<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-HEN21G61-YFY-2T-LHC"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S3408 IS: Federal Cloud Risk Management Improvements Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-12-15</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 3408</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20211215">December 15, 2021</action-date><action-desc><sponsor name-id="S414">Mr. Ossoff</sponsor> introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To amend <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">chapter 36</external-xref> of title 44, United States Code, to require reporting regarding the security of cloud computing products and services.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Federal Cloud Risk Management Improvements Act</short-title></quote>.</text></section><section section-type="subsequent-section" id="idC5A1C7C73EC44FD39E2AE49392884DA2"><enum>2.</enum><header>Reporting regarding security of cloud computing products and services</header><subsection id="idc1d6a055a5f14e3cac27273497bc9bf7"><enum>(a)</enum><header>In general</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">Chapter 36</external-xref> of title 44, United States Code, is amended by adding at the end the following:</text><quoted-block style="USC" display-inline="no-display-inline" id="idc43ea50a057248a39317be64683a6b1a"><section id="idafe0de1c7b3f49f9b0ae0aa500dc903d" section-type="subsequent-section"><enum>3607.</enum><header>Reporting regarding security of cloud computing products and services</header><subsection id="id44E9BFD35F02420EB537B86C340AF8A9"><enum>(a)</enum><header>Definitions</header><text>In this section: </text><paragraph id="id5A13CC0018004D338024E94820DE36A6"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given the term in section 3502.</text></paragraph><paragraph id="idF10F54815F9A436189746D1126A94C75"><enum>(2)</enum><header>Cloud computing</header><text>The term <term>cloud computing</term> has the meaning given the term in Special Publication 800–145 of the National Institute of Standards and Technology, or any successor document.</text></paragraph><paragraph id="id00DA9C62F09E4FFB8479D241672CA715"><enum>(3)</enum><header>Cloud service provider</header><text>The term <term>cloud service provider</term> means an entity offering cloud computing products or services to agencies. </text></paragraph></subsection><subsection id="id5C0E337EBA5B4A5285264259B2BA1E3E"><enum>(b)</enum><header>Reporting</header><text display-inline="yes-display-inline">Not later than 1 year after the date of enactment of this section, and annually thereafter, the Administrator of General Services shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives a report that includes a review of measures taken under the Federal Risk and Authorization Management Program, or any successor thereto, to ensure the security of data stored or processed by cloud service providers, which may include—</text><paragraph id="idf8a28b3e77eb4692b6f0557bbf82a84c"><enum>(1)</enum><text>geolocation restrictions for provided products or services;</text></paragraph><paragraph id="id74c803a65a904de5b5f04d1aecb8f041"><enum>(2)</enum><text>disclosures of foreign elements of supply chains of acquired products or services;</text></paragraph><paragraph id="idc1f747f4dc914135a95bbcd14065eb58"><enum>(3)</enum><text>regular disclosures of ownership of cloud service providers by foreign entities; and</text></paragraph><paragraph id="id4b8dfdacec394d2ebe44225e6b773c4c"><enum>(4)</enum><text>encryption requirements for data processed, stored, or transmitted by cloud service providers.</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="id419946262A674310B8CE34568521A605"><enum>(b)</enum><header>Conforming amendment</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/36">chapter 36</external-xref> of title 44, United States Code, is amended by adding at the end the following:</text><quoted-block style="USC" id="id07427643-8e24-4d89-a38d-63c5f78722ae"><toc><toc-entry level="section" idref="idafe0de1c7b3f49f9b0ae0aa500dc903d">3607. Reporting regarding security of cloud computing products and services.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section></legis-body></bill> 

