permitted</header><text>A member of the Committee covered by paragraph (1) may not receive pay by reason of service on the Committee.</text></paragraph></subsection><subsection id="H377302A788E640F2B4AF6315C06BBAC1"><enum>(e)</enum><header>Applicability to the federal advisory committee act</header><text>Section 14 of the Federal Advisory Committee Act (5 U.S.C. App.) shall not apply to the Committee.</text></subsection><subsection id="H80BF536A7B5B47D1890A5878BF14EC11"><enum>(f)</enum><header>Detail of employees</header><text>Any Federal Government employee may be detailed to the Committee without reimbursement from the Committee, and such detailee shall retain the rights, status, and privileges of his or her regular employment without interruption.</text></subsection><subsection id="H5F0C2E39CB6A4A038F07522427E017B8"><enum>(g)</enum><header>Postal services</header><text>The Committee may use the United States mails in the same manner and under the same conditions as agencies.</text></subsection><subsection id="H56080C6580D34FAA99EF72AE9B397DAC"><enum>(h)</enum><header>Reports</header><paragraph id="H75DD6B86D99649F887894CCAC7DA96C5"><enum>(1)</enum><header>Interim reports</header><text>The Committee may submit to the Administrator of General Services and Congress interim reports containing such findings, conclusions, and recommendations as have been agreed to by the Committee.</text></paragraph><paragraph id="H8DEB639D99464BE98FE7B20FA85D7C5E"><enum>(2)</enum><header>Annual reports</header><text>Not later than 540 days after the date of enactment of this section, and annually thereafter, the Committee shall submit to the Administrator of General Services and Congress a final report containing such findings, conclusions, and recommendations as have been agreed to by the Committee.</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="HD8513E54FE894D74AD4D7B54D4A25065"><enum>(b)</enum><header>Technical and conforming amendment</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">chapter 36</external-xref> of title 44, United States Code, is amended by adding at the end the following new items:</text><quoted-block style="USC" id="id3b958b73-283b-4ec0-bf42-7faacc3ceebe" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><toc changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><toc-entry level="section" idref="HFA102159A1FB4B709D48A640E5F21F36">3607. Definitions. </toc-entry><toc-entry level="section" idref="idBD4CB57249B24692A9A750E2946B59CC">3608. Federal Risk and Authorization Management Program. </toc-entry><toc-entry level="section" idref="H6DFB8D07285E487388B60D2E20A059E9">3609. Roles and responsibilities of the General Services Administration. </toc-entry><toc-entry level="section" idref="H87DD247AFC274804BF9F009CFB2A9568">3610. FedRAMP Board. </toc-entry><toc-entry level="section" idref="H256821EC52254F72A5B302F8BA523AC0">3611. Independent assessment organizations. </toc-entry><toc-entry level="section" idref="HAB60205D0D8A439A956A85C0E84DA3F9">3612. Roles and responsibilities of agencies. </toc-entry><toc-entry level="section" idref="H6105A69102CA482D8A06885FCC833A8C">3613. Roles and responsibilities of the Office of Management and Budget. </toc-entry><toc-entry level="section" idref="HFB95F5092ACD47E6BC7A53F20E0E12DC">3614. Authorization of appropriations for FedRAMP. </toc-entry><toc-entry level="section" idref="H31F9A6DCF6B04F3B9B5A6388FACB250A">3615. Reports to congress; GAO report. </toc-entry><toc-entry level="section" idref="H3BA670C2FE0C4CCFA64E6905CEE5DC40">3616. Federal Secure Cloud Advisory Committee.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="idE0B96594687E4966BCA4302D4737B5B8"><enum>(c)</enum><header>Sunset</header><paragraph id="idCAF07B90530847B4B8BD081B8CBDEF59"><enum>(1)</enum><header>In general</header><text>Effective on the date that is 5 years after the date of enactment of this Act, <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">chapter 36</external-xref> of title 44, United States Code, is amended by striking sections 3607 through 3616.</text></paragraph><paragraph id="id08E27B784D62465F8AB9D316EC06BCB8" commented="no" display-inline="no-display-inline"><enum>(2)</enum><header>Conforming amendment</header><text>Effective on the date that is 5 years after the date of enactment of this Act, the table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">chapter 36</external-xref> of title 44, United States Code, is amended by striking the items relating to sections 3607 through 3616.</text></paragraph></subsection><subsection id="HA252D30388094A06B554996CA84B3AB1"><enum>(d)</enum><header>Rule of construction</header><text>Nothing in this section or any amendment made by this section shall be construed as altering or impairing the authorities of the Director of the Office of Management and Budget or the Secretary of Homeland Security under subchapter II of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code.</text></subsection></section></legis-body><legis-body display-enacting-clause="no-display-enacting-clause"><section id="id83f01d4a-ee3e-4ff8-ba1d-ccf2dd771635" commented="no" display-inline="no-display-inline" section-type="section-one" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>1.</enum><header display-inline="yes-display-inline">Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Federal Secure Cloud Improvement and Jobs Act of 2021</short-title></quote>.</text></section><section display-inline="no-display-inline" commented="no" id="idb01b5b3c-cd94-40a7-92fb-3e6f8ae04bed" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds the following:</text><paragraph id="idc0d3c611-9583-4bd3-a4d5-0ab10ab0b0d3"><enum>(1)</enum><text>Ensuring that the Federal Government can securely leverage cloud computing products and services is key to expediting the modernization of legacy information technology systems, increasing cybersecurity within and across departments and agencies, and supporting the continued leadership of the United States in technology innovation and job creation.</text></paragraph><paragraph id="idb3c6d231-d19d-4802-a28d-5c2676b0409d"><enum>(2)</enum><text>According to independent analysis, as of calendar year 2019, the size of the cloud computing market had tripled since 2004, enabling more than 2,000,000 jobs and adding more than $200,000,000,000 to the gross domestic product of the United States.</text></paragraph><paragraph id="id1a6de4fe-b3f9-4a51-bad0-6545e764b478"><enum>(3)</enum><text>The Federal Government, across multiple presidential administrations and Congresses, has continued to support the ability of agencies to move to the cloud, including through—</text><subparagraph id="id32476a35-38ee-4b17-ab44-4aeaf034f012"><enum>(A)</enum><text>President Barack Obama’s <quote>Cloud First Strategy</quote>;</text></subparagraph><subparagraph id="id2845d6a8-8eb2-4a0f-90f7-bb1c6be9157a"><enum>(B)</enum><text>President Donald Trump’s <quote>Cloud Smart Strategy</quote>;</text></subparagraph><subparagraph id="id3f0bd73b-a27c-4168-b25c-fdb9394eb39c"><enum>(C)</enum><text>the prioritization of cloud security in Executive Order 14028 (86 Fed. Reg. 26633; relating to improving the nation’s cybersecurity), which was issued by President Joe Biden; and</text></subparagraph><subparagraph id="id76d77934-de4c-465d-a2d7-5d29a3edf2be"><enum>(D)</enum><text>more than a decade of appropriations and authorization legislation that provides agencies with relevant authorities and appropriations to modernize on-premises information technology systems and more readily adopt cloud computing products and services.</text></subparagraph></paragraph><paragraph id="id55d4512b-c407-4911-bb99-c0209bebdc84"><enum>(4)</enum><text>Since it was created in 2011, the Federal Risk and Authorization Management Program (referred to in this section as <quote>FedRAMP</quote>) at the General Services Administration has made steady and sustained improvements in supporting the secure authorization and reuse of cloud computing products and services within the Federal Government, including by reducing the costs and burdens on both agencies and cloud companies to quickly and securely enter the Federal market.</text></paragraph><paragraph id="id790e91a3-603e-41e6-ac0e-92b46bed955b"><enum>(5)</enum><text>According to data from the General Services Administration, as of the end of fiscal year 2021, there were 239 cloud providers with FedRAMP authorizations, and those authorizations had been reused more than 2,700 times across various agencies.</text></paragraph><paragraph id="ide2a77deb-7a88-4412-a3af-39f8428f76bb"><enum>(6)</enum><text>Providing a legislative framework for FedRAMP and new authorities to the General Services Administration, the Office of Management and Budget, and Federal agencies will—</text><subparagraph id="idb946e81a-a765-42e2-9f0c-00ff9539dcb8"><enum>(A)</enum><text>improve the speed at which new cloud computing products and services can be securely authorized;</text></subparagraph><subparagraph id="id782d86de-4ccf-448a-9593-65372312f47e"><enum>(B)</enum><text>enhance the ability of agencies to effectively evaluate FedRAMP authorized providers for reuse;</text></subparagraph><subparagraph id="id44dc550b-9c1e-4bc9-9a65-b596df038f2e"><enum>(C)</enum><text>reduce the costs and burdens to cloud providers seeking a FedRAMP authorization; and</text></subparagraph><subparagraph id="id2fbf9d8f-6b0e-4ba2-beec-da427807a74b"><enum>(D)</enum><text>provide for more robust transparency and dialogue between industry and the Federal Government to drive stronger adoption of secure cloud capabilities, create jobs, and reduce wasteful legacy information technology.</text></subparagraph></paragraph></section><section display-inline="no-display-inline" commented="no" id="idb2493f5d-eef4-497f-a4c4-fa9b2b708326" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>3.</enum><header>Title 44 amendments</header><subsection id="idaec74142-a788-4d12-8230-61a93c5c4121" commented="no" display-inline="no-display-inline"><enum>(a)</enum><header>Amendment</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">Chapter 36</external-xref> of title 44, United States Code, is amended by adding at the end the following:</text><quoted-block id="id7e0c5d4e-80e1-44c3-a34b-46988a9846ba" style="USC" changed="not-changed"><section id="id8d707228-c2e5-4df7-b9c1-bb4511d45836" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>3607.</enum><header>Definitions</header><subsection id="id9a1a846e-cf53-4353-b403-342a9f0b20f2"><enum>(a)</enum><header>In general</header><text>Except as provided under subsection (b), the definitions under sections 3502 and 3552 apply to this section through section 3616.</text></subsection><subsection id="idd51715e4-da94-49b4-9a0d-dcd4b2e52b7d"><enum>(b)</enum><header>Additional definitions</header><text>In this section through section 3616:</text><paragraph id="idFE757D6AF67A43A6BD4CCF64D55173F1"><enum>(1)</enum><header>Administrator</header><text>The term <term>Administrator</term> means the Administrator of General Services.</text></paragraph><paragraph id="id9E058D312A7648C681182D1B192A718A"><enum>(2)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives.</text></paragraph><paragraph id="id782F50634DD2418FBFF5B4B9F369C195"><enum>(3)</enum><header>Authorization to operate; Federal information</header><text>The terms <term>authorization to operate</term> and <term>Federal information</term> have the meaning given those term in Circular A–130 of the Office of Management and Budget entitled <quote>Managing Information as a Strategic Resource</quote>, or any successor document.</text></paragraph><paragraph id="id7bbaec8a-7f83-4ad1-b8ab-4a922174ac79"><enum>(4)</enum><header>Cloud computing</header><text>The term <term>cloud computing</term> has the meaning given the term in Special Publication 800–145 of the National Institute of Standards and Technology, or any successor document.</text></paragraph><paragraph id="id29994b87-6596-4960-8d6c-7d9656665efd"><enum>(5)</enum><header>Cloud service provider</header><text>The term <term>cloud service provider</term> means an entity offering cloud computing products or services to agencies.</text></paragraph><paragraph id="id9cfa2ba8-0900-4d97-911e-83a2cd79b735"><enum>(6)</enum><header>FedRAMP</header><text>The term <term>FedRAMP</term> means the Federal Risk and Authorization Management Program established under section 3608.</text></paragraph><paragraph id="id1734c19e-8a0b-4e60-967c-976b89fd94de"><enum>(7)</enum><header>FedRAMP authorization</header><text display-inline="yes-display-inline">The term <term>FedRAMP authorization</term> means a certification that a cloud computing product or service has—</text><subparagraph id="idd6d7b58b-3792-4d80-857f-30be32c5f845"><enum>(A)</enum><text display-inline="yes-display-inline">completed a FedRAMP authorization process, as determined by the Administrator; or</text></subparagraph><subparagraph id="idc2d13140-a0a2-4f57-93ff-a2aef7a573a1"><enum>(B)</enum><text display-inline="yes-display-inline">received a FedRAMP provisional authorization to operate, as determined by the FedRAMP Board.</text></subparagraph></paragraph><paragraph id="id4bee30d2-75c6-4aa9-9047-ab742aece7b3"><enum>(8)</enum><header>Fedramp authorization package</header><text>The term <term>FedRAMP authorization package</term> means the essential information that can be used by an agency to determine whether to authorize the operation of an information system or the use of a designated set of common controls for all cloud computing products and services authorized by FedRAMP.</text></paragraph><paragraph id="id32eaa32c-891d-4f18-90eb-463b6ce70dc5" commented="no" display-inline="no-display-inline"><enum>(9)</enum><header display-inline="yes-display-inline">FedRAMP Board</header><text display-inline="yes-display-inline">The term <term>FedRAMP Board</term> means the board established under section 3610.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idC72BED5130374DE389358B6D86C9FE70"><enum>(10)</enum><header>Independent assessment service</header><text display-inline="yes-display-inline">The term <term>independent assessment service</term> means a third-party organization accredited by the Administrator to undertake conformity assessments of cloud service providers and the products or services of cloud service providers. </text></paragraph><paragraph id="ide440806a-d60e-41b3-ad84-b434f573fa2b" commented="no" display-inline="no-display-inline"><enum>(11)</enum><header display-inline="yes-display-inline">Secretary</header><text display-inline="yes-display-inline">The term <term>Secretary</term> means the Secretary of Homeland Security. </text></paragraph></subsection></section><section id="idb5027c84-beb5-4be4-b904-3ecd74e6417c" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>3608.</enum><header>Federal Risk and Authorization Management Program</header><text display-inline="no-display-inline">There is established within the General Services Administration the Federal Risk and Authorization Management Program. The Administrator, subject to section 3614, shall establish a Government-wide program that provides a standardized, reusable approach to security assessment and authorization for cloud computing products and services that process unclassified information used by agencies.</text></section><section id="idfbffe3d4-f4d0-48b9-9f1f-b3fbfbd66d91" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>3609.</enum><header>Roles and responsibilities of the General Services Administration</header><subsection id="id6d1e9e42-4a9b-4fa5-b42a-0f264a66c0a3"><enum>(a)</enum><header>Roles and responsibilities</header><text>The Administrator shall—</text><paragraph id="idaaff9a6e-0b9d-4277-9912-747a3fb4a71f"><enum>(1)</enum><text>in consultation with the Secretary, develop, coordinate, and implement a process to support agency review, reuse, and standardization, where appropriate, of security assessments of cloud computing products and services, including, as appropriate, oversight of continuous monitoring of cloud computing products and services, pursuant to guidance issued by the Director pursuant to section 3614;</text></paragraph><paragraph id="idf9bf3412-410b-4ef7-8223-b7a0383332ef"><enum>(2)</enum><text display-inline="yes-display-inline">establish processes and identify criteria consistent with guidance issued by the Director under section 3614 to make a cloud computing product or service eligible for a FedRAMP authorization and validate whether a cloud computing product or service has a FedRAMP authorization;</text></paragraph><paragraph id="ide4285a5e-4c25-4b41-a06b-f0e015a6e83b"><enum>(3)</enum><text>develop and publish templates, best practices, technical assistance, and other materials to support the authorization of cloud computing products and services and increase the speed, effectiveness, and transparency of the authorization process, consistent with standards and guidelines established by the Director of the National Institute of Standards and Technology and relevant statutes;</text></paragraph><paragraph id="id973E43BD44314A03800A329AF3D3FE19"><enum>(4)</enum><text>establish and update guidance on the boundaries of FedRAMP authorization packages to enhance the security and protection of Federal information and promote transparency for agencies and users as to which services are included in the scope of a FedRAMP authorization;</text></paragraph><paragraph id="id42a1b912-1aeb-4e05-abc4-0f3e484a5faf"><enum>(5)</enum><text>grant FedRAMP authorizations to cloud computing products and services consistent with the guidance and direction of the FedRAMP Board;</text></paragraph><paragraph id="id7e2ee8f3-1e34-4c31-92aa-6be7198813ae"><enum>(6)</enum><text display-inline="yes-display-inline">establish and maintain a public comment process for proposed guidance and other FedRAMP directives that may have a direct impact on cloud service providers and agencies before the issuance of such guidance or other FedRAMP directives;</text></paragraph><paragraph id="id0a17b600-5459-4475-9531-2b48a8c51996"><enum>(7)</enum><text display-inline="yes-display-inline">coordinate with the FedRAMP Board, the Director of the Cybersecurity and Infrastructure Security Agency, and other entities identified by the Administrator, with the concurrence of the Director and the Secretary, to establish and regularly update a framework for continuous monitoring under section 3553;</text></paragraph><paragraph id="id8ed99fec-7a72-40c4-9886-9c9a184bd1c2"><enum>(8)</enum><text>provide a secure mechanism for storing and sharing necessary data, including FedRAMP authorization packages, to enable better reuse of such packages across agencies, including making available any information and data necessary for agencies to fulfill the requirements of section 3613;</text></paragraph><paragraph id="id6dee426c-481c-4835-b0f8-62c8b08b0e9d"><enum>(9)</enum><text display-inline="yes-display-inline">provide regular updates to applicant cloud service providers on the status of any cloud computing product or service during an assessment process;</text></paragraph><paragraph id="id824328a1-9285-4b25-9ea0-ed6785a63e5d"><enum>(10)</enum><text display-inline="yes-display-inline">regularly review, in consultation with the FedRAMP Board—</text><subparagraph id="id629924C9FA344345B293250CC703D4E0"><enum>(A)</enum><text display-inline="yes-display-inline">the costs associated with the independent assessment services described in section 3611; and</text></subparagraph><subparagraph id="id9C90FA3988E54067AE1A423670C4F942"><enum>(B)</enum><text>the information relating to foreign interests submitted pursuant to section 3612;</text></subparagraph></paragraph><paragraph id="id65F11B2CDCE245138E2A7F0F1DBE6E0C"><enum>(11)</enum><text>in coordination with the Director of the National Institute of Standards and Technology, the Director, the Secretary, and other stakeholders, as appropriate, determine the sufficiency of underlying standards and requirements to identify and assess the provenance of the software in cloud services and products;</text></paragraph><paragraph id="id67f0e9b8-0e9c-4b76-860c-9a5cf48d6a36"><enum>(12)</enum><text>support the Federal Secure Cloud Advisory Committee established pursuant to section 3616; and</text></paragraph><paragraph id="idf5bc85b0-3c72-4919-bd14-bca9f0fcdbb9"><enum>(13)</enum><text>take such other actions as the Administrator may determine necessary to carry out FedRAMP.</text></paragraph></subsection><subsection id="id09e04028-be0d-427a-b139-bec1992cbfb0"><enum>(b)</enum><header>Website</header><paragraph id="id7b2969e7-5180-4a8c-bb77-bbebcd99fd19"><enum>(1)</enum><header>In general</header><text>The Administrator shall maintain a public website to serve as the authoritative repository for FedRAMP, including the timely publication and updates for all relevant information, guidance, determinations, and other materials required under subsection (a).</text></paragraph><paragraph id="iddeb32ca7-bd70-4c4d-9390-3690da887284"><enum>(2)</enum><header>Criteria and process for FedRAMP authorization priorities</header><text display-inline="yes-display-inline">The Administrator shall develop and make publicly available on the website described in paragraph (1) the criteria and process for prioritizing and selecting cloud computing products and services that will receive a FedRAMP authorization, in consultation with the FedRAMP Board and the Chief Information Officers Council. </text></paragraph></subsection><subsection id="ida7b7e8f6-aa6c-44a6-ba9c-6ebffa81da9b"><enum>(c)</enum><header>Evaluation of automation procedures</header><paragraph id="id3d355e0e-e3f3-465a-b7cf-c7126407f313"><enum>(1)</enum><header>In general</header><text>The Administrator, in coordination with the Secretary, shall assess and evaluate available automation capabilities and procedures to improve the efficiency and effectiveness of the issuance of FedRAMP authorizations, including continuous monitoring of cloud computing products and services.</text></paragraph><paragraph id="id0fdadbe4-d54d-44a0-9dbb-f189a4fa33b4"><enum>(2)</enum><header>Means for automation</header><text>Not later than 1 year after the date of enactment of this section, and updated regularly thereafter, the Administrator shall establish a means for the automation of security assessments and reviews.</text></paragraph></subsection><subsection id="id688c215b-1961-4c8a-8e3a-5f2af807083b"><enum>(d)</enum><header>Metrics for authorization</header><text>The Administrator shall establish annual metrics regarding the time and quality of the assessments necessary for completion of a FedRAMP authorization process in a manner that can be consistently tracked over time in conjunction with the periodic testing and evaluation process pursuant to section 3554 in a manner that minimizes the agency reporting burden.</text></subsection></section><section id="idd7a8df42-0b45-4eee-941f-1e60c09eee90" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>3610.</enum><header>FedRAMP Board</header><subsection id="id32b9f93e-23a0-418a-9780-592bc6bcd5f3"><enum>(a)</enum><header>Establishment</header><text>There is established a FedRAMP Board to provide input and recommendations to the Administrator regarding the requirements and guidelines for, and the prioritization of, security assessments of cloud computing products and services.</text></subsection><subsection id="idedd94392-e480-4f4b-a608-408f0890315a"><enum>(b)</enum><header>Membership</header><text>The FedRAMP Board shall consist of not more than 7 senior officials or experts from agencies appointed by the Director, in consultation with the Administrator, from each of the following:</text><paragraph id="id54ba4c73-c1e2-4e68-9f3d-e9eed0e2b89e"><enum>(1)</enum><text>The Department of Defense.</text></paragraph><paragraph id="idac20f281-e466-41a3-8775-66fa9764fb50"><enum>(2)</enum><text>The Department of Homeland Security.</text></paragraph><paragraph id="ide539c3bb-987c-4e9e-8746-a9b30b6b1500"><enum>(3)</enum><text>The General Services Administration.</text></paragraph><paragraph id="id40deb2df-420b-4558-b691-68049b7e86ba"><enum>(4)</enum><text>Such other agencies as determined by the Director, in consultation with the Administrator.</text></paragraph></subsection><subsection id="idd985d0c7-875c-4551-9108-2abd0927a02c"><enum>(c)</enum><header>Qualifications</header><text>Members of the FedRAMP Board appointed under subsection (b) shall have technical expertise in domains relevant to FedRAMP, such as—</text><paragraph id="ida2729a9b-d6ae-480e-b6c7-5f01c32221c4"><enum>(1)</enum><text>cloud computing;</text></paragraph><paragraph id="id7bd3fe7b-caee-4146-b1e3-42160c1ebd4d"><enum>(2)</enum><text>cybersecurity;</text></paragraph><paragraph id="id64180c21-a01f-4a4a-90c2-c9a77cc991fc"><enum>(3)</enum><text>privacy;</text></paragraph><paragraph id="id4184f753-b6cf-4745-8886-63972968b2ef"><enum>(4)</enum><text>risk management; and</text></paragraph><paragraph id="id6cbdb0bf-36f6-411b-b3b5-aa348f19d8d2"><enum>(5)</enum><text>other competencies identified by the Director to support the secure authorization of cloud services and products.</text></paragraph></subsection><subsection id="idc496336f-d5a7-485b-b66d-8d1faa4e49cb"><enum>(d)</enum><header>Duties</header><text>The FedRAMP Board shall—</text><paragraph id="ide8eb76b4-b1af-451e-9f38-e7a369c6b284"><enum>(1)</enum><text>in consultation with the Administrator, serve as a resource for best practices to accelerate the process for obtaining a FedRAMP authorization;</text></paragraph><paragraph id="idd170352f-7717-4620-b27a-ee717da39043"><enum>(2)</enum><text display-inline="yes-display-inline">establish and regularly update requirements and guidelines for security authorizations of cloud computing products and services, consistent with standards and guidelines established by the Director of the National Institute of Standards and Technology, to be used in the determination of FedRAMP authorizations;</text></paragraph><paragraph id="idba753515-2e09-4a7e-b4a1-3b47ee2f2fac"><enum>(3)</enum><text display-inline="yes-display-inline">monitor and oversee, to the greatest extent practicable, the processes and procedures by which agencies determine and validate requirements for a FedRAMP authorization, including periodic review of the agency determinations described in section 3613(b);</text></paragraph><paragraph id="id6293e1f8-59cc-41b1-9b57-d02c1e6fab40"><enum>(4)</enum><text display-inline="yes-display-inline">ensure consistency and transparency between agencies and cloud service providers in a manner that minimizes confusion and engenders trust; and</text></paragraph><paragraph id="id4d91cd26-d1af-4468-896f-bb40c070af58"><enum>(5)</enum><text>perform such other roles and responsibilities as the Director may assign, with concurrence from the Administrator.</text></paragraph></subsection><subsection id="id476edd1b-7040-4c2d-be17-e78d888f3035"><enum>(e)</enum><header>Determinations of demand for cloud computing products and services</header><text>The FedRAMP Board may consult with the Chief Information Officers Council to establish a process, which may be made available on the website maintained under section 3609(b), for prioritizing and accepting the cloud computing products and services to be granted a FedRAMP authorization.</text></subsection></section><section id="id5475816B478042B6B53A396DB6E83D51" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>3611.</enum><header>Independent assessment</header><text display-inline="no-display-inline">The Administrator may determine whether FedRAMP may use an independent assessment service to analyze, validate, and attest to the quality and compliance of security assessment materials provided by cloud service providers during the course of a determination of whether to use a cloud computing product or service.</text></section><section id="id59088761-29ab-44ef-bf1d-7bda8f35c14c" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>3612.</enum><header>Declaration of foreign interests</header><subsection id="id9129CE15CEFC4A0381D3EBD7505D4E67"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">An independent assessment service that performs services described in section 3611 shall annually submit to the Administrator information relating to any foreign interest, foreign influence, or foreign control of the independent assessment service.</text></subsection><subsection id="id1065A9D21C3B470092EDDD3456ABD753"><enum>(b)</enum><header>Updates</header><text>Not later than 48 hours after there is a change in foreign ownership or control of an independent assessment service that performs services described in section 3611, the independent assessment service shall submit to the Administrator an update to the information submitted under subsection (a).</text></subsection><subsection id="id83F6262E0B734E7483BCB364EF3BFC86"><enum>(c)</enum><header>Certification</header><text display-inline="yes-display-inline">The Administrator may require a representative of an independent assessment service to certify the accuracy and completeness of any information submitted under this section.</text></subsection></section><section id="id7250b794-e393-411f-ad6d-ead9c4dce9af" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>3613.</enum><header>Roles and responsibilities of agencies</header><subsection id="iddb7ce26a-13de-476f-a23e-ec0a77dc21e1"><enum>(a)</enum><header>In general</header><text>In implementing the requirements of FedRAMP, the head of each agency shall, consistent with guidance issued by the Director pursuant to section 3614—</text><paragraph id="idba895628-fcb2-4308-a58e-196c9cadcdbf"><enum>(1)</enum><text>promote the use of cloud computing products and services that meet FedRAMP security requirements and other risk-based performance requirements as determined by the Director, in consultation with the Secretary;</text></paragraph><paragraph id="id9fa17315-4e8c-45be-8c1f-ca21f61a0844"><enum>(2)</enum><text>confirm whether there is a FedRAMP authorization in the secure mechanism provided under section 3609(a)(8) before beginning the process of granting a FedRAMP authorization for a cloud computing product or service;</text></paragraph><paragraph id="idbf6196a7-47b9-4337-8197-7ff2ed77aebd"><enum>(3)</enum><text>to the extent practicable, for any cloud computing product or service the agency seeks to authorize that has received a FedRAMP authorization, use the existing assessments of security controls and materials within any FedRAMP authorization package for that cloud computing product or service; and</text></paragraph><paragraph id="id7786178a-7a44-4b6e-84f6-14ab4985172b"><enum>(4)</enum><text>provide to the Director data and information required by the Director pursuant to section 3614 to determine how agencies are meeting metrics established by the Administrator.</text></paragraph></subsection><subsection id="id82f9ca3f-88d0-416e-a611-11fa098c8974"><enum>(b)</enum><header>Attestation</header><text display-inline="yes-display-inline">Upon completing an assessment or authorization activity with respect to a particular cloud computing product or service, if an agency determines that the information and data the agency has reviewed under paragraph (2) or (3) of subsection (a) is wholly or substantially deficient for the purposes of performing an authorization of the cloud computing product or service, the head of the agency shall document as part of the resulting FedRAMP authorization package the reasons for this determination.</text></subsection><subsection id="id3e7e0a6f-36b9-49aa-aa8b-f864bd9dd9dd"><enum>(c)</enum><header>Submission of authorizations to operate required</header><text>Upon issuance of an agency authorization to operate based on a FedRAMP authorization, the head of the agency shall provide a copy of its authorization to operate letter and any supplementary information required pursuant to section 3609(a) to the Administrator.</text></subsection><subsection id="id866108c8-9c20-40f1-b0b0-b69b969c3930"><enum>(d)</enum><header>Submission of policies required</header><text display-inline="yes-display-inline">Not later than 180 days after the date on which the Director issues guidance in accordance with section 3614(1), the head of each agency, acting through the chief information officer of the agency, shall submit to the Director all agency policies relating to the authorization of cloud computing products and services.</text></subsection><subsection id="id5f6ee4b5-5ca0-42ca-a9e3-8656b1b5373d"><enum>(e)</enum><header>Presumption of adequacy</header><paragraph id="idd1e0e08c-805e-46e6-9be2-c7521cebc967"><enum>(1)</enum><header>In general</header><text>The assessment of security controls and materials within the authorization package for a FedRAMP authorization shall be presumed adequate for use in an agency authorization to operate cloud computing products and services.</text></paragraph><paragraph id="ida6497325-4568-4885-9edf-861b710a7d14"><enum>(2)</enum><header>Information security requirements</header><text>The presumption under paragraph (1) does not modify or alter—</text><subparagraph id="idcb1dc1cd-1ffd-49fa-94d5-a85580a0aa5e"><enum>(A)</enum><text>the responsibility of any agency to ensure compliance with subchapter II of chapter 35 for any cloud computing product or service used by the agency; or</text></subparagraph><subparagraph id="id1ea70638-5e86-4bd7-9286-faf09d59810d"><enum>(B)</enum><text>the authority of the head of any agency to make a determination that there is a demonstrable need for additional security requirements beyond the security requirements included in a FedRAMP authorization for a particular control implementation.</text></subparagraph></paragraph></subsection></section><section id="id01e673ff-33e4-4344-b603-f792976693ef" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>3614.</enum><header>Roles and responsibilities of the Office of Management and Budget</header><text display-inline="no-display-inline">The Director shall—</text><paragraph id="idbe1a3952-5d35-4a84-82a5-3edd298d96e6"><enum>(1)</enum><text display-inline="yes-display-inline">in consultation with the Administrator and the Secretary, issue guidance that—</text><subparagraph id="id4cf7d0e2-54a1-44a5-a80e-5eb2f8d596ac"><enum>(A)</enum><text display-inline="yes-display-inline">specifies the categories or characteristics of cloud computing products and services that are within the scope of FedRAMP;</text></subparagraph><subparagraph id="ide756e4c0-f334-4f95-a4f4-1eddf0cb06e0"><enum>(B)</enum><text display-inline="yes-display-inline"> includes requirements for agencies to obtain a FedRAMP authorization when operating a cloud computing product or service described in subparagraph (A) as a Federal information system; and</text></subparagraph><subparagraph id="id03620dd8-742c-4339-91ec-222cb83c0ae4"><enum>(C)</enum><text display-inline="yes-display-inline">encompasses, to the greatest extent practicable, all necessary and appropriate cloud computing products and services;</text></subparagraph></paragraph><paragraph id="id5efbb209-5509-48af-ba79-fbb10dc8e067"><enum>(2)</enum><text>issue guidance describing additional responsibilities of FedRAMP and the FedRAMP Board to accelerate the adoption of secure cloud computing products and services by the Federal Government;</text></paragraph><paragraph id="id027A638C45E442CC819553D6B207777D"><enum>(3)</enum><text>in consultation with the Administrator, establish a process to periodically review FedRAMP authorization packages to support the secure authorization and reuse of secure cloud products and services;</text></paragraph><paragraph id="id2fccb57e-d79c-431b-afd6-c9f6f6e12a14"><enum>(4)</enum><text>oversee the effectiveness of FedRAMP and the FedRAMP Board, including the compliance by the FedRAMP Board with the duties described in section 3610(d); and</text></paragraph><paragraph id="id06da1bb6-e46a-49d8-b65e-a0b871a25104"><enum>(5)</enum><text>to the greatest extent practicable, encourage and promote consistency of the assessment, authorization, adoption, and use of secure cloud computing products and services within and across agencies.</text></paragraph></section><section id="idf1aaf16d-0759-47db-acf6-0929e5fb2220" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>3615.</enum><header>Reports to Congress; GAO report</header><subsection id="id9fa50d5e-2249-45db-a9fc-ecd944024b6c"><enum>(a)</enum><header>Reports to congress</header><text>Not later than 1 year after the date of enactment of this section, and annually thereafter, the Director shall submit to the appropriate congressional committees a report that includes the following:</text><paragraph id="idbe45c301-0ae0-48a4-83f4-3137b1426e63"><enum>(1)</enum><text>During the preceding year, the status, efficiency, and effectiveness of the General Services Administration under section 3609 and agencies under section 3613 and in supporting the speed, effectiveness, sharing, reuse, and security of authorizations to operate for secure cloud computing products and services.</text></paragraph><paragraph id="idda48d0bc-5442-480a-865e-9f9e0c398379"><enum>(2)</enum><text>Progress towards meeting the metrics required under section 3609(d).</text></paragraph><paragraph id="id144dc2e5-6292-42ac-aa59-2a982681add7"><enum>(3)</enum><text>Data on FedRAMP authorizations.</text></paragraph><paragraph id="id1ee20514-f674-407a-b5d6-7e28f79db0bb"><enum>(4)</enum><text>The average length of time to issue FedRAMP authorizations.</text></paragraph><paragraph id="id42ea1c2f-5562-4443-82fa-aeff9e83dcbd"><enum>(5)</enum><text>The number of FedRAMP authorizations submitted, issued, and denied for the preceding year.</text></paragraph><paragraph id="id0be13f29-a7d3-42e8-8f14-75500808ae75"><enum>(6)</enum><text>A review of progress made during the preceding year in advancing automation techniques to securely automate FedRAMP processes and to accelerate reporting under this section.</text></paragraph><paragraph id="id8f8cfea3-bcc1-48fc-af01-3aa92941caf3"><enum>(7)</enum><text>The number and characteristics of authorized cloud computing products and services in use at each agency consistent with guidance provided by the Director under section 3614.</text></paragraph><paragraph id="idFDFC5DA7D4654BAC8C349CA0B17CC099"><enum>(8)</enum><text>A review of FedRAMP measures to ensure the security of data stored or processed by cloud service providers, which may include—</text><subparagraph id="id075501715B9E492CAC2726695F1C992A"><enum>(A)</enum><text>geolocation restrictions for provided products or services;</text></subparagraph><subparagraph id="idAE71822785A9425EB687E4F3056E9193"><enum>(B)</enum><text>disclosures of foreign elements of supply chains of acquired products or services;</text></subparagraph><subparagraph id="id1336609BC34549358409A5A27DBD292C"><enum>(C)</enum><text>continued disclosures of ownership of cloud service providers by foreign entities; and</text></subparagraph><subparagraph id="idB98435CCC8A34DDD9325DAB97D971ABA"><enum>(D)</enum><text>encryption for data processed, stored, or transmitted by cloud service providers.</text></subparagraph></paragraph></subsection><subsection id="id28e57daf-82ad-412a-80b4-95d29ee76bc4"><enum>(b)</enum><header>GAO report</header><text>Not later than 180 days after the date of enactment of this section, the Comptroller General of the United States shall report to the appropriate congressional committees an assessment of the following:</text><paragraph id="id40c36318-c49e-4e0a-9160-61f7e74c1f39"><enum>(1)</enum><text>The costs incurred by agencies and cloud service providers relating to the issuance of FedRAMP authorizations.</text></paragraph><paragraph id="id10e5b74a-7d41-464b-b9fd-f84297e22042"><enum>(2)</enum><text>The extent to which agencies have processes in place to continuously monitor the implementation of cloud computing products and services operating as Federal information systems.</text></paragraph><paragraph id="ideaf5ef5c-b7a9-4680-8c22-76dcc1144582"><enum>(3)</enum><text>How often and for which categories of products and services agencies use FedRAMP authorizations.</text></paragraph><paragraph id="id1e853aaa-8fc5-45c0-bb86-f1a905709f1b"><enum>(4)</enum><text>The unique costs and potential burdens incurred by cloud computing companies that are small business concerns (as defined in section 3(a) of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632(a)</external-xref>) as a part of the FedRAMP authorization process.</text></paragraph></subsection></section><section id="id90dc5d8a-eeea-4cd2-9b09-15d9bbc028a6" changed="added" committee-id="SSGA00" reported-display-style="italic"><enum>3616.</enum><header>Federal Secure Cloud Advisory Committee</header><subsection id="idf1544ebb-d264-4a71-be75-354a2342ec71"><enum>(a)</enum><header>Establishment, purposes, and duties</header><paragraph id="id655066c5-7d8e-4e97-8a72-f1f5f8169c0d"><enum>(1)</enum><header>Establishment</header><text>There is established a Federal Secure Cloud Advisory Committee (referred to in this section as the <quote>Committee</quote>) to ensure effective and ongoing coordination of agency adoption, use, authorization, monitoring, acquisition, and security of cloud computing products and services to enable agency mission and administrative priorities.</text></paragraph><paragraph id="id41d24fe0-0428-4a3e-a61e-f78df7a8af36"><enum>(2)</enum><header>Purposes</header><text>The purposes of the Committee are the following:</text><subparagraph id="idd482c4b6-65d8-4879-930d-e7af5fce93a4"><enum>(A)</enum><text>To examine the operations of FedRAMP and determine ways that authorization processes can continuously be improved, including the following:</text><clause id="id8f127f19-e9b1-467f-8753-52cf53f5bac5"><enum>(i)</enum><text>Measures to increase agency reuse of FedRAMP authorizations.</text></clause><clause id="id07bbc998-fb1d-41c3-b7dc-06cf0d29ac97"><enum>(ii)</enum><text display-inline="yes-display-inline">Proposed actions that can be adopted to reduce the burden, confusion, and cost associated with FedRAMP authorizations for cloud service providers.</text></clause><clause id="id0b172e4f-09a0-41ce-a777-30fdb92dbe6d"><enum>(iii)</enum><text>Measures to increase the number of FedRAMP authorizations for cloud computing products and services offered by small businesses concerns (as defined by section 3(a) of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632(a)</external-xref>).</text></clause><clause id="id3c582c35-3905-462a-9fc7-55e1df80d5b4"><enum>(iv)</enum><text display-inline="yes-display-inline">Proposed actions that can be adopted to reduce the burden and cost of FedRAMP authorizations for agencies.</text></clause></subparagraph><subparagraph id="id48590dc8-960c-4696-8b4c-fe7b01f0a58e"><enum>(B)</enum><text>Collect information and feedback on agency compliance with and implementation of FedRAMP requirements.</text></subparagraph><subparagraph id="id41c0d7f6-d9ee-4320-b879-64d1f7bf4c3d"><enum>(C)</enum><text>Serve as a forum that facilitates communication and collaboration among the FedRAMP stakeholder community.</text></subparagraph></paragraph><paragraph id="id8535a84b-1cd2-4471-a2c9-39682957edd9"><enum>(3)</enum><header>Duties</header><text>The duties of the Committee include providing advice and recommendations to the Administrator, the FedRAMP Board, and agencies on technical, financial, programmatic, and operational matters regarding secure adoption of cloud computing products and services.</text></paragraph></subsection><subsection id="id7e50ab43-2603-45a9-b69b-8ae62db44f0d"><enum>(b)</enum><header>Members</header><paragraph id="ida5d01c54-af60-40a2-9741-7f5a9576245b"><enum>(1)</enum><header>Composition</header><text>The Committee shall be comprised of not more than 15 members who are qualified representatives from the public and private sectors, appointed by the Administrator, in consultation with the Director, as follows:</text><subparagraph id="idc211f393-ae45-4ce6-9467-0a7d238d175c"><enum>(A)</enum><text>The Administrator or the Administrator’s designee, who shall be the Chair of the Committee.</text></subparagraph><subparagraph id="idfeff7848-aa45-4f9b-b6bf-60d06506d0ef"><enum>(B)</enum><text>At least 1 representative each from the Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology.</text></subparagraph><subparagraph id="iddade6e42-7af4-4524-a19f-769da7637b58"><enum>(C)</enum><text>At least 2 officials who serve as the Chief Information Security Officer within an agency, who shall be required to maintain such a position throughout the duration of their service on the Committee.</text></subparagraph><subparagraph id="idf0f14cb4-9386-4ed8-8a29-f4225edafbf8"><enum>(D)</enum><text>At least 1 official serving as Chief Procurement Officer (or equivalent) in an agency, who shall be required to maintain such a position throughout the duration of their service on the Committee.</text></subparagraph><subparagraph id="id40a940b4-9bff-489e-9ef4-dec9f6b3e210"><enum>(E)</enum><text>At least 1 individual representing an independent assessment service.</text></subparagraph><subparagraph id="idcbf1a2ae-1b08-4b83-b56d-07285720a3c4"><enum>(F)</enum><text>At least 5 representatives from unique businesses that primarily provide cloud computing services or products, including at least 2 representatives from a small business concern (as defined by section 3(a) of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632(a)</external-xref>)).</text></subparagraph><subparagraph id="id11f81343-1d47-403b-b31e-5a3b82c3d6dc"><enum>(G)</enum><text>At least 2 other representatives of the Federal Government as the Administrator determines necessary to provide sufficient balance, insights, or expertise to the Committee.</text></subparagraph></paragraph><paragraph id="id35ae1acc-297d-4fa5-9335-e8c1992cd494"><enum>(2)</enum><header>Deadline for appointment</header><text>Each member of the Committee shall be appointed not later than 90 days after the date of enactment of this section.</text></paragraph><paragraph id="id402d5c15-359c-470e-b83f-4475919ca0ba"><enum>(3)</enum><header>Period of appointment; vacancies</header><subparagraph id="idbda8b955-bb9c-4a1b-a635-5fbdd8dad012"><enum>(A)</enum><header>In general</header><text>Each non-Federal member of the Committee shall be appointed for a term of 3 years, except that the initial terms for members may be staggered 1-, 2-, or 3-year terms to establish a rotation in which one-third of the members are selected each year. Any such member may be appointed for not more than 2 consecutive terms.</text></subparagraph><subparagraph id="id3d23b48e-b4d6-468a-8d14-2702c997b1ad"><enum>(B)</enum><header>Vacancies</header><text>Any vacancy in the Committee shall not affect its powers, but shall be filled in the same manner in which the original appointment was made. Any member appointed to fill a vacancy occurring before the expiration of the term for which the member’s predecessor was appointed shall be appointed only for the remainder of that term. A member may serve after the expiration of that member’s term until a successor has taken office.</text></subparagraph></paragraph></subsection><subsection id="id878cd17f-9f11-4e3f-bf4b-06eae5350360"><enum>(c)</enum><header>Meetings and rules of procedures</header><paragraph id="id26dbc8d7-55e4-4178-a39c-b415a3f02d54"><enum>(1)</enum><header>Meetings</header><text>The Committee shall hold not fewer than 3 meetings in a calendar year, at such time and place as determined by the Chair.</text></paragraph><paragraph id="id4e611964-1d2f-41c5-99e7-21d32a252e0b"><enum>(2)</enum><header>Initial meeting</header><text>Not later than 120 days after the date of enactment of this section, the Committee shall meet and begin the operations of the Committee.</text></paragraph><paragraph id="ida5eb30db-c0ff-4f5d-a13b-dab90fb7cfae"><enum>(3)</enum><header>Rules of procedure</header><text>The Committee may establish rules for the conduct of the business of the Committee if such rules are not inconsistent with this section or other applicable law.</text></paragraph></subsection><subsection id="id0c76aaac-2e9c-4945-80c9-99ff4e6ebb87"><enum>(d)</enum><header>Employee status</header><paragraph id="id2cbd2375-1b63-4beb-8c65-005f8a1429e5"><enum>(1)</enum><header>In general</header><text>A member of the Committee (other than a member who is appointed to the Committee in connection with another Federal appointment) shall not be considered an employee of the Federal Government by reason of any service as such a member, except for the purposes of section 5703 of title 5, relating to travel expenses.</text></paragraph><paragraph id="id7f92022c-41f8-4d41-8ded-34eb5a176be9"><enum>(2)</enum><header>Pay not permitted</header><text>A member of the Committee covered by paragraph (1) may not receive pay by reason of service on the Committee.</text></paragraph></subsection><subsection id="id3652bb47-2f6e-4291-8bef-c518430ff2ff"><enum>(e)</enum><header>Applicability to the federal advisory committee act</header><text>Section 14 of the Federal Advisory Committee Act (5 U.S.C. App.) shall not apply to the Committee.</text></subsection><subsection id="id19f9de2a-c45a-4048-bd4d-5242e2b8df0a"><enum>(f)</enum><header>Detail of employees</header><text>Any Federal Government employee may be detailed to the Committee without reimbursement from the Committee, and such detailee shall retain the rights, status, and privileges of his or her regular employment without interruption.</text></subsection><subsection id="id498aefbc-1168-433c-88b5-3349126fb107"><enum>(g)</enum><header>Postal services</header><text>The Committee may use the United States mails in the same manner and under the same conditions as agencies.</text></subsection><subsection id="id8897a880-02ce-48ac-83a9-cb3b754f53c3"><enum>(h)</enum><header>Reports</header><paragraph id="idec560c98-e330-4982-9b13-aa67fe2480fe"><enum>(1)</enum><header>Interim reports</header><text>The Committee may submit to the Administrator and Congress interim reports containing such findings, conclusions, and recommendations as have been agreed to by the Committee.</text></paragraph><paragraph id="ida967136d-2b7b-48d4-a6ca-ad34f9932bed"><enum>(2)</enum><header>Annual reports</header><text>Not later than 540 days after the date of enactment of this section, and annually thereafter, the Committee shall submit to the Administrator and Congress a report containing such findings, conclusions, and recommendations as have been agreed to by the Committee.</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="id1bdd60c9-33e1-45c2-9fdd-75292a55e6ee"><enum>(b)</enum><header>Technical and conforming amendment</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">chapter 36</external-xref> of title 44, United States Code, is amended by adding at the end the following new items:</text><quoted-block style="USC" id="id2e1f4858-af80-478c-8e5e-25d97d0c7fa6" changed="not-changed"><toc changed="not-changed"><toc-entry level="section" changed="added" committee-id="SSGA00" reported-display-style="italic">3607. Definitions. </toc-entry><toc-entry level="section" changed="added" committee-id="SSGA00" reported-display-style="italic">3608. Federal Risk and Authorization Management Program. </toc-entry><toc-entry level="section" changed="added" committee-id="SSGA00" reported-display-style="italic">3609. Roles and responsibilities of the General Services Administration. </toc-entry><toc-entry level="section" changed="added" committee-id="SSGA00" reported-display-style="italic">3610. FedRAMP Board. </toc-entry><toc-entry level="section" idref="id5475816B478042B6B53A396DB6E83D51" changed="added" committee-id="SSGA00" reported-display-style="italic">3611. Independent assessment. </toc-entry><toc-entry level="section" changed="added" committee-id="SSGA00" reported-display-style="italic">3612. Declaration of foreign interests. </toc-entry><toc-entry level="section" changed="added" committee-id="SSGA00" reported-display-style="italic">3613. Roles and responsibilities of agencies. </toc-entry><toc-entry level="section" changed="added" committee-id="SSGA00" reported-display-style="italic">3614. Roles and responsibilities of the Office of Management and Budget. </toc-entry><toc-entry level="section" changed="added" committee-id="SSGA00" reported-display-style="italic">3615. Reports to Congress; GAO report. </toc-entry><toc-entry level="section" changed="added" committee-id="SSGA00" reported-display-style="italic">3616. Federal Secure Cloud Advisory Committee.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="id4A6D4A35B3BD4C4D92D0BAAF00598CEA"><enum>(c)</enum><header>Sunset</header><paragraph id="id5B3BBD86A4C54738BDF6C5925AF4903E"><enum>(1)</enum><header>In general</header><text>Effective on the date that is 5 years after the date of enactment of this Act, <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">chapter 36</external-xref> of title 44, United States Code, is amended by striking sections 3607 through 3616.</text></paragraph><paragraph id="idf7939d5d-ba95-4f85-ab97-cf078eccb335" commented="no" display-inline="no-display-inline"><enum>(2)</enum><header>Conforming amendment</header><text>Effective on the date that is 5 years after the date of enactment of this Act, the table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">chapter 36</external-xref> of title 44, United States Code, is amended by striking the items relating to sections 3607 through 3616.</text></paragraph></subsection><subsection id="id42827d14-1406-4d0a-ab75-2122b2e310d7" commented="no" display-inline="no-display-inline"><enum>(d)</enum><header>Rule of construction</header><text>Nothing in this section or any amendment made by this section shall be construed as altering or impairing the authorities of the Director of the Office of Management and Budget or the Secretary of Homeland Security under subchapter II of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code.</text></subsection></section></legis-body><endorsement><action-date>May 24, 2022</action-date><action-desc>Reported with an amendment</action-desc></endorsement></bill> 

