<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-LIP22573-6XG-SV-T4K"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>114 S4908 IS: Strengthening Agency Management and Oversight of Software Assets Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2022-09-21</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>2d Session</session><legis-num>S. 4908</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20220921">September 21, 2022</action-date><action-desc><sponsor name-id="S380">Mr. Peters</sponsor> (for himself and <cosponsor name-id="S373">Mr. Cassidy</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To improve the visibility, accountability, and oversight of agency software asset management practices, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Strengthening Agency Management and Oversight of Software Assets Act</short-title></quote>.</text></section><section id="id8CD6AAAB634445A99B0092831893C173"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="idB20A9899767947B6BE9BE999D50DFD6B"><enum>(1)</enum><header>Administrator</header><text>The term <term>Administrator</term> means the Administrator of General Services.</text></paragraph><paragraph id="idFAC882F82C874878B794024EA07DDDDB"><enum>(2)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given the term <term>establishment</term> in <external-xref legal-doc="usc-act" parsable-cite="usc-act/Inspector General Act of 1978 /12">section 12</external-xref> of the Inspector General Act of 1978 (5 U.S.C. App.).</text></paragraph><paragraph id="id1FECAFE36717499A83E5344C56C4B8E4"><enum>(3)</enum><header>Cloud computing</header><text>The term <term>cloud computing</term> has the meaning given the term in Special Publication 800–145 of the National Institute of Standards and Technology, or any successor document.</text></paragraph><paragraph id="id1839807350FC4908BFACDD96198A341E"><enum>(4)</enum><header>Cloud service provider</header><text>The term <term>cloud service provider</term> means an entity offering cloud computing products or services to agencies. </text></paragraph><paragraph id="id2CBF1E653EBE4B29BD87659AA0EF4071"><enum>(5)</enum><header>Comprehensive assessment</header><text>The term <term>comprehensive assessment</term> means a comprehensive assessment conducted pursuant to section 3(a).</text></paragraph><paragraph id="idC02D2DEDA7834990A80D484607CBDA10"><enum>(6)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the Office of Management and Budget.</text></paragraph><paragraph id="idAC1F7F27494D4324BF0ACDA121C719B5"><enum>(7)</enum><header>Plan</header><text>The term <term>plan</term> means the plan developed by a Chief Information Officer, or equivalent official, pursuant to section 4(a).</text></paragraph><paragraph id="idd8b46b28615e47fb85b58ede3f7d02c2"><enum>(8)</enum><header>Software entitlement</header><text>The term <term>software entitlement</term> means any software that—</text><subparagraph id="id683260A1CCA242A595C773D931AE5E21"><enum>(A)</enum><text>has been purchased, leased, or licensed by or billed to an agency under any contract or other business arrangement; and </text></subparagraph><subparagraph id="id7A8F4B293A804B8C8C872B8CE44C6A96"><enum>(B)</enum><text>is subject to use limitations. </text></subparagraph></paragraph><paragraph id="id91FDEA1470684B01B38298307A416FBE"><enum>(9)</enum><header>Software inventory</header><text>The term <term>software inventory</term> means the software inventory of an agency required pursuant to—</text><subparagraph id="id6C1A2E888A1740DAB174E3165A27F2A0"><enum>(A)</enum><text>section 2(b)(2)(A) of the Making Electronic Government Accountable By Yielding Tangible Efficiencies Act of 2016 (<external-xref legal-doc="usc" parsable-cite="usc/40/11302">40 U.S.C. 11302</external-xref> note; <external-xref legal-doc="public-law" parsable-cite="pl/114/210">Public Law 114–210</external-xref>); or </text></subparagraph><subparagraph id="id86211A8F25A74284A7F20ECCC2F39B23"><enum>(B)</enum><text>subsequent guidance issued by the Director of the Office of Management and Budget pursuant to that Act.</text></subparagraph></paragraph></section><section id="idD23FF21F51074097BA397183AE9FAE0E"><enum>3.</enum><header>Software entitlement and inventory integrity</header><subsection id="id0dcd0064962b48fda19cfdf8284f007d"><enum>(a)</enum><header>In general</header><text>As soon as practicable, and not later than 1 year after the date of enactment of this Act, the Chief Information Officer of each agency, in consultation with the Chief Financial Officer, the Chief Procurement Officer, and General Counsel of the agency, or the equivalent officials of the agency, shall complete a comprehensive assessment of the software entitlements and software inventories of the agency, which shall include—</text><paragraph id="idE311D6F08D64468AA4B2B9E9F84D6B70"><enum>(1)</enum><text>the current software inventory of the agency, including software entitlements, contracts and other agreements or arrangements of the agency, and a list of the largest software entitlements of the agency separated by vendor;</text></paragraph><paragraph id="id7a7e6a3a78094b839c83a0ecae9c93f3"><enum>(2)</enum><text>a comprehensive, detailed accounting of—</text><subparagraph id="id959c0fcdfb314adf9bf095d830bfb33c"><enum>(A)</enum><text>any software deployed for the agency as of the date of the comprehensive assessment, including, to the extent identifiable, the contracts and other agreements or arrangements that the agency uses to acquire, deploy, or use such software;</text></subparagraph><subparagraph id="id1054aeeffc5a421ba41bd90d6c773c78"><enum>(B)</enum><text>information and data on software entitlements—</text><clause id="id9fc0c27657f14935b4ca7aab38233d22"><enum>(i)</enum><text>for which the agency pays;</text></clause><clause id="id0df0c93cb9ef4a15a4e793619429b1ce"><enum>(ii)</enum><text>that are not deployed or in use by the agency; and</text></clause><clause id="iddb666bb630834560affe8f1a5df18b1b"><enum>(iii)</enum><text>that are billed to the agency under any contract or business arrangement that creates redundancy in the deployment or use by the agency; and</text></clause></subparagraph><subparagraph id="id96cf94c65d8d48acb3861b0bc83720ae"><enum>(C)</enum><text>the extent—</text><clause id="idD360776749D848C9BB6A11EBC7D6A5A6"><enum>(i)</enum><text>to which any software paid for, in use, or deployed throughout the agency is interoperable; and </text></clause><clause id="idD1E35BD0599043B78180AE7771AF6E2D"><enum>(ii)</enum><text>of the efforts of the agency to improve interoperability of software assets throughout the agency enterprise;</text></clause></subparagraph></paragraph><paragraph id="id88f783baf7cf4c73a1b32fd7d894c355"><enum>(3)</enum><text>a categorization of software licenses of the agency by costs and volume;</text></paragraph><paragraph id="id9009cdf6d1164f338efa3d5e6974db45"><enum>(4)</enum><text>a list of any provisions in the software licenses of the agency that may restrict how the software can be deployed or accessed, either on desktop or server hardware or through a cloud service provider; and</text></paragraph><paragraph id="idA625F66FF3874BC68F1A24A37E5C122E"><enum>(5)</enum><text>an analysis addressing—</text><subparagraph id="idFDEA0D6AB9FF4B3AB847D70842D43464"><enum>(A)</enum><text>the accuracy and completeness of the software inventory and software entitlements of the agency before and after the comprehensive assessment;</text></subparagraph><subparagraph id="id42ba7e42f302428f8af440a877d92eb9"><enum>(B)</enum><text>management by the agency of and compliance by the agency with all contracts or other agreements or arrangements that include or implicate software licensing or software management within the agency;</text></subparagraph><subparagraph id="id508e7bc10e32428fb75def3cc935405b"><enum>(C)</enum><text>the extent to which the agency accurately captures the total costs of enterprise licenses agreements and related costs; and</text></subparagraph><subparagraph id="iddf8991106efa4986a06dd19ba160e8bd"><enum>(D)</enum><text>compliance with software license management policies of the agency. </text></subparagraph></paragraph></subsection><subsection id="id9fc95cff5ec44f40964de23ea9987895"><enum>(b)</enum><header>Contract support</header><paragraph id="id2C5F5B412D8E43359B0243779BE8B5F0"><enum>(1)</enum><header>Authority</header><text>The head of an agency may enter into 1 or more contracts to support the requirements of subsection (a).</text></paragraph><paragraph id="id5D0106167F6541348F1F8C15726592B9"><enum>(2)</enum><header>No conflict of interest</header><text>Contracts under paragraph (1) shall not include contractors with organization conflicts of interest.</text></paragraph><paragraph id="idB9CA9C3EF0B24C51A9FAA228A77200F6"><enum>(3)</enum><header>Operational independence</header><text>Over the course of a comprehensive assessment, contractors hired pursuant to paragraph (1) shall maintain operational independence from the integration, management, and operations of the software inventory and software entitlements of the agency. </text></paragraph></subsection><subsection id="id88650690d59f427aa850f88dcc7f736f"><enum>(c)</enum><header>Submission</header><text>On the date on which the Chief Information Officer, Chief Financial Officer, Chief Procurement Officer, and General Counsel of an agency, or the equivalent officials of the agency, complete the comprehensive assessment, and not later than 1 year after the date of enactment of this Act, the Chief Information Officer shall submit the comprehensive assessment to—</text><paragraph id="id462242CB8C7C45E79AA2017A20C1E4F0"><enum>(1)</enum><text>the head of the agency;</text></paragraph><paragraph id="idF44EF37228D7455C8DE5F028F7385215"><enum>(2)</enum><text>the Director;</text></paragraph><paragraph id="idC2ADDBEBAE7C4531A55A4B75977D825D"><enum>(3)</enum><text>the Administrator;</text></paragraph><paragraph id="id4AF6149B93174C099DF003C59CFE7B16"><enum>(4)</enum><text>the Comptroller General of the United States;</text></paragraph><paragraph id="idAD25E5E0B07E4F84A7EBA93510FC2403"><enum>(5)</enum><text>the Committee on Homeland Security and Governmental Affairs of the Senate; and</text></paragraph><paragraph id="id6E0012C52AC44B528B38EB880D45883B"><enum>(6)</enum><text>the Committee on Oversight and Reform of the House of Representatives.</text></paragraph></subsection><subsection id="id13e69fa399b44f8899fe85d9be7ffd22"><enum>(d)</enum><header>Consultation</header><text>In order to ensure the utility and standardization of the comprehensive assessment of each agency, including to support the development of each plan and the governmentwide strategy described in section 5, the Director, in consultation with the Administrator, may share information, best practices, and recommendations relating to the activities performed in the course of a comprehensive assessment of an agency. </text></subsection></section><section id="id96caab61b2d74ce7916dcb539b8fc271"><enum>4.</enum><header>Enterprise Licensing Positioning at Agencies</header><subsection id="id454ee3bfb63b4fb5a8464df09e7f141b"><enum>(a)</enum><header>In general</header><text>The Chief Information Officer of each agency, in consultation with the Chief Financial Officer and the Chief Procurement Officer of the agency, or the equivalent officials of the agency, shall use the information developed pursuant to the comprehensive assessment of the agency under section 3(a) to develop a plan for the agency to—</text><paragraph id="id796CD4ED93114EA8A87CFDE3079ACCB3"><enum>(1)</enum><text>consolidate software licenses of the agency; and </text></paragraph><paragraph id="id98039A4D3BC049B6B12923F90F244D2E"><enum>(2)</enum><text>to the greatest extent practicable, in order to improve the performance of, or reduce unnecessary costs to, the agency, adopt enterprise license agreements across the agency.</text></paragraph></subsection><subsection id="id8d44998492ff4ef880f6bce8b1ed2a37"><enum>(b)</enum><header>Plan requirements</header><text>The plan of an agency shall—</text><paragraph id="id66DD83C3B8FF40D4BEB7A5CC3569C102"><enum>(1)</enum><text>include a detailed strategy for—</text><subparagraph id="id26B69892768E49669B45A65F2209A9E8"><enum>(A)</enum><text>the remediation of any software asset management deficiencies found during the comprehensive assessment of the agency; </text></subparagraph><subparagraph id="idAB0C70249DE0400C847768F3FF058AE8"><enum>(B)</enum><text>the ongoing maintenance of software asset management upon the completion of the remediation; and</text></subparagraph><subparagraph id="iddde8adc3e7f344358bf92fe42618c7bb"><enum>(C)</enum><text>maximizing the effectiveness of software deployed by the agency, including, to the extent practicable, leveraging technologies that—</text><clause id="idc1fd6efaba9c4c49a545f0a8e2cc593d"><enum>(i)</enum><text>provide in-depth analysis of user behaviors and collect user feedback;</text></clause><clause id="ida9f721eeadc546389eaad031f8dfebdf"><enum>(ii)</enum><text>measure actual software usage via analytics that can identify inefficiencies to assist in rationalizing software spending;</text></clause><clause id="id8df02125159541879e571d82a44565c5"><enum>(iii)</enum><text>allow for segmentation of the user base; and</text></clause><clause id="idc8431351ebd143698ae556b1d5119a22"><enum>(iv)</enum><text>support effective governance and compliance in the use of software;</text></clause></subparagraph></paragraph><paragraph id="id534fdfe79fe14f88b05f3b5541dd7e66"><enum>(2)</enum><text>identify not fewer than 5 categories of software the agency will prioritize for conversion to enterprise licenses as the software entitlements, contracts, and other agreements or arrangements for those categories come up for renewal or renegotiation;</text></paragraph><paragraph id="id62e9e1441dc54128ae6d895608928bb8"><enum>(3)</enum><text>provide an estimate of the costs to move to enterprise, open-source, or other licenses that do not restrict the use of software by the agency, and any projected cost savings or efficiency measures;</text></paragraph><paragraph id="idf19131357ddb482b80092f5009e7da8a"><enum>(4)</enum><text>identify potential mitigations to minimize software license restrictions on how such software can be deployed or accessed, either on desktop or server hardware or through a cloud service provider;</text></paragraph><paragraph id="id601C490F23BB4404B516AE603B8D6001"><enum>(5)</enum><text>include any estimates for additional resources, services, or support the agency may need to execute the enterprise licensing position plan; and</text></paragraph><paragraph id="idcb0b0b48b28a42b3a6ce136bb6ccfabe"><enum>(6)</enum><text>include any additional information, data, or analysis determined necessary by the Chief Information Officer, or other equivalent official, of the agency.</text></paragraph></subsection><subsection id="id3d3b2c5fc6b44f9db289892a790a06d1"><enum>(c)</enum><header>Support</header><text>The Chief Information Officer, or other equivalent official, of an agency may request support from the Director and the Administrator for any analysis or developmental needs to create the plan of the agency.</text></subsection><subsection id="id1F24892D9E0F4B03AB6A9D80DA921138"><enum>(d)</enum><header>Submission</header><text>Not later than 120 days after the date on which the Chief Information Officer, or other equivalent official, of an agency submits the comprehensive assessment pursuant to section 3(c), the head of the agency shall submit to the Director, the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs of the Senate</committee-name>, and the <committee-name committee-id="">Committee on Oversight and Reform of the House of Representatives</committee-name> the plan of the agency.</text></subsection></section><section id="id39d345727b02444093b7c01dd1955f22"><enum>5.</enum><header>Governmentwide strategy</header><subsection id="id0EC7FBD0E2184AB5AA6092B33F7B6928"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 2 years after the date of enactment of this Act, the Director, in consultation with the Administrator and the Federal Chief Information Officers Council, shall submit to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs of the Senate</committee-name> and the <committee-name committee-id="">Committee on Oversight and Reform of the House of Representatives</committee-name> a strategy that includes—</text><paragraph id="id3B0DBEB7BAF44E8190529CEFFF2C4E91"><enum>(1)</enum><text>proposals to support the adoption of governmentwide enterprise licenses on the most widely used and most costly software entitlements identified through the comprehensive assessment and plans, including, where appropriate, a cost-benefit analysis;</text></paragraph><paragraph id="idbbb404bcd75540d8a48b55fdeba98ec5"><enum>(2)</enum><text>opportunities to leverage Government procurement policies and practices to increase interoperability of software entitlements acquired and deployed to reduce costs and improve performance; </text></paragraph><paragraph id="idEC65422B9D8C41C9B38C78BF214A8B50"><enum>(3)</enum><text>the incorporation of data on spending by agencies on, the performance of, and management by agencies of software entitlements as part of the information required under section 11302(c)(3)(B) of title 40, United States Code;</text></paragraph><paragraph id="idAAF85EEE8C0C4A59936DFB801037AF09"><enum>(4)</enum><text>where applicable, directions to agencies to transition to open-source software to obtain cost savings and performance improvement; and</text></paragraph><paragraph id="idC08CC9EF20BC469BBAABE14055C4F5AF"><enum>(5)</enum><text>any other information or data collected or analyzed by the Director.</text></paragraph></subsection><subsection id="id42572FAB5FA243FBB4FDEF329AF55655"><enum>(b)</enum><header>Budget Submission</header><paragraph id="idEAA4A443B0BD48D2B2199CE2AD7A4A25"><enum>(1)</enum><header>First budget</header><text>With respect to the first budget of the President submitted under section 1105(a) of title 31, United States Code, on or after the date that is 2 years after the date of enactment of this Act, the Director shall ensure that the strategy required under subsection (a) of this section and the plan of each agency are included in the budget justification materials of each agency submitted in conjunction with that budget.</text></paragraph><paragraph id="idAACCA3B316494BBEABB063927FE5C4C9"><enum>(2)</enum><header>Subsequent 5 budgets</header><text>With respect to the first 5 budgets of the President submitted under section 1105(a) of title 31, United States Code, after the budget described in paragraph (1), the Director shall—</text><subparagraph id="id33A1962033624EB89DC9EB47C731DB9B"><enum>(A)</enum><text>designate performance metrics for agencies for common software licensing, management, and cost criteria; and </text></subparagraph><subparagraph id="id36670EF34D1C4CE5B0CF9E09D2FDF581"><enum>(B)</enum><text>ensure that the progress of each agency toward the performance metrics is included in the budget justification materials of the agency submitted in conjunction with that budget.</text></subparagraph></paragraph></subsection></section><section id="id3338e4b8c09f469b85ed04d08ce49844"><enum>6.</enum><header>GAO report</header><text display-inline="no-display-inline">Not later than 3 years after the date of enactment of this Act, the Comptroller General of the United States shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives a report on governmentwide trends, comparisons among agencies, and other analyses of plans and the strategy required under section 5(a) by the Comptroller General of the United States.</text></section></legis-body></bill> 

