29 | | - | •S 933 RS |
---|
30 | | - | SECTION 1. SHORT TITLE. 1 |
---|
31 | | - | This Act may be cited as the ‘‘Federal Data Center 2 |
---|
32 | | - | Enhancement Act of 2023’’. 3 |
---|
33 | | - | SEC. 2. FEDERAL DATA CENTER CONSOLIDATION INITIA-4 |
---|
34 | | - | TIVE AMENDMENTS. 5 |
---|
35 | | - | (a) F |
---|
36 | | - | INDINGS.—Congress finds the following: 6 |
---|
37 | | - | (1) The statutory authorization for the Federal 7 |
---|
38 | | - | Data Center Optimization Initiative under section 8 |
---|
39 | | - | 834 of the Carl Levin and Howard P. ‘‘Buck’’ 9 |
---|
40 | | - | McKeon National Defense Authorization Act for 10 |
---|
41 | | - | Fiscal Year 2015 (44 U.S.C. 3601 note; Public Law 11 |
---|
42 | | - | 113–291) expires at the end of fiscal year 2022. 12 |
---|
43 | | - | (2) The expiration of the authorization de-13 |
---|
44 | | - | scribed in paragraph (1) presents Congress with an 14 |
---|
45 | | - | opportunity to review the objectives of the Federal 15 |
---|
46 | | - | Data Center Optimization Initiative to ensure that 16 |
---|
47 | | - | the initiative is meeting the current needs of the 17 |
---|
48 | | - | Federal Government. 18 |
---|
49 | | - | (3) The initial focus of the Federal Data Center 19 |
---|
50 | | - | Optimization Initiative, which was to consolidate 20 |
---|
51 | | - | data centers and create new efficiencies, has resulted 21 |
---|
52 | | - | in, since 2010— 22 |
---|
53 | | - | (A) the consolidation of more than 6,000 23 |
---|
54 | | - | Federal data centers; and 24 |
---|
55 | | - | (B) cost savings and avoidance of 25 |
---|
56 | | - | $5,800,000,000. 26 |
---|
57 | | - | VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00002 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933 |
---|
| 30 | + | •S 933 IS |
---|
| 31 | + | (1) The statutory authorization for the Federal 1 |
---|
| 32 | + | Data Center Optimization Initiative under section 2 |
---|
| 33 | + | 834 of the Carl Levin and Howard P. ‘‘Buck’’ 3 |
---|
| 34 | + | McKeon National Defense Authorization Act for 4 |
---|
| 35 | + | Fiscal Year 2015 (44 U.S.C. 3601 note; Public Law 5 |
---|
| 36 | + | 113–291) expires at the end of fiscal year 2022. 6 |
---|
| 37 | + | (2) The expiration of the authorization de-7 |
---|
| 38 | + | scribed in paragraph (1) presents Congress with an 8 |
---|
| 39 | + | opportunity to review the objectives of the Federal 9 |
---|
| 40 | + | Data Center Optimization Initiative to ensure that 10 |
---|
| 41 | + | the initiative is meeting the current needs of the 11 |
---|
| 42 | + | Federal Government. 12 |
---|
| 43 | + | (3) The initial focus of the Federal Data Center 13 |
---|
| 44 | + | Optimization Initiative, which was to consolidate 14 |
---|
| 45 | + | data centers and create new efficiencies, has resulted 15 |
---|
| 46 | + | in, since 2010— 16 |
---|
| 47 | + | (A) the consolidation of more than 6,000 17 |
---|
| 48 | + | Federal data centers; and 18 |
---|
| 49 | + | (B) cost savings and avoidance of 19 |
---|
| 50 | + | $5,800,000,000. 20 |
---|
| 51 | + | (4) The need of the Federal Government for ac-21 |
---|
| 52 | + | cess to data and data processing systems has evolved 22 |
---|
| 53 | + | since the date of enactment in 2014 of subtitle D of 23 |
---|
| 54 | + | title VIII of the Carl Levin and Howard P. ‘‘Buck’’ 24 |
---|
| 55 | + | VerDate Sep 11 2014 23:25 Mar 22, 2023 Jkt 039200 PO 00000 Frm 00002 Fmt 6652 Sfmt 6201 E:\BILLS\S933.IS S933 |
---|
87 | | - | •S 933 RS |
---|
88 | | - | ‘‘(3) NEW DATA CENTER.—The term ‘new data 1 |
---|
89 | | - | center’ means— 2 |
---|
90 | | - | ‘‘(A)(i) a data center or a portion thereof 3 |
---|
91 | | - | that is owned, operated, or maintained by a 4 |
---|
92 | | - | covered agency; or 5 |
---|
93 | | - | ‘‘(ii) to the extent practicable, a data cen-6 |
---|
94 | | - | ter or portion thereof— 7 |
---|
95 | | - | ‘‘(I) that is owned, operated, or main-8 |
---|
96 | | - | tained by a contractor on behalf of a cov-9 |
---|
97 | | - | ered agency on the date on which the con-10 |
---|
98 | | - | tract between the covered agency and the 11 |
---|
99 | | - | contractor expires; and 12 |
---|
100 | | - | ‘‘(II) with respect to which the cov-13 |
---|
101 | | - | ered agency extends the contract, or enters 14 |
---|
102 | | - | into a new contract, with the contractor; 15 |
---|
103 | | - | and 16 |
---|
104 | | - | ‘‘(B) on or after the date that is 180 days 17 |
---|
105 | | - | after the date of enactment of the Federal Data 18 |
---|
106 | | - | Center Enhancement Act of 2023, a data cen-19 |
---|
107 | | - | ter or portion thereof that is— 20 |
---|
108 | | - | ‘‘(i) established; or 21 |
---|
109 | | - | ‘‘(ii) substantially upgraded or ex-22 |
---|
110 | | - | panded.’’; 23 |
---|
111 | | - | (2) by striking subsection (b) and inserting the 24 |
---|
112 | | - | following: 25 |
---|
113 | | - | VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00004 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933 |
---|
| 87 | + | •S 933 IS |
---|
| 88 | + | ‘‘(ii) to the extent practicable, a data cen-1 |
---|
| 89 | + | ter or portion thereof— 2 |
---|
| 90 | + | ‘‘(I) that is owned, operated, or main-3 |
---|
| 91 | + | tained by a contractor on behalf of a cov-4 |
---|
| 92 | + | ered agency on the date on which the con-5 |
---|
| 93 | + | tract between the covered agency and the 6 |
---|
| 94 | + | contractor expires; and 7 |
---|
| 95 | + | ‘‘(II) with respect to which the cov-8 |
---|
| 96 | + | ered agency extends the contract, or enters 9 |
---|
| 97 | + | into a new contract, with the contractor; 10 |
---|
| 98 | + | and 11 |
---|
| 99 | + | ‘‘(B) on or after the date that is 180 days 12 |
---|
| 100 | + | after the date of enactment of the Federal Data 13 |
---|
| 101 | + | Center Enhancement Act of 2023, a data cen-14 |
---|
| 102 | + | ter or portion thereof that is— 15 |
---|
| 103 | + | ‘‘(i) established; or 16 |
---|
| 104 | + | ‘‘(ii) substantially upgraded or ex-17 |
---|
| 105 | + | panded.’’; 18 |
---|
| 106 | + | (2) by striking subsection (b) and inserting the 19 |
---|
| 107 | + | following: 20 |
---|
| 108 | + | ‘‘(b) M |
---|
| 109 | + | INIMUMREQUIREMENTS FOR NEWDATA 21 |
---|
| 110 | + | C |
---|
| 111 | + | ENTERS.— 22 |
---|
| 112 | + | ‘‘(1) I |
---|
| 113 | + | N GENERAL.—Not later than 180 days 23 |
---|
| 114 | + | after the date of enactment of the Federal Data 24 |
---|
| 115 | + | Center Enhancement Act of 2023, the Administrator 25 |
---|
| 116 | + | VerDate Sep 11 2014 23:25 Mar 22, 2023 Jkt 039200 PO 00000 Frm 00004 Fmt 6652 Sfmt 6201 E:\BILLS\S933.IS S933 |
---|
115 | | - | •S 933 RS |
---|
116 | | - | ‘‘(b) MINIMUMREQUIREMENTS FOR NEWDATA 1 |
---|
117 | | - | C |
---|
118 | | - | ENTERS.— 2 |
---|
| 118 | + | •S 933 IS |
---|
| 119 | + | shall establish minimum requirements for new data 1 |
---|
| 120 | + | centers in consultation with the Administrator of 2 |
---|
| 121 | + | General Services and the Federal Chief Information 3 |
---|
| 122 | + | Officers Council. 4 |
---|
| 123 | + | ‘‘(2) C |
---|
| 124 | + | ONTENTS.— 5 |
---|
| 125 | + | ‘‘(A) I |
---|
| 126 | + | N GENERAL.—The minimum re-6 |
---|
| 127 | + | quirements established under paragraph (1) 7 |
---|
| 128 | + | shall include requirements relating to— 8 |
---|
| 129 | + | ‘‘(i) the availability of new data cen-9 |
---|
| 130 | + | ters; 10 |
---|
| 131 | + | ‘‘(ii) the use of new data centers; 11 |
---|
| 132 | + | ‘‘(iii) the use of sustainable energy 12 |
---|
| 133 | + | sources; 13 |
---|
| 134 | + | ‘‘(iv) uptime percentage; 14 |
---|
| 135 | + | ‘‘(v) protections against power fail-15 |
---|
| 136 | + | ures, including on-site energy generation 16 |
---|
| 137 | + | and access to multiple transmission paths; 17 |
---|
| 138 | + | ‘‘(vi) protections against physical in-18 |
---|
| 139 | + | trusions and natural disasters; 19 |
---|
| 140 | + | ‘‘(vii) information security protections 20 |
---|
| 141 | + | required by subchapter II of chapter 35 of 21 |
---|
| 142 | + | title 44, United States Code, and other ap-22 |
---|
| 143 | + | plicable law and policy; and 23 |
---|
| 144 | + | ‘‘(viii) any other requirements the Ad-24 |
---|
| 145 | + | ministrator determines appropriate. 25 |
---|
| 146 | + | VerDate Sep 11 2014 23:25 Mar 22, 2023 Jkt 039200 PO 00000 Frm 00005 Fmt 6652 Sfmt 6201 E:\BILLS\S933.IS S933 |
---|
| 147 | + | pbinns on DSKJLVW7X2PROD with $$_JOB 6 |
---|
| 148 | + | •S 933 IS |
---|
| 149 | + | ‘‘(B) CONSULTATION.—In establishing the 1 |
---|
| 150 | + | requirements described in subparagraph 2 |
---|
| 151 | + | (A)(vii), the Administrator shall consult with 3 |
---|
| 152 | + | the Director of the Cybersecurity and Infra-4 |
---|
| 153 | + | structure Security Agency and the National 5 |
---|
| 154 | + | Cyber Director. 6 |
---|
| 155 | + | ‘‘(3) I |
---|
| 156 | + | NCORPORATION OF MINIMUM REQUIRE -7 |
---|
| 157 | + | MENTS INTO CURRENT DATA CENTERS .—As soon as 8 |
---|
| 158 | + | practicable, and in any case not later than 90 days 9 |
---|
| 159 | + | after the Administrator establishes the minimum re-10 |
---|
| 160 | + | quirements pursuant to paragraph (1), the Adminis-11 |
---|
| 161 | + | trator shall issue guidance to ensure, as appropriate, 12 |
---|
| 162 | + | that covered agencies incorporate the minimum re-13 |
---|
| 163 | + | quirements established under that paragraph into 14 |
---|
| 164 | + | the operations of any data center of a covered agen-15 |
---|
| 165 | + | cy existing as of the date of enactment of the Fed-16 |
---|
| 166 | + | eral Data Center Enhancement Act of 2023. 17 |
---|
| 167 | + | ‘‘(4) R |
---|
| 168 | + | EVIEW OF REQUIREMENTS .—The Admin-18 |
---|
| 169 | + | istrator, in consultation with the Administrator of 19 |
---|
| 170 | + | General Services and the Federal Chief Information 20 |
---|
| 171 | + | Officers Council, shall review, update, and modify 21 |
---|
| 172 | + | the minimum requirements established under para-22 |
---|
| 173 | + | graph (1), as necessary. 23 |
---|
| 174 | + | ‘‘(5) R |
---|
| 175 | + | EPORT ON NEW DATA CENTERS .—During 24 |
---|
| 176 | + | the development and planning lifecycle of a new data 25 |
---|
| 177 | + | VerDate Sep 11 2014 23:25 Mar 22, 2023 Jkt 039200 PO 00000 Frm 00006 Fmt 6652 Sfmt 6201 E:\BILLS\S933.IS S933 |
---|
| 178 | + | pbinns on DSKJLVW7X2PROD with $$_JOB 7 |
---|
| 179 | + | •S 933 IS |
---|
| 180 | + | center, if the head of a covered agency determines 1 |
---|
| 181 | + | that the covered agency is likely to make a manage-2 |
---|
| 182 | + | ment or financial decision relating to any data cen-3 |
---|
| 183 | + | ter, the head of the covered agency shall— 4 |
---|
| 184 | + | ‘‘(A) notify— 5 |
---|
| 185 | + | ‘‘(i) the Administrator; 6 |
---|
| 186 | + | ‘‘(ii) Committee on Homeland Secu-7 |
---|
| 187 | + | rity and Governmental Affairs of the Sen-8 |
---|
| 188 | + | ate; and 9 |
---|
| 189 | + | ‘‘(iii) Committee on Oversight and Ac-10 |
---|
| 190 | + | countability of the House of Representa-11 |
---|
| 191 | + | tives; and 12 |
---|
| 192 | + | ‘‘(B) describe in the notification with suffi-13 |
---|
| 193 | + | cient detail how the covered agency intends to 14 |
---|
| 194 | + | comply with the minimum requirements estab-15 |
---|
| 195 | + | lished under paragraph (1). 16 |
---|
| 196 | + | ‘‘(6) U |
---|
| 197 | + | SE OF TECHNOLOGY .—In determining 17 |
---|
| 198 | + | whether to establish or continue to operate an exist-18 |
---|
| 199 | + | ing data center, the head of a covered agency shall— 19 |
---|
| 200 | + | ‘‘(A) regularly assess the application port-20 |
---|
| 201 | + | folio of the covered agency and ensure that each 21 |
---|
| 202 | + | at-risk legacy application is updated, replaced, 22 |
---|
| 203 | + | or modernized, as appropriate, to take advan-23 |
---|
| 204 | + | tage of modern technologies; and 24 |
---|
| 205 | + | VerDate Sep 11 2014 23:25 Mar 22, 2023 Jkt 039200 PO 00000 Frm 00007 Fmt 6652 Sfmt 6201 E:\BILLS\S933.IS S933 |
---|
| 206 | + | pbinns on DSKJLVW7X2PROD with $$_JOB 8 |
---|
| 207 | + | •S 933 IS |
---|
| 208 | + | ‘‘(B) prioritize and, to the greatest extent 1 |
---|
| 209 | + | possible, leverage commercial cloud environ-2 |
---|
| 210 | + | ments rather than acquiring, overseeing, or 3 |
---|
| 211 | + | managing custom data center infrastructure. 4 |
---|
| 212 | + | ‘‘(7) P |
---|
| 213 | + | UBLIC WEBSITE.— 5 |
---|
| 214 | + | ‘‘(A) I |
---|
| 215 | + | N GENERAL.—The Administrator 6 |
---|
| 216 | + | shall maintain a public-facing website that in-7 |
---|
| 217 | + | cludes information, data, and explanatory state-8 |
---|
| 218 | + | ments relating to the compliance of covered 9 |
---|
| 219 | + | agencies with the requirements of this section. 10 |
---|
| 220 | + | ‘‘(B) P |
---|
| 221 | + | ROCESSES AND PROCEDURES .—In 11 |
---|
| 222 | + | maintaining the website described in subpara-12 |
---|
| 223 | + | graph (A), the Administrator shall— 13 |
---|
| 224 | + | ‘‘(i) ensure covered agencies regularly, 14 |
---|
| 225 | + | and not less frequently than biannually, 15 |
---|
| 226 | + | update the information, data, and explana-16 |
---|
| 227 | + | tory statements posed on the website, pur-17 |
---|
| 228 | + | suant to guidance issued by the Adminis-18 |
---|
| 229 | + | trator, relating to any new data centers 19 |
---|
| 230 | + | and, as appropriate, each existing data 20 |
---|
| 231 | + | center of the covered agency; and 21 |
---|
| 232 | + | ‘‘(ii) ensure that all information, data, 22 |
---|
| 233 | + | and explanatory statements on the website 23 |
---|
| 234 | + | are maintained as open Government data 24 |
---|
| 235 | + | assets.’’; and 25 |
---|
| 236 | + | VerDate Sep 11 2014 23:25 Mar 22, 2023 Jkt 039200 PO 00000 Frm 00008 Fmt 6652 Sfmt 6201 E:\BILLS\S933.IS S933 |
---|
| 237 | + | pbinns on DSKJLVW7X2PROD with $$_JOB 9 |
---|
| 238 | + | •S 933 IS |
---|
| 239 | + | (3) in subsection (c), by striking paragraph (1) 1 |
---|
| 240 | + | and inserting the following: 2 |
---|
120 | | - | N GENERAL.—Not later than 180 days 3 |
---|
121 | | - | after the date of enactment of the Federal Data 4 |
---|
122 | | - | Center Enhancement Act of 2023, the Administrator 5 |
---|
123 | | - | shall establish minimum requirements for new data 6 |
---|
124 | | - | centers in consultation with the Administrator of 7 |
---|
125 | | - | General Services and the Federal Chief Information 8 |
---|
126 | | - | Officers Council. 9 |
---|
127 | | - | ‘‘(2) C |
---|
128 | | - | ONTENTS.— 10 |
---|
129 | | - | ‘‘(A) I |
---|
130 | | - | N GENERAL.—The minimum re-11 |
---|
131 | | - | quirements established under paragraph (1) 12 |
---|
132 | | - | shall include requirements relating to— 13 |
---|
133 | | - | ‘‘(i) the availability of new data cen-14 |
---|
134 | | - | ters; 15 |
---|
135 | | - | ‘‘(ii) the use of new data centers; 16 |
---|
136 | | - | ‘‘(iii) the use of sustainable energy 17 |
---|
137 | | - | sources; 18 |
---|
138 | | - | ‘‘(iv) uptime percentage; 19 |
---|
139 | | - | ‘‘(v) protections against power fail-20 |
---|
140 | | - | ures, including on-site energy generation 21 |
---|
141 | | - | and access to multiple transmission paths; 22 |
---|
142 | | - | ‘‘(vi) protections against physical in-23 |
---|
143 | | - | trusions and natural disasters; 24 |
---|
144 | | - | VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00005 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933 |
---|
145 | | - | pbinns on DSKJLVW7X2PROD with $$_JOB 6 |
---|
146 | | - | •S 933 RS |
---|
147 | | - | ‘‘(vii) information security protections 1 |
---|
148 | | - | required by subchapter II of chapter 35 of 2 |
---|
149 | | - | title 44, United States Code, and other ap-3 |
---|
150 | | - | plicable law and policy; and 4 |
---|
151 | | - | ‘‘(viii) any other requirements the Ad-5 |
---|
152 | | - | ministrator determines appropriate. 6 |
---|
153 | | - | ‘‘(B) C |
---|
154 | | - | ONSULTATION.—In establishing the 7 |
---|
155 | | - | requirements described in subparagraph 8 |
---|
156 | | - | (A)(vii), the Administrator shall consult with 9 |
---|
157 | | - | the Director of the Cybersecurity and Infra-10 |
---|
158 | | - | structure Security Agency and the National 11 |
---|
159 | | - | Cyber Director. 12 |
---|
160 | | - | ‘‘(3) I |
---|
161 | | - | NCORPORATION OF MINIMUM REQUIRE -13 |
---|
162 | | - | MENTS INTO CURRENT DATA CENTERS .—As soon as 14 |
---|
163 | | - | practicable, and in any case not later than 90 days 15 |
---|
164 | | - | after the Administrator establishes the minimum re-16 |
---|
165 | | - | quirements pursuant to paragraph (1), the Adminis-17 |
---|
166 | | - | trator shall issue guidance to ensure, as appropriate, 18 |
---|
167 | | - | that covered agencies incorporate the minimum re-19 |
---|
168 | | - | quirements established under that paragraph into 20 |
---|
169 | | - | the operations of any data center of a covered agen-21 |
---|
170 | | - | cy existing as of the date of enactment of the Fed-22 |
---|
171 | | - | eral Data Center Enhancement Act of 2023. 23 |
---|
172 | | - | ‘‘(4) R |
---|
173 | | - | EVIEW OF REQUIREMENTS .—The Admin-24 |
---|
174 | | - | istrator, in consultation with the Administrator of 25 |
---|
175 | | - | VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00006 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933 |
---|
176 | | - | pbinns on DSKJLVW7X2PROD with $$_JOB 7 |
---|
177 | | - | •S 933 RS |
---|
178 | | - | General Services and the Federal Chief Information 1 |
---|
179 | | - | Officers Council, shall review, update, and modify 2 |
---|
180 | | - | the minimum requirements established under para-3 |
---|
181 | | - | graph (1), as necessary. 4 |
---|
182 | | - | ‘‘(5) R |
---|
183 | | - | EPORT ON NEW DATA CENTERS .—During 5 |
---|
184 | | - | the development and planning lifecycle of a new data 6 |
---|
185 | | - | center, if the head of a covered agency determines 7 |
---|
186 | | - | that the covered agency is likely to make a manage-8 |
---|
187 | | - | ment or financial decision relating to any data cen-9 |
---|
188 | | - | ter, the head of the covered agency shall— 10 |
---|
189 | | - | ‘‘(A) notify— 11 |
---|
190 | | - | ‘‘(i) the Administrator; 12 |
---|
191 | | - | ‘‘(ii) Committee on Homeland Secu-13 |
---|
192 | | - | rity and Governmental Affairs of the Sen-14 |
---|
193 | | - | ate; and 15 |
---|
194 | | - | ‘‘(iii) Committee on Oversight and Ac-16 |
---|
195 | | - | countability of the House of Representa-17 |
---|
196 | | - | tives; and 18 |
---|
197 | | - | ‘‘(B) describe in the notification with suffi-19 |
---|
198 | | - | cient detail how the covered agency intends to 20 |
---|
199 | | - | comply with the minimum requirements estab-21 |
---|
200 | | - | lished under paragraph (1). 22 |
---|
201 | | - | ‘‘(6) U |
---|
202 | | - | SE OF TECHNOLOGY .—In determining 23 |
---|
203 | | - | whether to establish or continue to operate an exist-24 |
---|
204 | | - | ing data center, the head of a covered agency shall— 25 |
---|
205 | | - | VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00007 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933 |
---|
206 | | - | pbinns on DSKJLVW7X2PROD with $$_JOB 8 |
---|
207 | | - | •S 933 RS |
---|
208 | | - | ‘‘(A) regularly assess the application port-1 |
---|
209 | | - | folio of the covered agency and ensure that each 2 |
---|
210 | | - | at-risk legacy application is updated, replaced, 3 |
---|
211 | | - | or modernized, as appropriate, to take advan-4 |
---|
212 | | - | tage of modern technologies; and 5 |
---|
213 | | - | ‘‘(B) prioritize and, to the greatest extent 6 |
---|
214 | | - | possible, leverage commercial cloud environ-7 |
---|
215 | | - | ments rather than acquiring, overseeing, or 8 |
---|
216 | | - | managing custom data center infrastructure. 9 |
---|
217 | | - | ‘‘(7) P |
---|
218 | | - | UBLIC WEBSITE.— 10 |
---|
219 | | - | ‘‘(A) I |
---|
220 | | - | N GENERAL.—The Administrator 11 |
---|
221 | | - | shall maintain a public-facing website that in-12 |
---|
222 | | - | cludes information, data, and explanatory state-13 |
---|
223 | | - | ments relating to the compliance of covered 14 |
---|
224 | | - | agencies with the requirements of this section. 15 |
---|
225 | | - | ‘‘(B) P |
---|
226 | | - | ROCESSES AND PROCEDURES .—In 16 |
---|
227 | | - | maintaining the website described in subpara-17 |
---|
228 | | - | graph (A), the Administrator shall— 18 |
---|
229 | | - | ‘‘(i) ensure covered agencies regularly, 19 |
---|
230 | | - | and not less frequently than biannually, 20 |
---|
231 | | - | update the information, data, and explana-21 |
---|
232 | | - | tory statements posed on the website, pur-22 |
---|
233 | | - | suant to guidance issued by the Adminis-23 |
---|
234 | | - | trator, relating to any new data centers 24 |
---|
235 | | - | VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00008 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933 |
---|
236 | | - | pbinns on DSKJLVW7X2PROD with $$_JOB 9 |
---|
237 | | - | •S 933 RS |
---|
238 | | - | and, as appropriate, each existing data 1 |
---|
239 | | - | center of the covered agency; and 2 |
---|
240 | | - | ‘‘(ii) ensure that all information, data, 3 |
---|
241 | | - | and explanatory statements on the website 4 |
---|
242 | | - | are maintained as open Government data 5 |
---|
243 | | - | assets.’’; and 6 |
---|
244 | | - | (3) in subsection (c), by striking paragraph (1) 7 |
---|
245 | | - | and inserting the following: 8 |
---|
246 | | - | ‘‘(1) I |
---|
247 | | - | N GENERAL.—The head of a covered 9 |
---|
248 | | - | agency shall oversee and manage the data center 10 |
---|
249 | | - | portfolio and the information technology strategy of 11 |
---|
250 | | - | the covered agency in accordance with Federal cy-12 |
---|
251 | | - | bersecurity guidelines and directives, including— 13 |
---|
252 | | - | ‘‘(A) information security standards and 14 |
---|
253 | | - | guidelines promulgated by the Director of the 15 |
---|
254 | | - | National Institute of Standards and Tech-16 |
---|
255 | | - | nology; 17 |
---|
256 | | - | ‘‘(B) applicable requirements and guidance 18 |
---|
257 | | - | issued by the Director of the Office of Manage-19 |
---|
258 | | - | ment and Budget pursuant to section 3614 of 20 |
---|
259 | | - | title 44, United States Code; and 21 |
---|
260 | | - | ‘‘(C) directives issued by the Secretary of 22 |
---|
261 | | - | Homeland Security under section 3553 of title 23 |
---|
262 | | - | 44, United States Code.’’. 24 |
---|
263 | | - | VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00009 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933 |
---|
| 242 | + | N GENERAL.—The head of a covered 3 |
---|
| 243 | + | agency shall oversee and manage the data center 4 |
---|
| 244 | + | portfolio and the information technology strategy of 5 |
---|
| 245 | + | the covered agency in accordance with Federal cy-6 |
---|
| 246 | + | bersecurity guidelines and directives, including— 7 |
---|
| 247 | + | ‘‘(A) information security standards and 8 |
---|
| 248 | + | guidelines promulgated by the Director of the 9 |
---|
| 249 | + | National Institute of Standards and Tech-10 |
---|
| 250 | + | nology; 11 |
---|
| 251 | + | ‘‘(B) applicable requirements and guidance 12 |
---|
| 252 | + | issued by the Director of the Office of Manage-13 |
---|
| 253 | + | ment and Budget pursuant to section 3614 of 14 |
---|
| 254 | + | title 44, United States Code; and 15 |
---|
| 255 | + | ‘‘(C) directives issued by the Secretary of 16 |
---|
| 256 | + | Homeland Security under section 3553 of title 17 |
---|
| 257 | + | 44, United States Code.’’. 18 |
---|
| 258 | + | (c) E |
---|
| 259 | + | XTENSION OFSUNSET.—Section 834(e) of the 19 |
---|
| 260 | + | Carl Levin and Howard P. ‘‘Buck’’ McKeon National De-20 |
---|
| 261 | + | fense Authorization Act for Fiscal Year 2015 (44 U.S.C. 21 |
---|
| 262 | + | 3601 note; Public Law 113–291) is amended by striking 22 |
---|
| 263 | + | ‘‘2022’’ and inserting ‘‘2026’’. 23 |
---|
| 264 | + | (d) GAO R |
---|
| 265 | + | EVIEW.—Not later than 1 year after the 24 |
---|
| 266 | + | date of the enactment of this Act, and annually thereafter, 25 |
---|
| 267 | + | VerDate Sep 11 2014 23:25 Mar 22, 2023 Jkt 039200 PO 00000 Frm 00009 Fmt 6652 Sfmt 6201 E:\BILLS\S933.IS S933 |
---|
265 | | - | •S 933 RS |
---|
266 | | - | (c) EXTENSION OFSUNSET.—Section 834(e) of the 1 |
---|
267 | | - | Carl Levin and Howard P. ‘‘Buck’’ McKeon National De-2 |
---|
268 | | - | fense Authorization Act for Fiscal Year 2015 (44 U.S.C. 3 |
---|
269 | | - | 3601 note; Public Law 113–291) is amended by striking 4 |
---|
270 | | - | ‘‘2022’’ and inserting ‘‘2026’’. 5 |
---|
271 | | - | (d) GAO R |
---|
272 | | - | EVIEW.—Not later than 1 year after the 6 |
---|
273 | | - | date of the enactment of this Act, and annually thereafter, 7 |
---|
274 | | - | the Comptroller General of the United States shall review, 8 |
---|
275 | | - | verify, and audit the compliance of covered agencies with 9 |
---|
276 | | - | the minimum requirements established pursuant to section 10 |
---|
277 | | - | 834(b)(1) of the Carl Levin and Howard P. ‘‘Buck’’ 11 |
---|
278 | | - | McKeon National Defense Authorization Act for Fiscal 12 |
---|
279 | | - | Year 2015 (44 U.S.C. 3601 note; Public Law 113–291) 13 |
---|
280 | | - | for new data centers and subsection (b)(3) of that Act for 14 |
---|
281 | | - | existing data centers, as appropriate. 15 |
---|
282 | | - | VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00010 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933 |
---|
283 | | - | pbinns on DSKJLVW7X2PROD with $$_JOB VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00011 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933 |
---|
284 | | - | pbinns on DSKJLVW7X2PROD with $$_JOB Calendar No. |
---|
285 | | - | 39 |
---|
286 | | - | 118 |
---|
287 | | - | TH |
---|
288 | | - | CONGRESS |
---|
289 | | - | 1 |
---|
290 | | - | ST |
---|
291 | | - | S |
---|
292 | | - | ESSION |
---|
293 | | - | |
---|
294 | | - | S. 933 |
---|
295 | | - | [Report No. 118–15] |
---|
296 | | - | A BILL |
---|
297 | | - | To amend the Carl Levin and Howard P. ‘‘Buck’’ |
---|
298 | | - | McKeon National Defense Authorization Act for |
---|
299 | | - | Fiscal Year 2015 to modify requirements relating |
---|
300 | | - | to data centers of certain Federal agencies, and |
---|
301 | | - | for other purposes. |
---|
302 | | - | A |
---|
303 | | - | PRIL |
---|
304 | | - | 27, 2023 |
---|
305 | | - | Reported without amendment |
---|
306 | | - | VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00012 Fmt 6651 Sfmt 6651 E:\BILLS\S933.RS S933 |
---|
| 269 | + | •S 933 IS |
---|
| 270 | + | the Comptroller General of the United States shall review, 1 |
---|
| 271 | + | verify, and audit the compliance of covered agencies with 2 |
---|
| 272 | + | the minimum requirements established pursuant to section 3 |
---|
| 273 | + | 834(b)(1) of the Carl Levin and Howard P. ‘‘Buck’’ 4 |
---|
| 274 | + | McKeon National Defense Authorization Act for Fiscal 5 |
---|
| 275 | + | Year 2015 (44 U.S.C. 3601 note; Public Law 113–291) 6 |
---|
| 276 | + | for new data centers and subsection (b)(3) of that Act for 7 |
---|
| 277 | + | existing data centers, as appropriate. 8 |
---|
| 278 | + | Æ |
---|
| 279 | + | VerDate Sep 11 2014 23:25 Mar 22, 2023 Jkt 039200 PO 00000 Frm 00010 Fmt 6652 Sfmt 6301 E:\BILLS\S933.IS S933 |
---|