[Congressional Record Volume 165, Number 107 (Tuesday, June 25, 2019)]
[Senate]
[Pages S4512-S4513]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 880. Mr. RUBIO submitted an amendment intended to be proposed to
amendment SA 764 proposed by Mr. Inhofe to the bill S. 1790, to
authorize appropriations for fiscal year 2020 for military activities
of the Department of Defense, for military construction, and for
defense activities of the Department of Energy, to prescribe military
personnel strengths for such fiscal year, and for other purposes; which
was ordered to lie on the table; as follows:
At the end of subtitle C of title XVI, insert the
following:
SEC. ___. ENSURING SECURITY OF COMMERCIAL CLOUD SERVICES
DEPLOYED IN CLASSIFIED ENVIRONMENTS.
(a) Short Title.--This section may be cited as the ``Cloud
Security Act of 2019''.
(b) Purpose.--The purpose of this section is to ensure that
architectures, specifications, and deployments of commercial
cloud services deployed in classified environments of the
United States are not the same as those deployed in foreign
countries of concern and shared with foreign military and
governments adverse to the United States.
(c) Definitions.--In this section:
(1) Appropriate committees of congress.--The term
``appropriate committees of Congress'' means--
(A) the Committee on Armed Services, the Select Committee
on Intelligence, the Committee on Foreign Relations, the
Committee on Energy and Natural Resources, and the Committee
on Homeland Security and Governmental Affairs of the Senate;
and
(B) the Committee on Armed Services, the Permanent Select
Committee on Intelligence, the Committee on Foreign Affairs,
Committee on Energy and Commerce, and the Committee on
Homeland Security of the House of Representatives.
(2) Classified environment.--The term ``classified
environment'' means a system which handles classified
information, which, for reasons of national security, is
specifically designated by a United States Government agency
as ``Top Secret''.
[[Page S4513]]
(3) Cloud computing service.--The term ``cloud computing
service'' means an infrastructure-as-a-service (IaaS) or a
platform-as-a-service (PaaS) as defined in Special
Publication 800-145 of the National Institutes of Standards
and Technology, as in effect on the day before the date of
the enactment of this Act.
(4) Commercial cloud service.--The term ``commercial cloud
service'' means a cloud computing service that is sold on the
commercial market to customers other than the United States
Government.
(5) Commercial cloud service provider.--The term
``commercial cloud service provider'' means a commercial
business or entity that provides a commercial cloud service.
(6) Foreign country of concern.--The term ``foreign country
of concern'' means a country that challenges or seeks to
undermine the United States or the interests of the United
States, as identified in the National Defense Strategy of the
United States of America.
(7) Intelligence community.--The term ``intelligence
community'' has the meaning given such term in section 3 of
the National Security Act of 1947 (50 U.S.C. 3003).
(8) Materially different.--The term ``materially
different'', with respect to two cloud computing services,
means if having immediate, physical access to and control
over the architectures, specifications, and technology as
well as the personnel used to operate one service could not
yield useful information for attacking, compromising, or
otherwise obtaining illicit access to the other service.
(d) Policies Required.--Not later than June 1, 2020, the
Secretary of Defense, the Director of National Intelligence,
the Secretary of State, the Secretary of Energy, and the
Secretary of Homeland Security shall jointly establish a
policy to ensure that a commercial cloud service procured
from a commercial cloud service provider and deployed in a
classified environment is materially different from
commercial cloud service deployed in a foreign country of
concern.
(e) Regulations Required.--Not later than June 1, 2020, the
Secretary of Defense, the Director of National Intelligence,
the Secretary of State, the Secretary of Energy, and the
Secretary of Homeland Security shall jointly promulgate such
regulations as may be necessary--
(1) to implement the policy established under subsection
(d) across the departments and agencies over which they have
jurisdiction; and
(2) enforce penalties should a commercial cloud service
provider fail to self-certify under subsection (d) or fail to
comply with a provision of the policies established under
subsection (d) or the regulations promulgated under this
subsection.
(f) Covered Technologies.--The policies established under
subsection (d) and the regulations promulgated under
subsection (e) shall set forth the technologies and
procedures covered by such policies and regulations,
including, at a minimum, the following:
(1) Nonpublic computer source code.
(2) Specifications for data centers and cloud computing
service architectures.
(3) Artificial intelligence systems.
(4) Cryptographic solutions.
(g) Self-certification.--
(1) In general.--The policies established under subsection
(d) and the regulations promulgated under subsection (e)
shall prohibit the secretaries and the director described in
such subsections from deploying in any classified environment
any commercial cloud service from a commercial cloud service
provider, and any relevant subcontractor of the commercial
cloud service provider, that has not self-certified
compliance with the requirements of such policies and
regulations.
(2) Elements.--Each self-certification under paragraph (1)
regarding a commercial cloud service shall include, at a
minimum, the following:
(A) An attestation of the following:
(i) The commercial cloud service and its infrastructure or
platform is materially different from any commercial cloud
service and its infrastructure or platform that has been or
is planned to be provided to a foreign nation of concern.
(ii) The operational processes for the data center used for
the commercial cloud service is materially different than the
operational processes for any data center--
(I) deployed in a foreign country of concern; or
(II) used for any commercial cloud service provided to a
foreign country of concern.
(iii) Any provisioning of technical assistance to the
foreign nation of concern relating to a commercial cloud
service will not lead to the Commercial cloud service
provider or subcontractor sharing information that would be
harmful to the United States or otherwise failing to comply
with the requirements of the policies established under
subsection (d) and the regulations promulgated under
subsection (e).
(iv) In any case in which the commercial cloud service
provider or subcontractor discovers that information about a
technology covered by the policies established under
subsection (d) or promulgated under subsection (e) is
released to a foreign country of concern, the commercial
cloud service provider or subcontractor will promptly notify
the Director of National Intelligence of such release,
including information that is released pursuant to a mandate
from a foreign entity or as a condition of operation in a
foreign country.
(B) A list any foreign commercial partners that have access
to information about the technologies and procedures covered
pursuant to subsection (f).
(h) Penalties.--
(1) In general.--The policies established under subsection
(d) and the regulations promulgated under subsection (e)
shall include penalties for failure to comply with
requirements set forth in such policies and regulations.
(2) Debarment.--The penalties established under paragraph
(1) shall include a debarment from contracting with the
Federal Government or supporting a contract with the Federal
Government, including the provisioning of tools, technology,
and services, for a period of not less than 5 years.
(i) Report.--
(1) In general.--Not later than 180 days after the date of
the enactment of this Act, Secretary of Defense, the Director
of National Intelligence, the Secretary of State, the
Secretary of Energy, and the Secretary of Homeland Security
shall jointly submit to the appropriate committees of
Congress a report on the activities of the secretaries and
the Director to carry out this section.
(2) Contents.--The report submitted under paragraph (1)
shall include the following:
(A) A description of the policy established under
subsection (d).
(B) An list of the contracts affected by the policies
established under subsection (d) and the regulations
promulgated under subsection (e).
(C) An assessment of each contract listed pursuant to
subparagraph (B) as to whether the parties to the contract
and the goods and services provided pursuant to the contract
are in compliance with such policies and regulations.
(D) A plan to ensure that parties, goods, and services
described in subparagraph (C) that are not in compliance with
such policies and regulations become compliant with such
policies and regulations.
______