1 | 1 | | I |
---|
2 | 2 | | 118THCONGRESS |
---|
3 | 3 | | 1 |
---|
4 | 4 | | STSESSION H. R. 5218 |
---|
5 | 5 | | To amend the Carl Levin and Howard P. ‘‘Buck’’ McKeon National Defense |
---|
6 | 6 | | Authorization Act for Fiscal Year 2015 to modify requirements relating |
---|
7 | 7 | | to data centers of certain Federal agencies, and for other purposes. |
---|
8 | 8 | | IN THE HOUSE OF REPRESENTATIVES |
---|
9 | 9 | | AUGUST15, 2023 |
---|
10 | 10 | | Mr. N |
---|
11 | 11 | | EGUSE(for himself and Mr. LALOTA) introduced the following bill; |
---|
12 | 12 | | which was referred to the Committee on Oversight and Accountability |
---|
13 | 13 | | A BILL |
---|
14 | 14 | | To amend the Carl Levin and Howard P. ‘‘Buck’’ McKeon |
---|
15 | 15 | | National Defense Authorization Act for Fiscal Year 2015 |
---|
16 | 16 | | to modify requirements relating to data centers of certain |
---|
17 | 17 | | Federal agencies, and for other purposes. |
---|
18 | 18 | | Be it enacted by the Senate and House of Representa-1 |
---|
19 | 19 | | tives of the United States of America in Congress assembled, 2 |
---|
20 | 20 | | SECTION 1. SHORT TITLE. 3 |
---|
21 | 21 | | This Act may be cited as the ‘‘Federal Data Center 4 |
---|
22 | 22 | | Enhancement Act of 2023’’. 5 |
---|
23 | 23 | | SEC. 2. FEDERAL DATA CENTER CONSOLIDATION INITIA-6 |
---|
24 | 24 | | TIVE AMENDMENTS. 7 |
---|
25 | 25 | | (a) F |
---|
26 | 26 | | INDINGS.—Congress finds the following: 8 |
---|
27 | 27 | | VerDate Sep 11 2014 00:14 Aug 23, 2023 Jkt 039200 PO 00000 Frm 00001 Fmt 6652 Sfmt 6201 E:\BILLS\H5218.IH H5218 |
---|
28 | 28 | | kjohnson on DSK79L0C42PROD with BILLS 2 |
---|
29 | 29 | | •HR 5218 IH |
---|
30 | 30 | | (1) The statutory authorization for the Federal 1 |
---|
31 | 31 | | Data Center Optimization Initiative under section 2 |
---|
32 | 32 | | 834 of the Carl Levin and Howard P. ‘‘Buck’’ 3 |
---|
33 | 33 | | McKeon National Defense Authorization Act for 4 |
---|
34 | 34 | | Fiscal Year 2015 (44 U.S.C. 3601 note; Public Law 5 |
---|
35 | 35 | | 113–291) expires at the end of fiscal year 2022. 6 |
---|
36 | 36 | | (2) The expiration of the authorization de-7 |
---|
37 | 37 | | scribed in paragraph (1) presents Congress with an 8 |
---|
38 | 38 | | opportunity to review the objectives of the Federal 9 |
---|
39 | 39 | | Data Center Optimization Initiative to ensure that 10 |
---|
40 | 40 | | the initiative is meeting the current needs of the 11 |
---|
41 | 41 | | Federal Government. 12 |
---|
42 | 42 | | (3) The initial focus of the Federal Data Center 13 |
---|
43 | 43 | | Optimization Initiative, which was to consolidate 14 |
---|
44 | 44 | | data centers and create new efficiencies, has resulted 15 |
---|
45 | 45 | | in, since 2010— 16 |
---|
46 | 46 | | (A) the consolidation of more than 6,000 17 |
---|
47 | 47 | | Federal data centers; and 18 |
---|
48 | 48 | | (B) cost savings and avoidance of 19 |
---|
49 | 49 | | $5,800,000,000. 20 |
---|
50 | 50 | | (4) The need of the Federal Government for ac-21 |
---|
51 | 51 | | cess to data and data processing systems has evolved 22 |
---|
52 | 52 | | since the date of enactment in 2014 of subtitle D of 23 |
---|
53 | 53 | | title VIII of the Carl Levin and Howard P. ‘‘Buck’’ 24 |
---|
54 | 54 | | VerDate Sep 11 2014 00:14 Aug 23, 2023 Jkt 039200 PO 00000 Frm 00002 Fmt 6652 Sfmt 6201 E:\BILLS\H5218.IH H5218 |
---|
55 | 55 | | kjohnson on DSK79L0C42PROD with BILLS 3 |
---|
56 | 56 | | •HR 5218 IH |
---|
57 | 57 | | McKeon National Defense Authorization Act for 1 |
---|
58 | 58 | | Fiscal Year 2015. 2 |
---|
59 | 59 | | (5) Federal agencies and employees involved in 3 |
---|
60 | 60 | | mission critical functions increasingly need reliable 4 |
---|
61 | 61 | | access to secure, reliable, sustainable, and protected 5 |
---|
62 | 62 | | facilities to house mission critical data and data op-6 |
---|
63 | 63 | | erations to meet the immediate needs of the people 7 |
---|
64 | 64 | | of the United States. 8 |
---|
65 | 65 | | (6) As of the date of enactment of this Act, 9 |
---|
66 | 66 | | there is a growing need for Federal agencies to use 10 |
---|
67 | 67 | | data centers and cloud applications that meet high 11 |
---|
68 | 68 | | standards for cybersecurity, resiliency, availability, 12 |
---|
69 | 69 | | and sustainability. 13 |
---|
70 | 70 | | (b) M |
---|
71 | 71 | | INIMUMREQUIREMENTS FOR NEWDATACEN-14 |
---|
72 | 72 | | TERS.—Section 834 of the Carl Levin and Howard P. 15 |
---|
73 | 73 | | ‘‘Buck’’ McKeon National Defense Authorization Act for 16 |
---|
74 | 74 | | Fiscal Year 2015 (44 U.S.C. 3601 note; Public Law 113– 17 |
---|
75 | 75 | | 291) is amended— 18 |
---|
76 | 76 | | (1) in subsection (a), by striking paragraphs 19 |
---|
77 | 77 | | (3) and (4) and inserting the following: 20 |
---|
78 | 78 | | ‘‘(3) N |
---|
79 | 79 | | EW DATA CENTER.—The term ‘new data 21 |
---|
80 | 80 | | center’ means— 22 |
---|
81 | 81 | | ‘‘(A)(i) a data center or a portion thereof 23 |
---|
82 | 82 | | that is owned, operated, or maintained by a 24 |
---|
83 | 83 | | covered agency; or 25 |
---|
84 | 84 | | VerDate Sep 11 2014 00:14 Aug 23, 2023 Jkt 039200 PO 00000 Frm 00003 Fmt 6652 Sfmt 6201 E:\BILLS\H5218.IH H5218 |
---|
85 | 85 | | kjohnson on DSK79L0C42PROD with BILLS 4 |
---|
86 | 86 | | •HR 5218 IH |
---|
87 | 87 | | ‘‘(ii) to the extent practicable, a data cen-1 |
---|
88 | 88 | | ter or portion thereof— 2 |
---|
89 | 89 | | ‘‘(I) that is owned, operated, or main-3 |
---|
90 | 90 | | tained by a contractor on behalf of a cov-4 |
---|
91 | 91 | | ered agency on the date on which the con-5 |
---|
92 | 92 | | tract between the covered agency and the 6 |
---|
93 | 93 | | contractor expires; and 7 |
---|
94 | 94 | | ‘‘(II) with respect to which the cov-8 |
---|
95 | 95 | | ered agency extends the contract, or enters 9 |
---|
96 | 96 | | into a new contract, with the contractor; 10 |
---|
97 | 97 | | and 11 |
---|
98 | 98 | | ‘‘(B) on or after the date that is 180 days 12 |
---|
99 | 99 | | after the date of enactment of the Federal Data 13 |
---|
100 | 100 | | Center Enhancement Act of 2023, a data cen-14 |
---|
101 | 101 | | ter or portion thereof that is— 15 |
---|
102 | 102 | | ‘‘(i) established; or 16 |
---|
103 | 103 | | ‘‘(ii) substantially upgraded or ex-17 |
---|
104 | 104 | | panded.’’; 18 |
---|
105 | 105 | | (2) by striking subsection (b) and inserting the 19 |
---|
106 | 106 | | following: 20 |
---|
107 | 107 | | ‘‘(b) M |
---|
108 | 108 | | INIMUMREQUIREMENTS FOR NEWDATA 21 |
---|
109 | 109 | | C |
---|
110 | 110 | | ENTERS.— 22 |
---|
111 | 111 | | ‘‘(1) I |
---|
112 | 112 | | N GENERAL.—Not later than 180 days 23 |
---|
113 | 113 | | after the date of enactment of the Federal Data 24 |
---|
114 | 114 | | Center Enhancement Act of 2023, the Administrator 25 |
---|
115 | 115 | | VerDate Sep 11 2014 00:14 Aug 23, 2023 Jkt 039200 PO 00000 Frm 00004 Fmt 6652 Sfmt 6201 E:\BILLS\H5218.IH H5218 |
---|
116 | 116 | | kjohnson on DSK79L0C42PROD with BILLS 5 |
---|
117 | 117 | | •HR 5218 IH |
---|
118 | 118 | | shall establish minimum requirements for new data 1 |
---|
119 | 119 | | centers in consultation with the Administrator of 2 |
---|
120 | 120 | | General Services and the Federal Chief Information 3 |
---|
121 | 121 | | Officers Council. 4 |
---|
122 | 122 | | ‘‘(2) C |
---|
123 | 123 | | ONTENTS.— 5 |
---|
124 | 124 | | ‘‘(A) I |
---|
125 | 125 | | N GENERAL.—The minimum re-6 |
---|
126 | 126 | | quirements established under paragraph (1) 7 |
---|
127 | 127 | | shall include requirements relating to— 8 |
---|
128 | 128 | | ‘‘(i) the availability of new data cen-9 |
---|
129 | 129 | | ters; 10 |
---|
130 | 130 | | ‘‘(ii) the use of new data centers; 11 |
---|
131 | 131 | | ‘‘(iii) the use of sustainable energy 12 |
---|
132 | 132 | | sources; 13 |
---|
133 | 133 | | ‘‘(iv) uptime percentage; 14 |
---|
134 | 134 | | ‘‘(v) protections against power fail-15 |
---|
135 | 135 | | ures, including on-site energy generation 16 |
---|
136 | 136 | | and access to multiple transmission paths; 17 |
---|
137 | 137 | | ‘‘(vi) protections against physical in-18 |
---|
138 | 138 | | trusions and natural disasters; 19 |
---|
139 | 139 | | ‘‘(vii) information security protections 20 |
---|
140 | 140 | | required by subchapter II of chapter 35 of 21 |
---|
141 | 141 | | title 44, United States Code, and other ap-22 |
---|
142 | 142 | | plicable law and policy; and 23 |
---|
143 | 143 | | ‘‘(viii) any other requirements the Ad-24 |
---|
144 | 144 | | ministrator determines appropriate. 25 |
---|
145 | 145 | | VerDate Sep 11 2014 00:14 Aug 23, 2023 Jkt 039200 PO 00000 Frm 00005 Fmt 6652 Sfmt 6201 E:\BILLS\H5218.IH H5218 |
---|
146 | 146 | | kjohnson on DSK79L0C42PROD with BILLS 6 |
---|
147 | 147 | | •HR 5218 IH |
---|
148 | 148 | | ‘‘(B) CONSULTATION.—In establishing the 1 |
---|
149 | 149 | | requirements described in subparagraph 2 |
---|
150 | 150 | | (A)(vii), the Administrator shall consult with 3 |
---|
151 | 151 | | the Director of the Cybersecurity and Infra-4 |
---|
152 | 152 | | structure Security Agency and the National 5 |
---|
153 | 153 | | Cyber Director. 6 |
---|
154 | 154 | | ‘‘(3) I |
---|
155 | 155 | | NCORPORATION OF MINIMUM REQUIRE -7 |
---|
156 | 156 | | MENTS INTO CURRENT DATA CENTERS .—As soon as 8 |
---|
157 | 157 | | practicable, and in any case not later than 90 days 9 |
---|
158 | 158 | | after the Administrator establishes the minimum re-10 |
---|
159 | 159 | | quirements pursuant to paragraph (1), the Adminis-11 |
---|
160 | 160 | | trator shall issue guidance to ensure, as appropriate, 12 |
---|
161 | 161 | | that covered agencies incorporate the minimum re-13 |
---|
162 | 162 | | quirements established under that paragraph into 14 |
---|
163 | 163 | | the operations of any data center of a covered agen-15 |
---|
164 | 164 | | cy existing as of the date of enactment of the Fed-16 |
---|
165 | 165 | | eral Data Center Enhancement Act of 2023. 17 |
---|
166 | 166 | | ‘‘(4) R |
---|
167 | 167 | | EVIEW OF REQUIREMENTS .—The Admin-18 |
---|
168 | 168 | | istrator, in consultation with the Administrator of 19 |
---|
169 | 169 | | General Services and the Federal Chief Information 20 |
---|
170 | 170 | | Officers Council, shall review, update, and modify 21 |
---|
171 | 171 | | the minimum requirements established under para-22 |
---|
172 | 172 | | graph (1), as necessary. 23 |
---|
173 | 173 | | ‘‘(5) R |
---|
174 | 174 | | EPORT ON NEW DATA CENTERS .—During 24 |
---|
175 | 175 | | the development and planning lifecycle of a new data 25 |
---|
176 | 176 | | VerDate Sep 11 2014 00:14 Aug 23, 2023 Jkt 039200 PO 00000 Frm 00006 Fmt 6652 Sfmt 6201 E:\BILLS\H5218.IH H5218 |
---|
177 | 177 | | kjohnson on DSK79L0C42PROD with BILLS 7 |
---|
178 | 178 | | •HR 5218 IH |
---|
179 | 179 | | center, if the head of a covered agency determines 1 |
---|
180 | 180 | | that the covered agency is likely to make a manage-2 |
---|
181 | 181 | | ment or financial decision relating to any data cen-3 |
---|
182 | 182 | | ter, the head of the covered agency shall— 4 |
---|
183 | 183 | | ‘‘(A) notify— 5 |
---|
184 | 184 | | ‘‘(i) the Administrator; 6 |
---|
185 | 185 | | ‘‘(ii) Committee on Homeland Secu-7 |
---|
186 | 186 | | rity and Governmental Affairs of the Sen-8 |
---|
187 | 187 | | ate; and 9 |
---|
188 | 188 | | ‘‘(iii) Committee on Oversight and Ac-10 |
---|
189 | 189 | | countability of the House of Representa-11 |
---|
190 | 190 | | tives; and 12 |
---|
191 | 191 | | ‘‘(B) describe in the notification with suffi-13 |
---|
192 | 192 | | cient detail how the covered agency intends to 14 |
---|
193 | 193 | | comply with the minimum requirements estab-15 |
---|
194 | 194 | | lished under paragraph (1). 16 |
---|
195 | 195 | | ‘‘(6) U |
---|
196 | 196 | | SE OF TECHNOLOGY .—In determining 17 |
---|
197 | 197 | | whether to establish or continue to operate an exist-18 |
---|
198 | 198 | | ing data center, the head of a covered agency shall— 19 |
---|
199 | 199 | | ‘‘(A) regularly assess the application port-20 |
---|
200 | 200 | | folio of the covered agency and ensure that each 21 |
---|
201 | 201 | | at-risk legacy application is updated, replaced, 22 |
---|
202 | 202 | | or modernized, as appropriate, to take advan-23 |
---|
203 | 203 | | tage of modern technologies; and 24 |
---|
204 | 204 | | VerDate Sep 11 2014 00:14 Aug 23, 2023 Jkt 039200 PO 00000 Frm 00007 Fmt 6652 Sfmt 6201 E:\BILLS\H5218.IH H5218 |
---|
205 | 205 | | kjohnson on DSK79L0C42PROD with BILLS 8 |
---|
206 | 206 | | •HR 5218 IH |
---|
207 | 207 | | ‘‘(B) prioritize and, to the greatest extent 1 |
---|
208 | 208 | | possible, leverage commercial cloud environ-2 |
---|
209 | 209 | | ments rather than acquiring, overseeing, or 3 |
---|
210 | 210 | | managing custom data center infrastructure. 4 |
---|
211 | 211 | | ‘‘(7) P |
---|
212 | 212 | | UBLIC WEBSITE.— 5 |
---|
213 | 213 | | ‘‘(A) I |
---|
214 | 214 | | N GENERAL.—The Administrator 6 |
---|
215 | 215 | | shall maintain a public-facing website that in-7 |
---|
216 | 216 | | cludes information, data, and explanatory state-8 |
---|
217 | 217 | | ments relating to the compliance of covered 9 |
---|
218 | 218 | | agencies with the requirements of this section. 10 |
---|
219 | 219 | | ‘‘(B) P |
---|
220 | 220 | | ROCESSES AND PROCEDURES .—In 11 |
---|
221 | 221 | | maintaining the website described in subpara-12 |
---|
222 | 222 | | graph (A), the Administrator shall— 13 |
---|
223 | 223 | | ‘‘(i) ensure covered agencies regularly, 14 |
---|
224 | 224 | | and not less frequently than biannually, 15 |
---|
225 | 225 | | update the information, data, and explana-16 |
---|
226 | 226 | | tory statements posed on the website, pur-17 |
---|
227 | 227 | | suant to guidance issued by the Adminis-18 |
---|
228 | 228 | | trator, relating to any new data centers 19 |
---|
229 | 229 | | and, as appropriate, each existing data 20 |
---|
230 | 230 | | center of the covered agency; and 21 |
---|
231 | 231 | | ‘‘(ii) ensure that all information, data, 22 |
---|
232 | 232 | | and explanatory statements on the website 23 |
---|
233 | 233 | | are maintained as open Government data 24 |
---|
234 | 234 | | assets.’’; and 25 |
---|
235 | 235 | | VerDate Sep 11 2014 00:14 Aug 23, 2023 Jkt 039200 PO 00000 Frm 00008 Fmt 6652 Sfmt 6201 E:\BILLS\H5218.IH H5218 |
---|
236 | 236 | | kjohnson on DSK79L0C42PROD with BILLS 9 |
---|
237 | 237 | | •HR 5218 IH |
---|
238 | 238 | | (3) in subsection (c), by striking paragraph (1) 1 |
---|
239 | 239 | | and inserting the following: 2 |
---|
240 | 240 | | ‘‘(1) I |
---|
241 | 241 | | N GENERAL.—The head of a covered 3 |
---|
242 | 242 | | agency shall oversee and manage the data center 4 |
---|
243 | 243 | | portfolio and the information technology strategy of 5 |
---|
244 | 244 | | the covered agency in accordance with Federal cy-6 |
---|
245 | 245 | | bersecurity guidelines and directives, including— 7 |
---|
246 | 246 | | ‘‘(A) information security standards and 8 |
---|
247 | 247 | | guidelines promulgated by the Director of the 9 |
---|
248 | 248 | | National Institute of Standards and Tech-10 |
---|
249 | 249 | | nology; 11 |
---|
250 | 250 | | ‘‘(B) applicable requirements and guidance 12 |
---|
251 | 251 | | issued by the Director of the Office of Manage-13 |
---|
252 | 252 | | ment and Budget pursuant to section 3614 of 14 |
---|
253 | 253 | | title 44, United States Code; and 15 |
---|
254 | 254 | | ‘‘(C) directives issued by the Secretary of 16 |
---|
255 | 255 | | Homeland Security under section 3553 of title 17 |
---|
256 | 256 | | 44, United States Code.’’. 18 |
---|
257 | 257 | | (c) E |
---|
258 | 258 | | XTENSION OFSUNSET.—Section 834(e) of the 19 |
---|
259 | 259 | | Carl Levin and Howard P. ‘‘Buck’’ McKeon National De-20 |
---|
260 | 260 | | fense Authorization Act for Fiscal Year 2015 (44 U.S.C. 21 |
---|
261 | 261 | | 3601 note; Public Law 113–291) is amended by striking 22 |
---|
262 | 262 | | ‘‘2022’’ and inserting ‘‘2026’’. 23 |
---|
263 | 263 | | (d) GAO R |
---|
264 | 264 | | EVIEW.—Not later than 1 year after the 24 |
---|
265 | 265 | | date of the enactment of this Act, and annually thereafter, 25 |
---|
266 | 266 | | VerDate Sep 11 2014 00:14 Aug 23, 2023 Jkt 039200 PO 00000 Frm 00009 Fmt 6652 Sfmt 6201 E:\BILLS\H5218.IH H5218 |
---|
267 | 267 | | kjohnson on DSK79L0C42PROD with BILLS 10 |
---|
268 | 268 | | •HR 5218 IH |
---|
269 | 269 | | the Comptroller General of the United States shall review, 1 |
---|
270 | 270 | | verify, and audit the compliance of covered agencies with 2 |
---|
271 | 271 | | the minimum requirements established pursuant to section 3 |
---|
272 | 272 | | 834(b)(1) of the Carl Levin and Howard P. ‘‘Buck’’ 4 |
---|
273 | 273 | | McKeon National Defense Authorization Act for Fiscal 5 |
---|
274 | 274 | | Year 2015 (44 U.S.C. 3601 note; Public Law 113–291) 6 |
---|
275 | 275 | | for new data centers and subsection (b)(3) of that Act for 7 |
---|
276 | 276 | | existing data centers, as appropriate. 8 |
---|
277 | 277 | | Æ |
---|
278 | 278 | | VerDate Sep 11 2014 00:14 Aug 23, 2023 Jkt 039200 PO 00000 Frm 00010 Fmt 6652 Sfmt 6301 E:\BILLS\H5218.IH H5218 |
---|
279 | 279 | | kjohnson on DSK79L0C42PROD with BILLS |
---|