Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
IIB
117TH CONGRESS
1ST SESSION
H. R. 21
IN THE SENATE OF THE UNITED STATES
JANUARY 6, 2021
Received; read twice and referred to the Committee on Homeland Security and
Governmental Affairs
AN ACT
To enhance the innovation, security, and availability of cloud
computing products and services used in the Federal
Government by establishing the Federal Risk and Au-
thorization Management Program within the General
Services Administration and by establishing a risk man-
agement, authorization, and continuous monitoring proc-
ess to enable the Federal Government to leverage cloud
computing products and services using a risk-based ap-
proach consistent with the Federal Information Security
Modernization Act of 2014 and cloud-based operations,
and for other purposes.
VerDate Sep 11 2014
23:15 Jan 07, 2021
Jkt 019200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6652
E:\BILLS\H21.RFS
H21
kjohnson on DSK79L0C42PROD with BILLS
2
HR 21 RFS
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ββFederal Risk and Au-
4
thorization Management Program Authorization Act of
5
2021ββ or the ββFedRAMP Authorization Actββ.
6
SEC. 2. CODIFICATION OF THE FEDRAMP PROGRAM.
7
(a) AMENDMENT.βChapter 36 of title 44, United
8
States Code, is amended by adding at the end the fol-
9
lowing new sections:
10
ββΒ§ 3607. Federal Risk and Authorization Management
11
Program
12
ββ(a) ESTABLISHMENT.βThere is established within
13
the General Services Administration the Federal Risk and
14
Authorization Management Program. The Administrator
15
of General Services, in accordance with section 3612, shall
16
establish a governmentwide program that provides the au-
17
thoritative standardized approach to security assessment
18
and authorization for cloud computing products and serv-
19
ices that process unclassified information used by agen-
20
cies.
21
ββ(b) COMPONENTS OF FEDRAMP.βThe Joint Au-
22
thorization Board and the FedRAMP Program Manage-
23
ment Office are established as components of FedRAMP.
24
VerDate Sep 11 2014
23:15 Jan 07, 2021
Jkt 019200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H21.RFS
H21
kjohnson on DSK79L0C42PROD with BILLS
3
HR 21 RFS
ββΒ§ 3608. FedRAMP Program Management Office
1
ββ(a) GSA DUTIES.β
2
ββ(1) ROLES AND RESPONSIBILITIES.βThe Ad-
3
ministrator of General Services shallβ
4
ββ(A) determine the categories and charac-
5
teristics of cloud computing products and serv-
6
ices that are within the jurisdiction of
7
FedRAMP and that require a FedRAMP au-
8
thorization or a FedRAMP provisional author-
9
ization;
10
ββ(B) develop, coordinate, and implement a
11
process for the FedRAMP Program Manage-
12
ment Office, the Joint Authorization Board,
13
and agencies to review security assessments of
14
cloud computing products and services pursuant
15
to subsections (b) and (c) of section 3611, and
16
appropriate oversight of continuous monitoring
17
of cloud computing products and services; and
18
ββ(C) ensure the continuous improvement of
19
FedRAMP.
20
ββ(2) IMPLEMENTATION.βThe Administrator
21
shall oversee the implementation of FedRAMP, in-
22
cludingβ
23
ββ(A) appointing a Program Director to
24
oversee the FedRAMP Program Management
25
Office;
26
VerDate Sep 11 2014
23:15 Jan 07, 2021
Jkt 019200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H21.RFS
H21
kjohnson on DSK79L0C42PROD with BILLS
4
HR 21 RFS
ββ(B) hiring professional staff as may be
1
necessary for the effective operation of the
2
FedRAMP Program Management Office, and
3
such other activities as are essential to properly
4
perform critical functions;
5
ββ(C) entering into interagency agreements
6
to detail personnel on a reimbursable or non-re-
7
imbursable basis to assist the FedRAMP Pro-
8
gram Management Office and the Joint Author-
9
ization Board in discharging the responsibilities
10
of the Office under this section; and
11
ββ(D) such other actions as the Adminis-
12
trator may determine necessary to carry out
13
this section.
14
ββ(b) DUTIES.βThe FedRAMP Program Manage-
15
ment Office shall have the following duties:
16
ββ(1) Provide guidance to independent assess-
17
ment organizations, validate the independent assess-
18
ments, and apply the requirements and guidelines
19
adopted in section 3609(c)(5).
20
ββ(2) Oversee and issue guidelines regarding the
21
necessary requirements for accreditation of third-
22
party organizations seeking to be awarded accredita-
23
tion as independent assessment organizations, in-
24
VerDate Sep 11 2014
23:15 Jan 07, 2021
Jkt 019200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H21.RFS
H21
kjohnson on DSK79L0C42PROD with BILLS
5
HR 21 RFS
cluding qualifications, roles, and responsibilities of
1
independent assessment organizations.
2
ββ(3) Develop templates and other materials to
3
support the Joint Authorization Board and agencies
4
in the authorization of cloud computing products
5
and services to increase the speed, effectiveness, and
6
transparency of the authorization process, consistent
7
with standards defined by the National Institute of
8
Standards and Technology.
9
ββ(4) Establish and maintain a public comment
10
process for proposed guidance before the issuance of
11
such guidance by FedRAMP.
12
ββ(5) Review any authorization to operate issued
13
by an agency to determine if the authorization meets
14
the requirements and guidelines adopted in section
15
3609(c)(5).
16
ββ(6) Establish frameworks for agencies to use
17
authorization packages processed by the FedRAMP
18
Program Management Office and Joint Authoriza-
19
tion Board.
20
ββ(7) Coordinate with the Secretary of Defense
21
and the Secretary of Homeland Security to establish
22
a framework for continuous monitoring under sec-
23
tion 3553 and agency reports required under section
24
3554.
25
VerDate Sep 11 2014
23:15 Jan 07, 2021
Jkt 019200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H21.RFS
H21
kjohnson on DSK79L0C42PROD with BILLS
6
HR 21 RFS
ββ(8) Establish a centralized and secure reposi-
1
tory to collect and share necessary data, including
2
security authorization packages, from the Joint Au-
3
thorization Board and agencies to enable better
4
sharing and reuse of such packages across agencies.
5
ββ(c) EVALUATION OF AUTOMATION PROCEDURES.β
6
ββ(1) IN
GENERAL.βThe FedRAMP Program
7
Management Office shall assess and evaluate avail-
8
able automation capabilities and procedures to im-
9
prove the efficiency and effectiveness of the issuance
10
of FedRAMP authorizations and FedRAMP provi-
11
sional authorizations, including continuous moni-
12
toring of cloud computing products and services.
13
ββ(2) MEANS FOR AUTOMATION.βNot later than
14
1 year after the date of the enactment of this sec-
15
tion,
and
updated
annually
thereafter,
the
16
FedRAMP Program Management Office shall estab-
17
lish a means for the automation of security assess-
18
ments and reviews.
19
ββ(d)
METRICS
FOR
AUTHORIZATION.βThe
20
FedRAMP Program Management Office shall establish
21
annual metrics regarding the time and quality of the as-
22
sessments necessary for completion of a FedRAMP au-
23
thorization process in a manner that can be consistently
24
tracked over time in conjunction with the periodic testing
25
VerDate Sep 11 2014
23:15 Jan 07, 2021
Jkt 019200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\H21.RFS
H21
kjohnson on DSK79L0C42PROD with BILLS
7
HR 21 RFS
and evaluation process pursuant to section 3554 in a man-
1
ner that minimizes the agency reporting burden.
2
ββΒ§ 3609. Joint Authorization Board
3
ββ(a) ESTABLISHMENT.βThe Joint Authorization
4
Board shall consist of cloud computing experts, appointed
5
by the Director in consultation with the Administrator,
6
from each of the following:
7
ββ(1) The Department of Defense.
8
ββ(2) The Department of Homeland Security.
9
ββ(3) The General Services Administration.
10
ββ(4) Such other agencies as determined by the
11
Director, in consultation with the Administrator.
12
ββ(b) ISSUANCE
OF FEDRAMP PROVISIONAL AU-
13
THORIZATIONS.βThe Joint Authorization Board shall
14
conduct security assessments of cloud computing products
15
and services and issue FedRAMP provisional authoriza-
16
tions to cloud service providers that meet the requirements
17
and guidelines established in subsection (c)(5).
18
ββ(c) DUTIES.βThe Joint Authorization Board
19
shallβ
20
ββ(1) develop and make publicly available on a
21
website, determined by the Administrator, criteria
22
for prioritizing and selecting cloud computing prod-
23
ucts and services to be assessed by the Joint Author-
24
ization Board;
25
VerDate Sep 11 2014
23:15 Jan 07, 2021
Jkt 019200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\H21.RFS
H21
kjohnson on DSK79L0C42PROD with BILLS
8
HR 21 RFS
ββ(2) provide regular updates to applicant cloud
1
service providers on the status of any cloud com-
2
puting product or service during the assessment and
3
authorization process of the Joint Authorization
4
Board;
5
ββ(3) review and validate cloud computing prod-
6
ucts and services and materials submitted by inde-
7
pendent assessment organizations or any documenta-
8
tion determined to be necessary by the Joint Author-
9
ization Board to evaluate the system security of a
10
cloud computing product or service;
11
ββ(4) in consultation with the FedRAMP Pro-
12
gram Management Office, serve as a resource for
13
best practices to accelerate the process for obtaining
14
a FedRAMP authorization or FedRAMP provisional
15
authorization;
16
ββ(5) establish requirements and guidelines for
17
security assessments of cloud computing products
18
and services, consistent with standards defined by
19
the National Institute of Standards and Technology,
20
to be used by the Joint Authorization Board and
21
agencies;
22
ββ(6) perform such other roles and responsibil-
23
ities as the Administrator may assign, in consulta-
24
tion with the FedRAMP Program Management Of-
25
VerDate Sep 11 2014
23:15 Jan 07, 2021
Jkt 019200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\H21.RFS
H21
kjohnson on DSK79L0C42PROD with BILLS
9
HR 21 RFS
fice and members of the Joint Authorization Board;
1
and
2
ββ(7) establish metrics and goals for reviews and
3
activities associated with issuing FedRAMP provi-
4
sional authorizations and provide to the FedRAMP
5
Program Management Office.
6
ββ(d) DETERMINATIONS
OF DEMAND
FOR CLOUD
7
COMPUTING PRODUCTS AND SERVICES.βThe Joint Au-
8
thorization Board shall consult with the Chief Information
9
Officers Council established in section 3603 to establish
10
a process, that shall be made available on a public website,
11
for prioritizing and accepting the cloud computing prod-
12
ucts and services to be granted a FedRAMP provisional
13
authorization.
14
ββ(e) DETAIL OF PERSONNEL.βTo assist the Joint
15
Authorization Board in discharging the responsibilities
16
under this section, personnel of agencies may be detailed
17
to the Joint Authorization Board for the performance of
18
duties described under subsection (c).
19
ββΒ§ 3610. Independent assessment organizations
20
ββ(a) REQUIREMENTS
FOR
ACCREDITATION.βThe
21
Joint Authorization Board shall determine the require-
22
ments for the accreditation of a third-party organization
23
seeking to be accredited as an independent assessment or-
24
ganization, ensuring adequate implementation of section
25
VerDate Sep 11 2014
23:15 Jan 07, 2021
Jkt 019200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6201
E:\BILLS\H21.RFS
H21
kjohnson on DSK79L0C42PROD with BILLS
10
HR 21 RFS
3609. Such requirements may include developing or re-
1
quiring certification programs for individuals employed by
2
the third-party organization seeking accreditation. The
3
Program Director of the FedRAMP Program Manage-
4
ment Office shall accredit any third-party organization
5
that meets the requirements for accreditation.
6
ββ(b) ASSESSMENT.βAn independent assessment or-
7
ganization may assess, validate, and attest to the quality
8
and compliance of security assessment materials provided
9
by cloud service providers as part of the FedRAMP au-
10
thorization or the FedRAMP provisional authorization
11
process.
12
ββΒ§ 3611. Roles and responsibilities of agencies
13
ββ(a) IN GENERAL.βIn implementing the require-
14
ments of FedRAMP, the head of each agency shall, con-
15
sistent with guidance issued by the Director pursuant to
16
section 3612β
17
ββ(1) create policies to ensure cloud computing
18
products and services used by the agency meet
19
FedRAMP security requirements and other risk-
20
based performance requirements as defined by the
21
Director;
22
ββ(2) issue agency-specific authorizations to op-
23
erate for cloud computing services in compliance
24
with section 3554;
25
VerDate Sep 11 2014
23:15 Jan 07, 2021
Jkt 019200
PO 00000
Frm 00010
Fmt 6652
Sfmt 6201
E:\BILLS\H21.RFS
H21
kjohnson on DSK79L0C42PROD with BILLS
11
HR 21 RFS
ββ(3) confirm whether there is a FedRAMP au-
1
thorization or FedRAMP provisional authorization
2
in the cloud security repository established under
3
section 3608(b)(8) before beginning the process to
4
award a FedRAMP authorization or a FedRAMP
5
provisional authorization for a cloud computing
6
product or service;
7
ββ(4) to the extent practicable, for any cloud
8
computing product or service the agency seeks to au-
9
thorize that has received a FedRAMP authorization
10
or FedRAMP provisional authorization, use the ex-
11
isting assessments of security controls and materials
12
within the authorization package; and
13
ββ(5) provide data and information required to
14
the Director pursuant to section 3612 to determine
15
how agencies are meeting metrics as defined by the
16
FedRAMP Program Management Office.
17
ββ(b) SUBMISSION
OF POLICIES REQUIRED.βNot
18
later than 6 months after the date of the enactment of
19
this section, the head of each agency shall submit to the
20
Director the policies created pursuant to subsection (a)(1)
21
for review and approval.
22
ββ(c) SUBMISSION OF AUTHORIZATIONS TO OPERATE
23
REQUIRED.βUpon issuance of an agency authorization to
24
operate, the head of the agency shall provide a copy of
25
VerDate Sep 11 2014
23:15 Jan 07, 2021
Jkt 019200
PO 00000
Frm 00011
Fmt 6652
Sfmt 6201
E:\BILLS\H21.RFS
H21
kjohnson on DSK79L0C42PROD with BILLS
12
HR 21 RFS
the authorization to operate letter and any supplementary
1
information required pursuant to section 3608(b) to the
2
FedRAMP Program Management Office.
3
ββ(d) PRESUMPTION OF ADEQUACY.β
4
ββ(1) IN GENERAL.βThe assessment of security
5
controls and materials within the authorization
6
package
for
a
FedRAMP
authorization
or
7
FedRAMP provisional authorization shall be pre-
8
sumed adequate for use in an agency authorization
9
to
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.