172 lines
No EOL
20 KiB
HTML
172 lines
No EOL
20 KiB
HTML
<!doctype html>
|
||
<html class="no-js" lang="en">
|
||
<head>
|
||
<!-- REQUIRED META INFORMATION -->
|
||
<meta charset="utf-8" />
|
||
<meta http-equiv="X-UA-Compatible" content="IE=Edge,chrome=1" />
|
||
<meta name="viewport" content="width=device-width" />
|
||
|
||
<!-- DOCUMENT TITLE -->
|
||
<title>House Passes H.R. 21, the “Federal Risk and Authorization Management Program (FedRAMP) Authorization Act of 2021”
|
||
|
||
</title>
|
||
|
||
<!-- OCOMM META INFORMATION -->
|
||
<meta name="dc.creator" content="OLCA" />
|
||
<meta name="lead_content_manager" content="Brianne Klimas" />
|
||
<meta name="coder" content="Gary Davis" /><!-- OCOMM STYLES & SCRIPTS -->
|
||
<link href="/framework/css/phoenix.css" rel="stylesheet" media="all" />
|
||
<!-- SSA INTERNET HEAD SCRIPTS -->
|
||
<script src="/framework/js/ssa.internet.head.js"></script>
|
||
|
||
<!-- LEGISLATION STYLES -->
|
||
<link href="css/legislation.css" type="text/css" rel="stylesheet" media="all" />
|
||
|
||
<script>(window.BOOMR_mq=window.BOOMR_mq||[]).push(["addVar",{"rua.upush":"false","rua.cpush":"false","rua.upre":"false","rua.cpre":"false","rua.uprl":"false","rua.cprl":"false","rua.cprf":"false","rua.trans":"","rua.cook":"false","rua.ims":"false","rua.ufprl":"false","rua.cfprl":"false","rua.isuxp":"false","rua.texp":"norulematch","rua.ceh":"false","rua.ueh":"false","rua.ieh.st":"0"}]);</script>
|
||
<script>!function(e){var n="https://s.go-mpulse.net/boomerang/";if("False"=="True")e.BOOMR_config=e.BOOMR_config||{},e.BOOMR_config.PageParams=e.BOOMR_config.PageParams||{},e.BOOMR_config.PageParams.pci=!0,n="https://s2.go-mpulse.net/boomerang/";if(window.BOOMR_API_key="LERZW-HECFS-R8H4E-23UQ7-ERMQB",function(){function e(){if(!o){var e=document.createElement("script");e.id="boomr-scr-as",e.src=window.BOOMR.url,e.async=!0,i.parentNode.appendChild(e),o=!0}}function t(e){o=!0;var n,t,a,r,d=document,O=window;if(window.BOOMR.snippetMethod=e?"if":"i",t=function(e,n){var t=d.createElement("script");t.id=n||"boomr-if-as",t.src=window.BOOMR.url,BOOMR_lstart=(new Date).getTime(),e=e||d.body,e.appendChild(t)},!window.addEventListener&&window.attachEvent&&navigator.userAgent.match(/MSIE [67]\./))return window.BOOMR.snippetMethod="s",void t(i.parentNode,"boomr-async");a=document.createElement("IFRAME"),a.src="about:blank",a.title="",a.role="presentation",a.loading="eager",r=(a.frameElement||a).style,r.width=0,r.height=0,r.border=0,r.display="none",i.parentNode.appendChild(a);try{O=a.contentWindow,d=O.document.open()}catch(_){n=document.domain,a.src="javascript:var d=document.open();d.domain='"+n+"';void(0);",O=a.contentWindow,d=O.document.open()}if(n)d._boomrl=function(){this.domain=n,t()},d.write("<bo"+"dy onload='document._boomrl();'>");else if(O._boomrl=function(){t()},O.addEventListener)O.addEventListener("load",O._boomrl,!1);else if(O.attachEvent)O.attachEvent("onload",O._boomrl);d.close()}function a(e){window.BOOMR_onload=e&&e.timeStamp||(new Date).getTime()}if(!window.BOOMR||!window.BOOMR.version&&!window.BOOMR.snippetExecuted){window.BOOMR=window.BOOMR||{},window.BOOMR.snippetStart=(new Date).getTime(),window.BOOMR.snippetExecuted=!0,window.BOOMR.snippetVersion=12,window.BOOMR.url=n+"LERZW-HECFS-R8H4E-23UQ7-ERMQB";var i=document.currentScript||document.getElementsByTagName("script")[0],o=!1,r=document.createElement("link");if(r.relList&&"function"==typeof r.relList.supports&&r.relList.supports("preload")&&"as"in r)window.BOOMR.snippetMethod="p",r.href=window.BOOMR.url,r.rel="preload",r.as="script",r.addEventListener("load",e),r.addEventListener("error",function(){t(!0)}),setTimeout(function(){if(!o)t(!0)},3e3),BOOMR_lstart=(new Date).getTime(),i.parentNode.appendChild(r);else t(!1);if(window.addEventListener)window.addEventListener("load",a,!1);else if(window.attachEvent)window.attachEvent("onload",a)}}(),"".length>0)if(e&&"performance"in e&&e.performance&&"function"==typeof e.performance.setResourceTimingBufferSize)e.performance.setResourceTimingBufferSize();!function(){if(BOOMR=e.BOOMR||{},BOOMR.plugins=BOOMR.plugins||{},!BOOMR.plugins.AK){var n=""=="true"?1:0,t="",a="vht6pfix22vgcz6v7csa-f-46148eda0-clientnsv4-s.akamaihd.net",i="false"=="true"?2:1,o={"ak.v":"39","ak.cp":"1204614","ak.ai":parseInt("728289",10),"ak.ol":"0","ak.cr":3,"ak.ipv":4,"ak.proto":"http/1.1","ak.rid":"7e05f1","ak.r":35636,"ak.a2":n,"ak.m":"dsca","ak.n":"essl","ak.bpcip":"169.231.231.0","ak.cport":39754,"ak.gh":"23.214.170.79","ak.quicv":"","ak.tlsv":"tls1.3","ak.0rtt":"","ak.0rtt.ed":"","ak.csrc":"-","ak.acc":"bbr","ak.t":"1742076068","ak.ak":"hOBiQwZUYzCg5VSAfCLimQ==ah5VSv3eSCzT6mP2aLngDTyL6LZVBVGcpM5CwDNEKI1gk4yC5bEpwj+xqmLlE3iIdqmQK1job5eoQ9Mid7Q1zmVabPL2yPlru4hqV3Vdxc1BYU/fjlQkMWf6yseWxn+gmLeuHlVpKbwKxam+2q0KKckWLxglKLNzCTqKqO9d/T9Is+TeO1cQMQo9i61H8XeyVSP6j9lic7Ur0arr25B+sUt+0wziysXODdQgIk3sEGOeVmAmy3Wu7drvoWz5HZQ2TefDSzTSEwZuVEnHwcUbXH53M9rIK5VHSVxbt2H07mYzXAfSAEV82QdORkYhWnfIp+qNHq88kfJ40ZB3Vs9rMhTgjUF4t35D1JuVItITUUNJDFBTIV1btjMAT+LXsPInHFsdqYuFkJJ2J2zlUbSIUekjZXokPt4vjtW+rYuc5X8=","ak.pv":"98","ak.dpoabenc":"","ak.tf":i};if(""!==t)o["ak.ruds"]=t;var r={i:!1,av:function(n){var t="http.initiator";if(n&&(!n[t]||"spa_hard"===n[t]))o["ak.feo"]=void 0!==e.aFeoApplied?1:0,BOOMR.addVar(o)},rv:function(){var e=["ak.bpcip","ak.cport","ak.cr","ak.csrc","ak.gh","ak.ipv","ak.m","ak.n","ak.ol","ak.proto","ak.quicv","ak.tlsv","ak.0rtt","ak.0rtt.ed","ak.r","ak.acc","ak.t","ak.tf"];BOOMR.removeVar(e)}};BOOMR.plugins.AK={akVars:o,akDNSPreFetchDomain:a,init:function(){if(!r.i){var e=BOOMR.subscribe;e("before_beacon",r.av,null,null),e("onbeacon",r.rv,null,null),r.i=!0}return this},is_complete:function(){return!0}}}}()}(window);</script></head>
|
||
<body id="news" lang="EN-US">
|
||
<!-- PAGE CONTAINER -->
|
||
<div id="page">
|
||
|
||
<!-- PAGE HEADER -->
|
||
<div class="bg-dark-gray accessibility" id="accessibility"><a id="skip-navigation" href="#content">Skip to main content</a></div><ssa-header class="print-hide"><noscript><header class="banner-neo" id="banner" role="banner" style="background-color: #0b4778;"><div class="banner-wrapper"><h1 class="banner-logo"><a class="banner-logo__link" href="/">Social Security</a></h1><nav class="banner-nav" id="banner-nav"><a class="banner-nav__link banner-search" href="https://search.ssa.gov/search?affiliate=ssa" title="Search" target="_blank"><svg class="banner-nav__icon" focusable="false" width="24" height="24" viewbox="0 0 24 24"><path d="M 10 23 C 11.219 23 12.384 22.762 13.496 22.285 C 14.608 21.808 15.565 21.169 16.367 20.367 C 17.169 19.565 17.808 18.608 18.285 17.496 C 18.762 16.384 19 15.219 19 14 C 19 12.953 18.829 11.951 18.488 10.992 C 18.147 10.033 17.661 9.164 17.031 8.383 L 22.711 2.711 C 22.904 2.518 23 2.281 23 2 C 23 1.713 22.905 1.475 22.715 1.285 C 22.525 1.095 22.287 1 22 1 C 21.719 1 21.482 1.096 21.289 1.289 L 15.617 6.969 C 14.836 6.339 13.966 5.853 13.008 5.512 C 12.05 5.171 11.047 5 10 5 C 8.781 5 7.616 5.238 6.504 5.715 C 5.392 6.192 4.435 6.831 3.633 7.633 C 2.831 8.435 2.192 9.392 1.715 10.504 C 1.238 11.616 1 12.781 1 14 C 1 15.219 1.238 16.384 1.715 17.496 C 2.192 18.608 2.831 19.565 3.633 20.367 C 4.435 21.169 5.392 21.808 6.504 22.285 C 7.616 22.762 8.781 23 10 23 Z M 10 21 C 9.052 21 8.146 20.815 7.281 20.445 C 6.416 20.075 5.672 19.578 5.047 18.953 C 4.422 18.328 3.925 17.584 3.555 16.719 C 3.185 15.854 3 14.948 3 14 C 3 13.052 3.185 12.146 3.555 11.281 C 3.925 10.416 4.422 9.672 5.047 9.047 C 5.672 8.422 6.416 7.925 7.281 7.555 C 8.146 7.185 9.052 7 10 7 C 10.948 7 11.854 7.185 12.719 7.555 C 13.584 7.925 14.328 8.422 14.953 9.047 C 15.578 9.672 16.075 10.416 16.445 11.281 C 16.815 12.146 17 13.052 17 14 C 17 14.948 16.815 15.854 16.445 16.719 C 16.075 17.584 15.578 18.328 14.953 18.953 C 14.328 19.578 13.584 20.075 12.719 20.445 C 11.854 20.815 10.948 21 10 21 Z" transform="matrix(-1, 0, 0, -1, 24.000001, 24.000001)" vector-effect="non-scaling-stroke"></path></svg> <span>Search</span> </a><a class="banner-nav__link banner-menu" href="/menu" id="ssa-menu" title="Menu"><svg class="banner-nav__icon" focusable="false" width="24" height="24" viewbox="0 0 24 24"><path d="M3 5h18q.414 0 .707.293T22 6t-.293.707T21 7H3q-.414 0-.707-.293T2 6t.293-.707T3 5zm0 12h18q.414 0 .707.293T22 18t-.293.707T21 19H3q-.414 0-.707-.293T2 18t.293-.707T3 17zm0-6h18q.414 0 .707.293T22 12t-.293.707T21 13H3q-.414 0-.707-.293T2 12t.293-.707T3 11z" vector-effect="non-scaling-stroke"></path></svg> <span>Menu</span> </a><a class="banner-nav__link banner-languages" href="/es" id="ssa-languages" title="Español" hreflang="es"><svg class="banner-nav__icon" focusable="false" width="24" height="24" viewbox="0 0 24 24"><path d="M12 0C5.373 0 0 5.373 0 12s5.373 12 12 12c.812 0 1.604-.08 2.37-.235-.31-.147-.343-1.255-.037-1.887.34-.703 1.406-2.485.35-3.08-1.053-.6-.76-.868-1.405-1.56-.644-.692-.38-.796-.422-.974-.14-.61.62-1.523.656-1.616.035-.094.035-.446.023-.55-.012-.107-.48-.387-.597-.4-.117-.01-.176.188-.34.2-.164.012-.88-.433-1.03-.55-.154-.117-.224-.398-.435-.61-.21-.212-.235-.047-.562-.175-.327-.13-1.382-.516-2.19-.844-.81-.33-.88-.79-.892-1.114-.012-.325-.492-.797-.718-1.137-.225-.342-.267-.81-.348-.705-.082.106.422 1.336.34 1.37-.083.037-.26-.338-.493-.643-.235-.304.245-.14-.505-1.617-.75-1.476.235-2.23.282-3 .048-.77.633.28.328-.21-.304-.493.023-1.524-.21-1.9-.235-.374-1.57.423-1.57.423.034-.363 1.17-.985 1.99-1.56.82-.573 1.322-.128 1.982.083.66.21.703.142.48-.07-.222-.21.094-.316.61-.235.516.082.656.704 1.442.645.784-.06.08.152.186.35.105.2-.117.177-.633.53-.516.35.012.35.926 1.02.913.667.632-.447.538-.94-.094-.49.668-.105.668-.105.563.375.46.02.87.15.408.13 1.52 1.07 1.52 1.07-1.395.762-.516.844-.282 1.02.235.175-.48.515-.48.515-.294-.293-.34.012-.528.117-.187.105-.012.375-.012.375-.97.153-.75 1.173-.738 1.418.012.247-.62.622-.786.973-.164.35.423 1.113.117 1.16-.305.048-.61-1.148-2.25-.703-.495.134-1.593.703-1.008 1.863.585 1.16 1.558-.328 1.886-.164.33.163-.093.902-.023.913.07.012.927.033.974 1.032.048 1 1.3.914 1.57.938.27.023 1.173-.74 1.3-.774.13-.035.646-.47 1.77.175 1.126.644 1.7.55 2.086.82.387.27.117.81.48.985.365.176 1.818-.058 2.18.54.364.597-1.5 3.597-2.085 3.925-.586.328-.856 1.078-1.442 1.558-.69.563-1.418 1.076-2.18 1.535-.684.407-.807 1.137-1.112 1.367C19.984 22.52 24 17.73 24 12c0-6.627-5.373-12-12-12zm2.813 11.262c-.165.047-.504.352-1.336-.14-.832-.494-1.406-.4-1.477-.48 0 0-.07-.2.293-.236.747-.072 1.688.692 1.9.704.21.012.315-.21.69-.09.375.12.094.195-.07.242zM10.887 1.196c-.082-.06.068-.128.157-.246.05-.07.013-.182.078-.246.175-.177 1.043-.423.874.058-.17.48-.98.527-1.11.434zm2.098 1.523c-.293-.013-.983-.086-.856-.212.494-.492-.188-.633-.61-.668-.423-.036-.598-.27-.388-.294.21-.024 1.055.013 1.196.13.14.117.902.422.95.644.047.223 0 .41-.293.4zm2.542-.083c-.234.188-1.413-.673-1.64-.867-.985-.844-1.513-.563-1.72-.703-.206-.142-.132-.33.184-.61.318-.282 1.21.094 1.724.152.516.058 1.113.457 1.125.93.01.474.562.91.327 1.097z" vector-effect="non-scaling-stroke"></path></svg> <span>Español</span> </a><a class="banner-nav__link banner-signin" href="https://secure.ssa.gov/RIL/SiView.action" id="ssa-signin" title="Sign in" target="_blank"><svg class="banner-nav__icon" focusable="false" width="24" height="24" viewbox="0 0 24 24"><path d="M12 17.016q-.797 0-1.406-.61t-.61-1.405.61-1.405 1.406-.61 1.406.61.61 1.406-.61 1.407-1.406.61zm6 3V9.986H6v10.03h12zm-6-17.11q-1.266 0-2.18.914T8.906 6H9v2.016h6.094V6q0-1.266-.914-2.18T12 2.906zm6 5.11q.797 0 1.406.586t.61 1.383v10.03q0 .798-.61 1.384T18 21.984H6q-.797 0-1.406-.586t-.61-1.384V9.986q0-.798.61-1.384T6 8.016h.984V6q0-2.063 1.477-3.54T12 .985t3.54 1.477T17.015 6v2.016H18z" vector-effect="non-scaling-stroke"></path></svg> <span>Sign in</span></a></nav></div></header></noscript></ssa-header><script src="https://www.ssa.gov/legacy/components/dist/ssa-header.js"></script>
|
||
|
||
<!-- PAGE NAVIGATION -->
|
||
<a class="btn-top-menu show-phone" id="btn-top-menu" href="#nav-top-menu">OLCA MENU</a>
|
||
<nav class="nav-top-menu hide-print" id="nav-top-menu" role="navigation">
|
||
<ul>
|
||
<li><a href="/legislation/index.html">OLCA Home</a></li>
|
||
<li><a href="/legislation/118th.html">118th Congress</a></li>
|
||
<li><a href="/legislation/priorcongress.html">Prior Sessions of Congress</a></li>
|
||
<li><a href="/legislation/resources.html">Program Resources</a></li>
|
||
<li><a href="/legislation/other.html">Other Materials for Congress</a></li>
|
||
</ul>
|
||
</nav>
|
||
|
||
<!-- PAGE TITLE -->
|
||
<div id="title-bar">
|
||
<h2>Social Security Legislative Bulletin</h2></div>
|
||
|
||
<!-- PAGE CONTENT -->
|
||
<div id="content" role="main">
|
||
|
||
<!-- GRID SYSTEM -->
|
||
<div class="grid">
|
||
<div class="row-12">
|
||
|
||
|
||
<!-- NEWS - PAGE 1 -->
|
||
<div class="column-12 topic">
|
||
<p align="center"> </p>
|
||
<p><strong>Number: 117-1 </strong><br>
|
||
<strong>Date: January 28, 2021</strong></p>
|
||
<p align="center"><strong>House Passes H.R. 21, the<br>
|
||
“Federal Risk and Authorization Management Program (FedRAMP)<br>Authorization Act of 2021”
|
||
</strong></p>
|
||
|
||
|
||
<p>On January 5, 2021, the House suspended the rules and passed <a href="https://www.congress.gov/bill/117th-congress/house-bill/21/text?format=txt&q=%7B%22search%22%3A%5B%22hr+21%22%5D%7D&r=1&s=1" target="_blank">H.R. 21</a>, the Federal Risk and Authorization Management Program (FedRAMP) Authorization Act of 2021, by voice vote. The bill was moved to the Senate for action on January 6. Introduced by Representative Gerald E. Connolly on January 4, the bill would codify FedRAMP.</p>
|
||
|
||
<p>H.R. 21 includes the following provisions of interest to SSA that would be codified at 44 USC:</p>
|
||
|
||
<p><strong>Sec. 3607 Federal Risk and Authorization Management Program (FedRAMP)</strong></p>
|
||
|
||
<p>
|
||
<ul><li>Would establish FedRAMP within the General Services Administration (GSA) and establish the Joint Authorization Board (JAB) and the FedRAMP Program Management Office (PMO) as components of FedRAMP.</li></ul></p>
|
||
|
||
<p><strong>Sec. 3608 FedRAMP Program Management Office (PMO)</strong></p>
|
||
|
||
<p>
|
||
<ul><li>Would require the Administrator of GSA (Administrator) to coordinate a process for the PMO, JAB and agencies to review security assessments of cloud computing products and services.</li></ul></p>
|
||
|
||
<ul><li>Would require the PMO to:</li></ul></p>
|
||
|
||
<ul><ul><li>develop templates and other materials to support the Board and agencies in the authorization of cloud computing products and services;</li></ul></ul>
|
||
|
||
<ul><ul><li>the Federal tenant will only grant the covered entity access to such space if it determines that access is consistent with its mission and responsibilities; and</li></ul></ul>
|
||
|
||
<ul><ul><li>establish frameworks for agencies to use authorization packages processed by the PMO and JAB; and</li></ul></ul>
|
||
|
||
<ul><ul><li>establish a centralized and secure repository to collect and share necessary data, including security authorization packages, from the JAB and agencies to enable better sharing and reuse of such packages across agencies.</li></ul></ul>
|
||
|
||
<p>
|
||
<ul><li>Would require the PMO to establish annual metrics regarding the time and quality of the assessments necessary for completion of a FedRAMP authorization process in a manner that minimizes the agency reporting burden.</li></ul></p>
|
||
|
||
<p><strong>Sec. 3609 Joint Authorization Board (JAB)</strong></p>
|
||
|
||
<p>
|
||
<ul><li>Would require the JAB to establish requirements and guidelines for security assessments of cloud computing products and services, consistent with NIST standards, to be used by agencies.</li></ul></p>
|
||
|
||
<p><strong>Sec. 3611 Roles and responsibilities of agencies</strong></p>
|
||
|
||
<p>
|
||
<ul><li>Would require the head of each agency to:</li></ul></p>
|
||
|
||
<ul><ul><li>create policies to ensure cloud computing products and services used by the agency meet FedRAMP security requirements and submit such polices, no later than 6 months after enactment of this section, to the Director of the Office of Management and Budget (Director) for review and approval;</li></ul></ul>
|
||
|
||
<ul><ul><li>issue agency-specific “authorizations to operate” for cloud computing services ;</li></ul></ul>
|
||
|
||
<ul><ul><li>confirm whether there is a FedRAMP authorization or provisional authorization in the cloud security repository established under 3608 before beginning the award process;</li></ul></ul>
|
||
|
||
<ul><ul><li>use the existing assessments of security controls and materials within the authorization package, to the extent possible, for any cloud computing product or service the agency seeks to authorize that has received a FedRAMP authorization or provisional authorization; and</li></ul></ul>
|
||
|
||
<ul><ul><li>provide data and information required to the Director under section 3612 to determine how agencies are meeting metrics as defined by the PMO.</li></ul></ul>
|
||
|
||
<p>
|
||
<ul><li>Would require the head of each agency to provide to the PMO a copy of the authorization to operate letter required under section 3608.</li></ul></p>
|
||
|
||
<p><strong>Sec. 3612 Roles and Responsibilities of the Office of Management and Budget</strong></p>
|
||
|
||
<p>
|
||
<ul><li>Would require the Director to:</li></ul></p>
|
||
|
||
<ul><ul><li>issue guidance to ensure that an agency does not operate a Federal Government cloud computing product or service using Government data without an authorization to operate issued by the agency that meets the information security requirements of <a href="https://uscode.house.gov/browse/prelim@title44/chapter35&edition=prelim" target="_blank">subchapter II of chapter 35</a> and the FedRAMP authorization or provisional authorization;</li></ul></ul>
|
||
|
||
<ul><ul><li>ensure agencies are in compliance with any guidance or other requirements issued related to FedRAMP; and</li></ul></ul>
|
||
|
||
<ul><ul><li>review, analyze, and update guidance on the adoption, security, and use of cloud computing services used by agencies.</li></ul></ul>
|
||
|
||
<p><strong>Sec. 3614 Reports to Congress; GAO Report</strong></p>
|
||
|
||
<p>
|
||
<ul><li>Would require the Director to submit a report, no later than 12 months after enactment of this section, to the House Committee on Oversight and Reform and the Senate Committee on Homeland Security and Governmental Affairs that includes:</li></ul></p>
|
||
|
||
<ul><ul><li>the status, efficiency, and effectiveness of the PMO and agencies during the preceding year in supporting the speed, effectiveness, sharing, reuse, and security of authorizations to operate for cloud computing products and services, including progress towards meeting the metrics adopted by the PMO and the JAB;</li></ul></ul>
|
||
|
||
<ul><ul><li>the number and characteristics of authorized cloud computing products and services in use at each agency consistent with guidance provided by the Director in section 3612; and</li></ul></ul>
|
||
|
||
<ul><ul><li>the cost incurred by agencies and cloud service providers related to the issuance of FedRAMP authorizations and provisional authorizations, including information responsive to the GAO report.</li></ul></ul>
|
||
|
||
<p>
|
||
<ul><li>Would require the Comptroller General of GAO to publish a report, no later than 6 months after the date of the enactment of this section, that includes an assessment of the cost incurred by agencies and cloud service providers related to the issuance of FedRAMP authorizations and provisional authorizations.</li></ul></p>
|
||
|
||
<p><strong>Sec. 3615 Federal Secure Cloud Advisory Committee</strong></p>
|
||
|
||
<p>
|
||
<ul><li>Would establish a Federal Secure Cloud Advisory Committee (Committee) to ensure effective and ongoing coordination of agency adoption, use, authorization, monitoring, acquisition, and security of cloud computing products and services.</li></ul></p>
|
||
|
||
<p>
|
||
<ul><li>Would authorize the Committee to secure information directly from any agency to carry out the Committee’s purpose and require the agency, to the extent authorized by law, to furnish such information to the Committee upon request.</li></ul></p>
|
||
|
||
<p>
|
||
<ul><li>Would allow any Federal Government employee to be detailed to the Committee without reimbursement from the Committee, and require the detailee to retain the rights of their regular employment without interruption.</li></ul></p>
|
||
|
||
<p>Unless stated otherwise, all provisions would be effective upon enactment. The legislation would sunset 10 years after enactment.</p>
|
||
|
||
<p>________________</p>
|
||
|
||
<p>1 FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by agencies.<br>
|
||
2 As proposed to be defined in 44 USC §3616, “authorization package” means, in general, the information used to determine whether to authorize the operation of an information system.<br>
|
||
3 In compliance with title 44, §3554 U.S. Code.<br>
|
||
4 Section 14 of the Federal Advisory Committee Act (<a href="https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title5a-node2-section14&num=0&edition=prelim" target="_blank">5 U.S.C. App.</a>) does not apply to the Committee.
|
||
</p>
|
||
|
||
<div>
|
||
<div id="ftn1"></div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</body>
|
||
</html> |