[Congressional Record Volume 165, Number 107 (Tuesday, June 25, 2019)]
[Senate]
[Pages S4512-S4513]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 880. Mr. RUBIO submitted an amendment intended to be proposed to 
amendment SA 764 proposed by Mr. Inhofe to the bill S. 1790, to 
authorize appropriations for fiscal year 2020 for military activities 
of the Department of Defense, for military construction, and for 
defense activities of the Department of Energy, to prescribe military 
personnel strengths for such fiscal year, and for other purposes; which 
was ordered to lie on the table; as follows:

       At the end of subtitle C of title XVI, insert the 
     following:

     SEC. ___. ENSURING SECURITY OF COMMERCIAL CLOUD SERVICES 
                   DEPLOYED IN CLASSIFIED ENVIRONMENTS.

       (a) Short Title.--This section may be cited as the ``Cloud 
     Security Act of 2019''.
       (b) Purpose.--The purpose of this section is to ensure that 
     architectures, specifications, and deployments of commercial 
     cloud services deployed in classified environments of the 
     United States are not the same as those deployed in foreign 
     countries of concern and shared with foreign military and 
     governments adverse to the United States.
       (c) Definitions.--In this section:
       (1) Appropriate committees of congress.--The term 
     ``appropriate committees of Congress'' means--
       (A) the Committee on Armed Services, the Select Committee 
     on Intelligence, the Committee on Foreign Relations, the 
     Committee on Energy and Natural Resources, and the Committee 
     on Homeland Security and Governmental Affairs of the Senate; 
     and
       (B) the Committee on Armed Services, the Permanent Select 
     Committee on Intelligence, the Committee on Foreign Affairs, 
     Committee on Energy and Commerce, and the Committee on 
     Homeland Security of the House of Representatives.
       (2) Classified environment.--The term ``classified 
     environment'' means a system which handles classified 
     information, which, for reasons of national security, is 
     specifically designated by a United States Government agency 
     as ``Top Secret''.

[[Page S4513]]

       (3) Cloud computing service.--The term ``cloud computing 
     service'' means an infrastructure-as-a-service (IaaS) or a 
     platform-as-a-service (PaaS) as defined in Special 
     Publication 800-145 of the National Institutes of Standards 
     and Technology, as in effect on the day before the date of 
     the enactment of this Act.
       (4) Commercial cloud service.--The term ``commercial cloud 
     service'' means a cloud computing service that is sold on the 
     commercial market to customers other than the United States 
     Government.
       (5) Commercial cloud service provider.--The term 
     ``commercial cloud service provider'' means a commercial 
     business or entity that provides a commercial cloud service.
       (6) Foreign country of concern.--The term ``foreign country 
     of concern'' means a country that challenges or seeks to 
     undermine the United States or the interests of the United 
     States, as identified in the National Defense Strategy of the 
     United States of America.
       (7) Intelligence community.--The term ``intelligence 
     community'' has the meaning given such term in section 3 of 
     the National Security Act of 1947 (50 U.S.C. 3003).
       (8) Materially different.--The term ``materially 
     different'', with respect to two cloud computing services, 
     means if having immediate, physical access to and control 
     over the architectures, specifications, and technology as 
     well as the personnel used to operate one service could not 
     yield useful information for attacking, compromising, or 
     otherwise obtaining illicit access to the other service.
       (d) Policies Required.--Not later than June 1, 2020, the 
     Secretary of Defense, the Director of National Intelligence, 
     the Secretary of State, the Secretary of Energy, and the 
     Secretary of Homeland Security shall jointly establish a 
     policy to ensure that a commercial cloud service procured 
     from a commercial cloud service provider and deployed in a 
     classified environment is materially different from 
     commercial cloud service deployed in a foreign country of 
     concern.
       (e) Regulations Required.--Not later than June 1, 2020, the 
     Secretary of Defense, the Director of National Intelligence, 
     the Secretary of State, the Secretary of Energy, and the 
     Secretary of Homeland Security shall jointly promulgate such 
     regulations as may be necessary--
       (1) to implement the policy established under subsection 
     (d) across the departments and agencies over which they have 
     jurisdiction; and
       (2) enforce penalties should a commercial cloud service 
     provider fail to self-certify under subsection (d) or fail to 
     comply with a provision of the policies established under 
     subsection (d) or the regulations promulgated under this 
     subsection.
       (f) Covered Technologies.--The policies established under 
     subsection (d) and the regulations promulgated under 
     subsection (e) shall set forth the technologies and 
     procedures covered by such policies and regulations, 
     including, at a minimum, the following:
       (1) Nonpublic computer source code.
       (2) Specifications for data centers and cloud computing 
     service architectures.
       (3) Artificial intelligence systems.
       (4) Cryptographic solutions.
       (g) Self-certification.--
       (1) In general.--The policies established under subsection 
     (d) and the regulations promulgated under subsection (e) 
     shall prohibit the secretaries and the director described in 
     such subsections from deploying in any classified environment 
     any commercial cloud service from a commercial cloud service 
     provider, and any relevant subcontractor of the commercial 
     cloud service provider, that has not self-certified 
     compliance with the requirements of such policies and 
     regulations.
       (2) Elements.--Each self-certification under paragraph (1) 
     regarding a commercial cloud service shall include, at a 
     minimum, the following:
       (A) An attestation of the following:
       (i) The commercial cloud service and its infrastructure or 
     platform is materially different from any commercial cloud 
     service and its infrastructure or platform that has been or 
     is planned to be provided to a foreign nation of concern.
       (ii) The operational processes for the data center used for 
     the commercial cloud service is materially different than the 
     operational processes for any data center--

       (I) deployed in a foreign country of concern; or
       (II) used for any commercial cloud service provided to a 
     foreign country of concern.

       (iii) Any provisioning of technical assistance to the 
     foreign nation of concern relating to a commercial cloud 
     service will not lead to the Commercial cloud service 
     provider or subcontractor sharing information that would be 
     harmful to the United States or otherwise failing to comply 
     with the requirements of the policies established under 
     subsection (d) and the regulations promulgated under 
     subsection (e).
       (iv) In any case in which the commercial cloud service 
     provider or subcontractor discovers that information about a 
     technology covered by the policies established under 
     subsection (d) or promulgated under subsection (e) is 
     released to a foreign country of concern, the commercial 
     cloud service provider or subcontractor will promptly notify 
     the Director of National Intelligence of such release, 
     including information that is released pursuant to a mandate 
     from a foreign entity or as a condition of operation in a 
     foreign country.
       (B) A list any foreign commercial partners that have access 
     to information about the technologies and procedures covered 
     pursuant to subsection (f).
       (h) Penalties.--
       (1) In general.--The policies established under subsection 
     (d) and the regulations promulgated under subsection (e) 
     shall include penalties for failure to comply with 
     requirements set forth in such policies and regulations.
       (2) Debarment.--The penalties established under paragraph 
     (1) shall include a debarment from contracting with the 
     Federal Government or supporting a contract with the Federal 
     Government, including the provisioning of tools, technology, 
     and services, for a period of not less than 5 years.
       (i) Report.--
       (1) In general.--Not later than 180 days after the date of 
     the enactment of this Act, Secretary of Defense, the Director 
     of National Intelligence, the Secretary of State, the 
     Secretary of Energy, and the Secretary of Homeland Security 
     shall jointly submit to the appropriate committees of 
     Congress a report on the activities of the secretaries and 
     the Director to carry out this section.
       (2) Contents.--The report submitted under paragraph (1) 
     shall include the following:
       (A) A description of the policy established under 
     subsection (d).
       (B) An list of the contracts affected by the policies 
     established under subsection (d) and the regulations 
     promulgated under subsection (e).
       (C) An assessment of each contract listed pursuant to 
     subparagraph (B) as to whether the parties to the contract 
     and the goods and services provided pursuant to the contract 
     are in compliance with such policies and regulations.
       (D) A plan to ensure that parties, goods, and services 
     described in subparagraph (C) that are not in compliance with 
     such policies and regulations become compliant with such 
     policies and regulations.
                                 ______