<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-ALL23353-48F-X7-KG0"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 S2032 IS: Legacy IT Reduction Act of 2023</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2023-06-15</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>1st Session</session><legis-num>S. 2032</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20230615">June 15, 2023</action-date><action-desc><sponsor name-id="S388">Ms. Hassan</sponsor> (for herself and <cosponsor name-id="S287">Mr. Cornyn</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the reduction of the reliance and expenditures of the Federal Government on legacy information technology systems, and for other purposes.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause" changed="not-changed"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Legacy IT Reduction Act of 2023</short-title></quote>.</text></section><section id="idB638C7C8B4E04857A7138870837ED7DA"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="id0F1C296F1E1F4A73BF47D147E43AB240"><enum>(1)</enum><header>Administrator</header><text>The term <term>Administrator</term> means the Administrator of General Services.</text></paragraph><paragraph id="idB5720877D55F4D23ACE7979F1BCF2E6B"><enum>(2)</enum><header>Agency</header><text>The term <term>agency</term> means an agency described in paragraph (1) or (2) of section 901(b) of title 31, United States Code.</text></paragraph><paragraph id="idC321781C57B042359FD991BE6C1D1268"><enum>(3)</enum><header>Chief information officer</header><text>The term <term>Chief Information Officer</term> means a Chief Information Officer designated under section 3506(a)(2) of title 44, United States Code.</text></paragraph><paragraph id="id39E44DC95C2A4B7CB5EEA79632229A3C"><enum>(4)</enum><header>Comptroller general</header><text>The term <term>Comptroller General</term> means the Comptroller General of the United States. </text></paragraph><paragraph id="id4ACF50244CC54C08A5C696441F01087E"><enum>(5)</enum><header>Congressional oversight committee</header><text>The term <term>congressional oversight committee</term> means, with respect to a particular agency, a committee or subcommittee of the Senate and the House of Representatives that provides oversight of the agency.</text></paragraph><paragraph id="idE3D4B182C9CD430DACA429A9AEE29F25"><enum>(6)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the Office of Management and Budget.</text></paragraph><paragraph id="id28869FC1E40D41BA8645B2071795A503"><enum>(7)</enum><header>Information technology</header><text>The term <term>information technology</term> has the meaning given the term in section 11101 of title 40, United States Code.</text></paragraph><paragraph id="idC85DF1E9AAC04461A56582794BB26D79"><enum>(8)</enum><header>IT working capital fund; legacy information technology system</header><text>The terms <term>IT working capital fund</term> and <term>legacy information technology system</term> have the meaning given the terms in section 1076 of the National Defense Authorization Act for Fiscal Year 2018 (<external-xref legal-doc="usc" parsable-cite="usc/40/11301">40 U.S.C. 11301</external-xref> note; <external-xref legal-doc="public-law" parsable-cite="pl/115/91">Public Law 115–91</external-xref>).</text></paragraph><paragraph id="idF751A91F299E4D2DB97AFBBFAD5C52DF"><enum>(9)</enum><header>National security system</header><text>The term <term>national security system</term> has the meaning given the term in section 11103 of title 40, United States Code.</text></paragraph><paragraph id="idEF1B248F2E48402993F69BCCC41724A2"><enum>(10)</enum><header>Technology Modernization Fund</header><text>The term <term>Technology Modernization Fund</term> means the fund established under section 1078(b)(1) of the National Defense Authorization Act for Fiscal Year 2018 (<external-xref legal-doc="usc" parsable-cite="usc/40/11301">40 U.S.C. 11301</external-xref> note; <external-xref legal-doc="public-law" parsable-cite="pl/115/91">Public Law 115–91</external-xref>).</text></paragraph></section><section id="id36FABABF0C214AA5B4A608E4C30E4DE3"><enum>3.</enum><header>Legacy information technology system inventory</header><subsection id="id3690C19F39FD46DEBFBBF54AB2B95CD0"><enum>(a)</enum><header>Inventory of legacy information technology systems</header><paragraph id="idBF27350316684092BC11DA80976E924E"><enum>(1)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this Act, and not later than 5 years thereafter, the Chief Information Officer of each agency shall compile an inventory that lists each legacy information technology system used, operated, or maintained by the agency.</text></paragraph><paragraph id="id0814F8453DB94C4E837C7293846E3860"><enum>(2)</enum><header>Contents</header><text>The Director shall issue guidance prescribing the information that the Chief Information Officer of each agency shall include for each legacy technology information system listed in the inventory required under paragraph (1). In issuing such guidance, the Director shall consider including for each legacy technology information system listed in the inventory—</text><subparagraph id="idE917D3437C964ADC915865B4973B2329"><enum>(A)</enum><text>the name or an identification of the legacy information technology system;</text></subparagraph><subparagraph id="id37820b9acb454eb087cf94ad290a69c9"><enum>(B)</enum><text>the office or mission of the agency that the legacy information technology system supports and how the office or mission uses the legacy information technology system;</text></subparagraph><subparagraph id="id060A6C2A06514921BCAF834445164F0A"><enum>(C)</enum><text>to the extent that information is available—</text><clause id="idF7EF3A9B85324969899FCFE6F4076C36"><enum>(i)</enum><text>the date of the last update or refresh of the legacy information technology system;</text></clause><clause id="idCF6DD3505479497E89383A7F04772537"><enum>(ii)</enum><text>the annual price, including recurring subscription costs and any costs to contract labor, to operate or maintain the legacy information technology system; and</text></clause><clause id="idF301E3A20DA94C18A03627DAB278D755"><enum>(iii)</enum><text>the name and contact information of the vendor; and</text></clause></subparagraph><subparagraph id="id487a67a4cae84167924c5cb71a59ef36"><enum>(D)</enum><text>the date of the next expected update or modernization, retirement, or disposal of the legacy information technology system.</text></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id4aa8b87d7e0e4caa9f42a24116815d0e"><enum>(b)</enum><header>Transparency and accountability</header><paragraph commented="no" display-inline="no-display-inline" id="id0A0E0DAC2B6048A599DFA8108F7AEC16"><enum>(1)</enum><header>In general</header><text>Upon request by a House of Congress, a congressional oversight committee of an agency, the Comptroller General of the United States, or an inspector general of an agency, the head of the agency shall make available the inventory compiled under subsection (a)(1) or the relevant portion of that inventory.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idD29925FFDFF04E89B5CD00FB00DFA573"><enum>(2)</enum><header>Reporting</header><text>The Director may require an agency to include the inventory compiled under subsection (a)(1) in a reporting structure determined by the Director.</text></paragraph></subsection></section><section id="idF736F289ED0046019E900BA0E1A3A6C9"><enum>4.</enum><header>Agency legacy information technology systems modernization plans</header><subsection id="idE2EA3EB356634A82998A56E49E4311E1"><enum>(a)</enum><header>In general</header><text>Not later than 2 years after the date of enactment of this Act, and every 5 years thereafter, the head of an agency shall develop and include as part of the information resource management strategic plan of the agency submitted under section 3506(b)(2) of title 44, United States Code, a plan to modernize the legacy information technology systems of the agency.</text></subsection><subsection id="idF214D6F0C6814C019AEC2EFB1225A208"><enum>(b)</enum><header>Contents</header><text>A modernization plan of an agency developed under subsection (a) shall include—</text><paragraph id="idf67029e9cab74f4d945e74f21bc63e04"><enum>(1)</enum><text>an inventory of the legacy information technology systems of the agency;</text></paragraph><paragraph id="id78412f022bc54b92b036b13457f20dc1"><enum>(2)</enum><text>an identification of legacy information technology systems that the agency has prioritized for updates, modernization, retirement, or disposal;</text></paragraph><paragraph id="id6444646a000e4254a5b99453802926d0"><enum>(3)</enum><text>steps the agency intends to make toward updating, modernizing, retiring, or disposing of the legacy information technology systems of the agency prioritized under paragraph (2) during the 5-year period beginning on the date of submission of the plan; and</text></paragraph><paragraph id="idbad7e0e7e0204b06a334203d7d76dce7"><enum>(4)</enum><text>any additional information that the Director determines necessary or useful for the agency to consider or include to effectively and efficiently execute the modernization plan, which may include—</text><subparagraph id="id0403dd36a1d24730b4bc5bdd03458fba"><enum>(A)</enum><text>the capacity of the agency to operate and maintain an updated or modernized legacy information technology system;</text></subparagraph><subparagraph id="id9759A3B46D12424D8826F9A56DEE4E5A" changed="not-changed"><enum>(B)</enum><text>the estimated cost and sources of funding required to execute the modernization plan; and</text></subparagraph><subparagraph id="idA75A2FB1718D4036B2C95F0936AC7B2C" changed="not-changed"><enum>(C)</enum><text>the ability of the agency to adapt an updated or modernized legacy information technology system to changes in policy, technology, or other user needs, as necessary.</text></subparagraph></paragraph></subsection><subsection id="idE3A7CDB59A104C87987D05048E6F1ABF"><enum>(c)</enum><header>Publication and submission to Congress</header><text>Not later than 30 days after the date on which the head of an agency submits the modernization plan developed under subsection (a) as part of the information resource management strategic plan of the agency submitted under section 3506(b)(2) of title 44, United States Code, the head of the agency shall submit the modernization plan to the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Oversight and Accountability of the House of Representatives, and each congressional oversight committee of the agency.</text></subsection></section><section id="idAED1FE27D6D241F8855BF49694AD5944"><enum>5.</enum><header>Role of the Office of Management and Budget</header><text display-inline="no-display-inline">Not later than 180 days after the date of enactment of this Act, the Director, in coordination with the Administrator of the Office of Electronic Government, shall issue guidance on the implementation of this Act and the amendments made by this Act, which shall include— </text><paragraph id="ideb0066459f644c5b84fee386ef3705c1"><enum>(1)</enum><text>criteria to determine whether information technology qualifies as a <quote>legacy information technology system</quote> for the purposes of compiling the inventory required under section 3(a)(1);</text></paragraph><paragraph id="id84e078f87ae54681a0a142784f64da9d"><enum>(2)</enum><text>instructions and templates to inform the compilation of the inventory required under section 3(a)(1), as necessary;</text></paragraph><paragraph id="id57d26937903e4518b083e665bd04c96b"><enum>(3)</enum><text>instructions and templates to inform the compilation and publication of, and any subsequent updates to, the modernization plans required under section 4(a), as necessary; and</text></paragraph><paragraph id="id0c33bd9330a544ccb0bdc33d9188db33"><enum>(4)</enum><text>any other guidance determined necessary for the implementation of this Act or the amendments made by this Act, including how the implementation of this Act or those amendments complements laws, regulations, and guidance relating to information technology modernization.</text></paragraph></section><section id="idEACB74221F4D45E88B5331C001D859F9"><enum>6.</enum><header>Comptroller General review</header><subsection id="id998feed1660e4601b2a9bb979dc8c643"><enum>(a)</enum><header>In general</header><text>Not later than 3 years after the date of enactment of this Act, the Comptroller General shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Accountability of the House of Representatives a report on—</text><paragraph id="id1B0870DB6FED4BBBA937F05E1B5EC5EF"><enum>(1)</enum><text>the implementation of this Act and the amendments made by this Act; and</text></paragraph><paragraph id="idE4960B3E237D40E8A783CFDC27C4A80F"><enum>(2)</enum><text>how this Act and the amendments made by this Act function alongside other information technology modernization offices, policies, and programs, such as—</text><subparagraph id="id1bf669d5be754487b2d9c11d487e0b4e"><enum>(A)</enum><text>the Technology Modernization Fund and the IT working capital fund;</text></subparagraph><subparagraph id="idb9f0e81afadb41eaa766fd4d7e9d7c3e"><enum>(B)</enum><text>the Federal Risk and Authorization Management Program, the 18F program, and the 10X program of the General Services Administration;</text></subparagraph><subparagraph id="idc53c6cf796744f68b56bfb6c1d9b82ab"><enum>(C)</enum><text>programs and policies of the Office of Management and Budget, including the Office of Electronic Government and the United States Digital Service; and</text></subparagraph><subparagraph id="ide1d6de97c645497db4e753e645f36c87"><enum>(D)</enum><text>any other office, policy, or program of the Federal Government determined relevant by the Comptroller General.</text></subparagraph></paragraph></subsection></section><section id="id3392f8dbe9a644f19b96f1809ac3b53a"><enum>7.</enum><header>Protection of sensitive information; exemption of national security systems</header><subsection id="id8251969bde4b4c1389fb858847091509"><enum>(a)</enum><header>In general</header><text>Nothing in this Act or the amendments made by this Act shall be construed to require the head of an agency to disclose sensitive information that—</text><paragraph id="id962D985FDD334C588FC06549A40C52DC"><enum>(1)</enum><text>is protected from disclosure under any other law; or</text></paragraph><paragraph id="idE801624C996B4D76821A1874FCC8E82F"><enum>(2)</enum><text>would compromise the security of any information technology system of the Federal Government.</text></paragraph></subsection><subsection id="id5daa0ccb34074d8fa82f3fc698a18e26"><enum>(b)</enum><header>Exemption</header><text>Nothing in this Act or the amendments made by this Act shall be construed to authorize or require the head of an agency to inventory, develop a report relating to, or transfer, a national security system.</text></subsection></section></legis-body></bill> 

