[Congressional Record Volume 171, Number 143 (Tuesday, September 2, 2025)]
[Senate]
[Pages S5646-S5647]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 3715. Mr. COTTON submitted an amendment intended to be proposed by
him to the bill S. 2296, to authorize appropriations for fiscal year
2026 for military activities of the Department of Defense, for military
construction, and for defense activities of the Department of Energy,
to prescribe military personnel strengths for such fiscal year, and for
other purposes; which was ordered to lie on the table; as follows:
At the appropriate place in title XVI, insert the
following:
SEC. 16__. PROHIBITION ON ACCESS TO DEPARTMENT OF DEFENSE
CLOUD-BASED RESOURCES BY INDIVIDUALS WHO ARE
NOT CITIZENS OF THE UNITED STATES OR ALLIED
COUNTRIES.
(a) Maintenance, Administration, Operation, and Access.--
(1) In general.--An individual not described in paragraph
(2) may not maintain, administer, operate, use, receive
information about, or directly access or indirectly access,
irrespective of whether the individual is supervised by a
citizen of the United States, any Department of Defense cloud
computing system or cloud-based software, Department data, or
Department-related data.
(2) Individual described.--An individual is described in
this paragraph if the individual--
(A) has the requisite security clearance or authorization
required to access the applicable system, software, or data;
and
(B)(i) is person described in paragraph (1) or (2) of
section 504(b) of title 10, United States Code; or
(ii) is a citizen of a member country of the Five Eyes
intelligence-sharing alliance or of a country that is an ally
or partner of the United States that has a similar agreement
in effect.
(3) Safeguards.--The Secretary of Defense shall establish
regulations to carry out this subsection, including
safeguards to ensure that only individuals described in
paragraph (2) maintain, administer, operate, access, and use
the systems, software, and data described in paragraph (1).
(b) Department of Defense Guidance, Directives, Procedures,
Requirements, and Regulations.--The Secretary shall--
(1) review all relevant guidance, directives, procedures,
requirements, and regulations of the Department of Defense,
including the Cloud Computing Security Requirements Guide,
the Security Technical Implementation Guides, and related
Department instructions; and
(2) make such revisions as may be necessary to ensure
conformity and compliance with subsection (a).
(c) Review and Report.--The Secretary shall--
(1) conduct a review of all cloud computing contracts in
effect for the Department--
(A) for any violations of section 252.225-7058 of the
Defense Federal Acquisition Regulation Supplement and
recommended penalties; and
(B) to determine--
(i) which contracts have allowed individuals not described
in paragraph (2) to maintain, administer, operate, or
directly access or indirectly access, whether supervised or
unsupervised by a United States citizen, any Government cloud
computing system or cloud-based software, Government data, or
Government-related data; and
[[Page S5647]]
(ii) how many of the individuals described in clause (i)
are citizens of foreign countries of concern; and
(2) submit to the Committee on Armed Services of the Senate
and the Committee on Armed Services of the House of
Representatives a report on the findings of the Secretary
with respect to the review conducted pursuant to paragraph
(1).
(d) Definitions.--ln this section:
(1) The term ``cloud computing'' has the meaning given such
term in section 239.7601 of the Defense Federal Acquisition
Regulation Supplement, or successor regulation.
(2) The term ``cloud-based software'' means a software
application, platform, or computational service that is--
(A) delivered to end users via internet-based cloud
computing infrastructure;
(B) hosted, operated, maintained, and controlled by a
third-party service provider; and
(C) accessed remotely by users without requiring local
installation or deployment of the software on user devices or
Department-controlled systems.
(3) The terms ``Department data'' and ``Department-related
data'' have the meanings given the terms ``Government data''
and ``Government-related data'', respectively, in section
239.7601 of the Defense Federal Acquisition Regulation
Supplement, or successor regulation, except in this section,
such terms apply only to the Department of Defense.
(4) The term ``directly access'', with respect to a system,
software, or data, means--
(A) to physically access the system, software, or data; or
(B) to logically access the system, software, or data,
through proxy, virtual, administrative, or programmatic means
such that an individual can modify, alter, control,
administer, configure, or deploy the system, software, or
data.
(5) The term ``Five Eyes intelligence-sharing alliance''
includes the following:
(A) The Commonwealth of Australia.
(B) Canada.
(C) New Zealand.
(D) The United Kingdom of Great Britain and Northern
Ireland.
(E) The United States of America.
(6) The term ``foreign country of concern'' has the meaning
given that term in section 9901 of the William M. (Mac)
Thornberry National Defense Authorization Act for Fiscal Year
2021 (15 U.S.C. 4651).
(7) The term ``indirectly access'', with respect to a
system, software, or data, means to obtain, receive, collect,
or derive information from the system, software, or data
regarding technical details, operational characteristics, or
security-related attributes, including--
(A) system configurations;
(B) network architecture;
(C) security controls;
(D) data schemas;
(E) performance metrics; and
(F) access logs or other information that could compromise
the confidentiality, integrity, or availability of the
system, software, or data.
______