Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
IIB
116TH CONGRESS
2D SESSION
H. R. 3941
IN THE SENATE OF THE UNITED STATES
FEBRUARY 10, 2020
Received; read twice and referred to the Committee on Homeland Security and
Governmental Affairs
AN ACT
To enhance the innovation, security, and availability of cloud
computing services used in the Federal Government by
establishing the Federal Risk and Authorization Manage-
ment Program within the General Services Administra-
tion and by establishing a risk management, authoriza-
tion, and continuous monitoring process to enable the
Federal Government to leverage cloud computing services
using a risk-based approach consistent with the Federal
Information Security Modernization Act of 2014 and
cloud-based operations, and for other purposes.
VerDate Sep 11 2014
22:43 Feb 10, 2020
Jkt 099200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6652
E:\BILLS\H3941.RFS
H3941
pamtmann on DSKBC07HB2PROD with BILLS
2
HR 3941 RFS
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ββFederal Risk and Au-
4
thorization Management Program Authorization Act of
5
2019ββ or the ββFedRAMP Authorization Actββ.
6
SEC. 2. CODIFICATION OF THE FEDRAMP PROGRAM.
7
(a) AMENDMENT.βChapter 36 of title 44, United
8
States Code, is amended by adding at the end the fol-
9
lowing new sections:
10
ββΒ§ 3607. Federal Risk and Authorization Management
11
Program
12
ββ(a) ESTABLISHMENT.βThere is established within
13
the General Services Administration the Federal Risk and
14
Authorization Management Program. The Administrator
15
of General Services, in accordance with the guidelines es-
16
tablished pursuant to section 3612, shall establish a gov-
17
ernmentwide program that provides the authoritative
18
standardized approach to security assessment and author-
19
ization for cloud computing products and services that
20
process unclassified information used by agencies.
21
ββ(b) COMPONENTS OF FEDRAMP.βThe Joint Au-
22
thorization Board and the FedRAMP Program Manage-
23
ment Office are established as components of FedRAMP.
24
VerDate Sep 11 2014
22:43 Feb 10, 2020
Jkt 099200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H3941.RFS
H3941
pamtmann on DSKBC07HB2PROD with BILLS
3
HR 3941 RFS
ββΒ§ 3608. FedRAMP Program Management Office
1
ββ(a) GSA DUTIES.β
2
ββ(1) ROLES AND RESPONSIBILITIES.βThe Ad-
3
ministrator of General Services shallβ
4
ββ(A) determine the categories and charac-
5
teristics of cloud computing information tech-
6
nology goods or services that are within the ju-
7
risdiction of FedRAMP and that require
8
FedRAMP authorization from the Joint Au-
9
thorization Board or the FedRAMP Program
10
Management Office;
11
ββ(B) develop, coordinate, and implement a
12
process for the FedRAMP Program Manage-
13
ment Office, the Joint Authorization Board,
14
and agencies to review security assessments of
15
cloud computing services pursuant to sub-
16
sections (b) and (c) of section 3611, and appro-
17
priate oversight of continuous monitoring of
18
cloud computing services; and
19
ββ(C) ensure the continuous improvement of
20
FedRAMP.
21
ββ(2) IMPLEMENTATION.βThe Administrator
22
shall oversee the implementation of FedRAMP, in-
23
cludingβ
24
VerDate Sep 11 2014
22:43 Feb 10, 2020
Jkt 099200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H3941.RFS
H3941
pamtmann on DSKBC07HB2PROD with BILLS
4
HR 3941 RFS
ββ(A) appointing a Program Director to
1
oversee the FedRAMP Program Management
2
Office;
3
ββ(B) hiring professional staff as may be
4
necessary for the effective operation of the
5
FedRAMP Program Management Office, and
6
such other activities as are essential to properly
7
perform critical functions;
8
ββ(C) entering into interagency agreements
9
to detail personnel on a reimbursable or non-re-
10
imbursable basis to assist the FedRAMP Pro-
11
gram Management Office and the Joint Author-
12
ization Board in discharging the responsibilities
13
of the Office under this section; and
14
ββ(D) such other actions as the Adminis-
15
trator may determine necessary to carry out
16
this section.
17
ββ(b) DUTIES.βThe FedRAMP Program Manage-
18
ment Office shall have the following duties:
19
ββ(1) Provide guidance to independent assess-
20
ment organizations, validate the independent assess-
21
ments, and apply the requirements and guidelines
22
adopted in section 3609(c)(5).
23
VerDate Sep 11 2014
22:43 Feb 10, 2020
Jkt 099200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H3941.RFS
H3941
pamtmann on DSKBC07HB2PROD with BILLS
5
HR 3941 RFS
ββ(2) Oversee and issue guidelines regarding the
1
qualifications, roles, and responsibilities of inde-
2
pendent assessment organizations.
3
ββ(3) Develop templates and other materials to
4
support the Joint Authorization Board and agencies
5
in the authorization of cloud computing services to
6
increase the speed, effectiveness, and transparency
7
of the authorization process, consistent with stand-
8
ards defined by the National Institute of Standards
9
and Technology.
10
ββ(4) Establish and maintain a public comment
11
process for proposed guidance before the issuance of
12
such guidance by FedRAMP.
13
ββ(5) Issue FedRAMP authorization for any au-
14
thorizations to operate issued by an agency that
15
meets the requirements and guidelines described in
16
paragraph (1).
17
ββ(6) Establish frameworks for agencies to use
18
authorization packages processed by the FedRAMP
19
Program Management Office and Joint Authoriza-
20
tion Board.
21
ββ(7) Coordinate with the Secretary of Defense
22
and the Secretary of Homeland Security to establish
23
a framework for continuous monitoring and report-
24
ing required of agencies pursuant to section 3553.
25
VerDate Sep 11 2014
22:43 Feb 10, 2020
Jkt 099200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H3941.RFS
H3941
pamtmann on DSKBC07HB2PROD with BILLS
6
HR 3941 RFS
ββ(8) Establish a centralized and secure reposi-
1
tory to collect and share necessary data, including
2
security authorization packages, from the Joint Au-
3
thorization Board and agencies to enable better
4
sharing and reuse to such packages across agencies.
5
ββ(c) EVALUATION OF AUTOMATION PROCEDURES.β
6
ββ(1) IN
GENERAL.βThe FedRAMP Program
7
Management Office shall assess and evaluate avail-
8
able automation capabilities and procedures to im-
9
prove the efficiency and effectiveness of the issuance
10
of provisional authorizations to operate issued by the
11
Joint Authorization Board and FedRAMP author-
12
izations, including continuous monitoring of cloud
13
environments and among cloud environments.
14
ββ(2) MEANS FOR AUTOMATION.βNot later than
15
1 year after the date of the enactment of this section
16
and updated annually thereafter, the FedRAMP
17
Program Management Office shall establish a means
18
for the automation of security assessments and re-
19
views.
20
ββ(d)
METRICS
FOR
AUTHORIZATION.βThe
21
FedRAMP Program Management Office shall establish
22
annual metrics regarding the time and quality of the as-
23
sessments necessary for completion of a FedRAMP au-
24
thorization process in a manner that can be consistently
25
VerDate Sep 11 2014
22:43 Feb 10, 2020
Jkt 099200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\H3941.RFS
H3941
pamtmann on DSKBC07HB2PROD with BILLS
7
HR 3941 RFS
tracked over time in conjunction with the periodic testing
1
and evaluation process pursuant to section 3554 in a man-
2
ner that minimizes the agency reporting burden.
3
ββΒ§ 3609. Joint Authorization Board
4
ββ(a) ESTABLISHMENT.βThere is established the
5
Joint Authorization Board which shall consist of cloud
6
computing experts, appointed by the Director in consulta-
7
tion with the Administrator, from each of the following:
8
ββ(1) The Department of Defense.
9
ββ(2) The Department of Homeland Security.
10
ββ(3) The General Services Administration.
11
ββ(4) Such other agencies as determined by the
12
Director, in consultation with the Administrator.
13
ββ(b) ISSUANCE OF PROVISIONAL AUTHORIZATIONS
14
TO OPERATE.βThe Joint Authorization Board shall con-
15
duct security assessments of cloud computing services and
16
issue provisional authorizations to operate to cloud service
17
providers that meet FedRAMP security guidelines set
18
forth in section 3608(b)(1).
19
ββ(c) DUTIES.βThe Joint Authorization Board
20
shallβ
21
ββ(1) develop and make publicly available on a
22
website, determined by the Administrator, criteria
23
for prioritizing and selecting cloud computing serv-
24
VerDate Sep 11 2014
22:43 Feb 10, 2020
Jkt 099200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\H3941.RFS
H3941
pamtmann on DSKBC07HB2PROD with BILLS
8
HR 3941 RFS
ices to be assessed by the Joint Authorization
1
Board;
2
ββ(2) provide regular updates on the status of
3
any cloud computing service during the assessment
4
and authorization process of the Joint Authorization
5
Board;
6
ββ(3) review and validate cloud computing serv-
7
ices and independent assessment organization secu-
8
rity packages or any documentation determined to
9
be necessary by the Joint Authorization Board to
10
evaluate the system security of a cloud computing
11
service;
12
ββ(4) in consultation with the FedRAMP Pro-
13
gram Management Office, serve as a resource for
14
best practices to accelerate the FedRAMP process;
15
ββ(5) establish requirements and guidelines for
16
security assessments of cloud computing services,
17
consistent with standards defined by the National
18
Institute of Standards and Technology, to be used
19
by the Joint Authorization Board and agencies;
20
ββ(6) perform such other roles and responsibil-
21
ities as the Administrator may assign, in consulta-
22
tion with the FedRAMP Program Management Of-
23
fice and members of the Joint Authorization Board;
24
and
25
VerDate Sep 11 2014
22:43 Feb 10, 2020
Jkt 099200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\H3941.RFS
H3941
pamtmann on DSKBC07HB2PROD with BILLS
9
HR 3941 RFS
ββ(7) establish metrics and goals for reviews and
1
activities associated with issuing provisional author-
2
izations to operate and provide to the FedRAMP
3
Program Management Office.
4
ββ(d) DETERMINATIONS
OF DEMAND
FOR CLOUD
5
COMPUTING SERVICES.βThe Joint Authorization Board
6
shall consult with the Chief Information Officers Council
7
established in section 3603 to establish a process for
8
prioritizing and accepting the cloud computing services to
9
be granted a provisional authorization to operate through
10
the Joint Authorization Board, which shall be made avail-
11
able on a public website.
12
ββ(e) DETAIL OF PERSONNEL.βTo assist the Joint
13
Authorization Board in discharging the responsibilities
14
under this section, personnel of agencies may be detailed
15
to the Joint Authorization Board for the performance of
16
duties described under subsection (c).
17
ββΒ§ 3610. Independent assessment organizations
18
ββ(a) REQUIREMENTS
FOR
ACCREDITATION.βThe
19
Joint Authorization Board shall determine the require-
20
ments for certification of independent assessment organi-
21
zations pursuant to section 3609. Such requirements may
22
include developing or requiring certification programs for
23
individuals employed by the independent assessment orga-
24
nizations who lead FedRAMP assessment teams.
25
VerDate Sep 11 2014
22:43 Feb 10, 2020
Jkt 099200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6201
E:\BILLS\H3941.RFS
H3941
pamtmann on DSKBC07HB2PROD with BILLS
10
HR 3941 RFS
ββ(b) ASSESSMENT.βAccredited independent assess-
1
ment organizations may assess, validate, and attest to the
2
quality and compliance of security assessment materials
3
provided by cloud service providers.
4
ββΒ§ 3611. Roles and responsibilities of agencies
5
ββ(a) IN GENERAL.βIn implementing the require-
6
ments of FedRAMP, the head of each agency shall, con-
7
sistent with guidance issued by the Director pursuant to
8
section 3612β
9
ββ(1) create policies to ensure cloud computing
10
services used by the agency meet FedRAMP security
11
requirements and other risk-based performance re-
12
quirements as defined by the Director;
13
ββ(2) issue agency-specific authorizations to op-
14
erate for cloud computing services in compliance
15
with section 3554;
16
ββ(3) confirm whether there is a provisional au-
17
thorization to operate in the cloud security reposi-
18
tory established under section 3608(b)(10) issued by
19
the Joint Authorization Board or a FedRAMP au-
20
thorization issued by the FedRAMP Program Man-
21
agement Office before beginning an agency author-
22
ization for a cloud computing product or service;
23
ββ(4) to the extent practicable, for any cloud
24
computing product or service the agency seeks to au-
25
VerDate Sep 11 2014
22:43 Feb 10, 2020
Jkt 099200
PO 00000
Frm 00010
Fmt 6652
Sfmt 6201
E:\BILLS\H3941.RFS
H3941
pamtmann on DSKBC07HB2PROD with BILLS
11
HR 3941 RFS
thorize that has received either a provisional author-
1
ization to operate by the Joint Authorization Board
2
or a FedRAMP authorization by the FedRAMP Pro-
3
gram Management Office, use the existing assess-
4
ments of security controls and materials within the
5
authorization package; and
6
ββ(5) provide data and information required to
7
the Director pursuant to section 3612 to determine
8
how agencies are meeting metrics as defined by the
9
FedRAMP Program Management Office.
10
ββ(b) SUBMISSION
OF POLICIES REQUIRED.βNot
11
later than 6 months after the date of the enactment of
12
this section, the head of each agency shall submit to the
13
Director the policies created pursuant to subsection (a)(1)
14
for review and approval.
15
ββ(c) SUBMISSION OF AUTHORIZATIONS TO OPERATE
16
REQUIRED.βUpon issuance of an authorization to oper-
17
ate or a provisional authorization to operate issued by an
18
agency, the head of each agency shall provide a copy of
19
the authorization to operate letter and any supplementary
20
information required pursuant to section 3608(b) to the
21
FedRAMP Program Management Office.
22
ββ(d) PRESUMPTION OF ADEQUACY.β
23
ββ(1) IN GENERAL.βThe assessment of security
24
controls and materials within the authorization
25
VerDate Sep 11 2014
22:43 Feb 10, 2020
Jkt 099200
PO 00000
Frm 00011
Fmt 6652
Sfmt 6201
E:\BILLS\H3941.RFS
H3941
pamtmann on DSKBC07HB2PROD with BILLS
12
HR 3941 RFS
package for provisional authorizations to operate
1
issued by the Joint Authorization Board and agency
2
authorizations to operate that receive FedRAMP au-
3
thorization from the FedRAMP Program Manage-
4
ment Office shall be presumed adequate for use in
5
agency authorizations of cloud computing products
6
and services.
7
ββ(2)
INFORMATION
SECURITY
REQUIRE-
8
MENTS.βThe presumption under paragraph (1)
9
does not modify or alter the responsibility of any
10
agency to e
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.