Us Congress 2023-2024 Regular Session

Us Congress Senate Bill SB933 Latest Draft

Bill / Introduced Version Filed 04/28/2023

                            II 
Calendar No. 39 
118THCONGRESS 
1
STSESSION S. 933 
[Report No. 118–15] 
To amend the Carl Levin and Howard P. ‘‘Buck’’ McKeon National Defense 
Authorization Act for Fiscal Year 2015 to modify requirements relating 
to data centers of certain Federal agencies, and for other purposes. 
IN THE SENATE OF THE UNITED STATES 
MARCH22, 2023 
Ms. R
OSEN(for herself, Mr. CORNYN, and Mr. PETERS) introduced the fol-
lowing bill; which was read twice and referred to the Committee on 
Homeland Security and Governmental Affairs 
A
PRIL27, 2023 
Reported by Mr. P
ETERS, without amendment 
A BILL 
To amend the Carl Levin and Howard P. ‘‘Buck’’ McKeon 
National Defense Authorization Act for Fiscal Year 2015 
to modify requirements relating to data centers of certain 
Federal agencies, and for other purposes. 
Be it enacted by the Senate and House of Representa-1
tives of the United States of America in Congress assembled, 2
VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00001 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB 2 
•S 933 RS
SECTION 1. SHORT TITLE. 1
This Act may be cited as the ‘‘Federal Data Center 2
Enhancement Act of 2023’’. 3
SEC. 2. FEDERAL DATA CENTER CONSOLIDATION INITIA-4
TIVE AMENDMENTS. 5
(a) F
INDINGS.—Congress finds the following: 6
(1) The statutory authorization for the Federal 7
Data Center Optimization Initiative under section 8
834 of the Carl Levin and Howard P. ‘‘Buck’’ 9
McKeon National Defense Authorization Act for 10
Fiscal Year 2015 (44 U.S.C. 3601 note; Public Law 11
113–291) expires at the end of fiscal year 2022. 12
(2) The expiration of the authorization de-13
scribed in paragraph (1) presents Congress with an 14
opportunity to review the objectives of the Federal 15
Data Center Optimization Initiative to ensure that 16
the initiative is meeting the current needs of the 17
Federal Government. 18
(3) The initial focus of the Federal Data Center 19
Optimization Initiative, which was to consolidate 20
data centers and create new efficiencies, has resulted 21
in, since 2010— 22
(A) the consolidation of more than 6,000 23
Federal data centers; and 24
(B) cost savings and avoidance of 25
$5,800,000,000. 26
VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00002 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB 3 
•S 933 RS
(4) The need of the Federal Government for ac-1
cess to data and data processing systems has evolved 2
since the date of enactment in 2014 of subtitle D of 3
title VIII of the Carl Levin and Howard P. ‘‘Buck’’ 4
McKeon National Defense Authorization Act for 5
Fiscal Year 2015. 6
(5) Federal agencies and employees involved in 7
mission critical functions increasingly need reliable 8
access to secure, reliable, sustainable, and protected 9
facilities to house mission critical data and data op-10
erations to meet the immediate needs of the people 11
of the United States. 12
(6) As of the date of enactment of this Act, 13
there is a growing need for Federal agencies to use 14
data centers and cloud applications that meet high 15
standards for cybersecurity, resiliency, availability, 16
and sustainability. 17
(b) M
INIMUMREQUIREMENTS FOR NEWDATACEN-18
TERS.—Section 834 of the Carl Levin and Howard P. 19
‘‘Buck’’ McKeon National Defense Authorization Act for 20
Fiscal Year 2015 (44 U.S.C. 3601 note; Public Law 113– 21
291) is amended— 22
(1) in subsection (a), by striking paragraphs 23
(3) and (4) and inserting the following: 24
VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00003 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB 4 
•S 933 RS
‘‘(3) NEW DATA CENTER.—The term ‘new data 1
center’ means— 2
‘‘(A)(i) a data center or a portion thereof 3
that is owned, operated, or maintained by a 4
covered agency; or 5
‘‘(ii) to the extent practicable, a data cen-6
ter or portion thereof— 7
‘‘(I) that is owned, operated, or main-8
tained by a contractor on behalf of a cov-9
ered agency on the date on which the con-10
tract between the covered agency and the 11
contractor expires; and 12
‘‘(II) with respect to which the cov-13
ered agency extends the contract, or enters 14
into a new contract, with the contractor; 15
and 16
‘‘(B) on or after the date that is 180 days 17
after the date of enactment of the Federal Data 18
Center Enhancement Act of 2023, a data cen-19
ter or portion thereof that is— 20
‘‘(i) established; or 21
‘‘(ii) substantially upgraded or ex-22
panded.’’; 23
(2) by striking subsection (b) and inserting the 24
following: 25
VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00004 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB 5 
•S 933 RS
‘‘(b) MINIMUMREQUIREMENTS FOR NEWDATA 1
C
ENTERS.— 2
‘‘(1) I
N GENERAL.—Not later than 180 days 3
after the date of enactment of the Federal Data 4
Center Enhancement Act of 2023, the Administrator 5
shall establish minimum requirements for new data 6
centers in consultation with the Administrator of 7
General Services and the Federal Chief Information 8
Officers Council. 9
‘‘(2) C
ONTENTS.— 10
‘‘(A) I
N GENERAL.—The minimum re-11
quirements established under paragraph (1) 12
shall include requirements relating to— 13
‘‘(i) the availability of new data cen-14
ters; 15
‘‘(ii) the use of new data centers; 16
‘‘(iii) the use of sustainable energy 17
sources; 18
‘‘(iv) uptime percentage; 19
‘‘(v) protections against power fail-20
ures, including on-site energy generation 21
and access to multiple transmission paths; 22
‘‘(vi) protections against physical in-23
trusions and natural disasters; 24
VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00005 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB 6 
•S 933 RS
‘‘(vii) information security protections 1
required by subchapter II of chapter 35 of 2
title 44, United States Code, and other ap-3
plicable law and policy; and 4
‘‘(viii) any other requirements the Ad-5
ministrator determines appropriate. 6
‘‘(B) C
ONSULTATION.—In establishing the 7
requirements described in subparagraph 8
(A)(vii), the Administrator shall consult with 9
the Director of the Cybersecurity and Infra-10
structure Security Agency and the National 11
Cyber Director. 12
‘‘(3) I
NCORPORATION OF MINIMUM REQUIRE -13
MENTS INTO CURRENT DATA CENTERS .—As soon as 14
practicable, and in any case not later than 90 days 15
after the Administrator establishes the minimum re-16
quirements pursuant to paragraph (1), the Adminis-17
trator shall issue guidance to ensure, as appropriate, 18
that covered agencies incorporate the minimum re-19
quirements established under that paragraph into 20
the operations of any data center of a covered agen-21
cy existing as of the date of enactment of the Fed-22
eral Data Center Enhancement Act of 2023. 23
‘‘(4) R
EVIEW OF REQUIREMENTS .—The Admin-24
istrator, in consultation with the Administrator of 25
VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00006 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB 7 
•S 933 RS
General Services and the Federal Chief Information 1
Officers Council, shall review, update, and modify 2
the minimum requirements established under para-3
graph (1), as necessary. 4
‘‘(5) R
EPORT ON NEW DATA CENTERS .—During 5
the development and planning lifecycle of a new data 6
center, if the head of a covered agency determines 7
that the covered agency is likely to make a manage-8
ment or financial decision relating to any data cen-9
ter, the head of the covered agency shall— 10
‘‘(A) notify— 11
‘‘(i) the Administrator; 12
‘‘(ii) Committee on Homeland Secu-13
rity and Governmental Affairs of the Sen-14
ate; and 15
‘‘(iii) Committee on Oversight and Ac-16
countability of the House of Representa-17
tives; and 18
‘‘(B) describe in the notification with suffi-19
cient detail how the covered agency intends to 20
comply with the minimum requirements estab-21
lished under paragraph (1). 22
‘‘(6) U
SE OF TECHNOLOGY .—In determining 23
whether to establish or continue to operate an exist-24
ing data center, the head of a covered agency shall— 25
VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00007 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB 8 
•S 933 RS
‘‘(A) regularly assess the application port-1
folio of the covered agency and ensure that each 2
at-risk legacy application is updated, replaced, 3
or modernized, as appropriate, to take advan-4
tage of modern technologies; and 5
‘‘(B) prioritize and, to the greatest extent 6
possible, leverage commercial cloud environ-7
ments rather than acquiring, overseeing, or 8
managing custom data center infrastructure. 9
‘‘(7) P
UBLIC WEBSITE.— 10
‘‘(A) I
N GENERAL.—The Administrator 11
shall maintain a public-facing website that in-12
cludes information, data, and explanatory state-13
ments relating to the compliance of covered 14
agencies with the requirements of this section. 15
‘‘(B) P
ROCESSES AND PROCEDURES .—In 16
maintaining the website described in subpara-17
graph (A), the Administrator shall— 18
‘‘(i) ensure covered agencies regularly, 19
and not less frequently than biannually, 20
update the information, data, and explana-21
tory statements posed on the website, pur-22
suant to guidance issued by the Adminis-23
trator, relating to any new data centers 24
VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00008 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB 9 
•S 933 RS
and, as appropriate, each existing data 1
center of the covered agency; and 2
‘‘(ii) ensure that all information, data, 3
and explanatory statements on the website 4
are maintained as open Government data 5
assets.’’; and 6
(3) in subsection (c), by striking paragraph (1) 7
and inserting the following: 8
‘‘(1) I
N GENERAL.—The head of a covered 9
agency shall oversee and manage the data center 10
portfolio and the information technology strategy of 11
the covered agency in accordance with Federal cy-12
bersecurity guidelines and directives, including— 13
‘‘(A) information security standards and 14
guidelines promulgated by the Director of the 15
National Institute of Standards and Tech-16
nology; 17
‘‘(B) applicable requirements and guidance 18
issued by the Director of the Office of Manage-19
ment and Budget pursuant to section 3614 of 20
title 44, United States Code; and 21
‘‘(C) directives issued by the Secretary of 22
Homeland Security under section 3553 of title 23
44, United States Code.’’. 24
VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00009 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB 10 
•S 933 RS
(c) EXTENSION OFSUNSET.—Section 834(e) of the 1
Carl Levin and Howard P. ‘‘Buck’’ McKeon National De-2
fense Authorization Act for Fiscal Year 2015 (44 U.S.C. 3
3601 note; Public Law 113–291) is amended by striking 4
‘‘2022’’ and inserting ‘‘2026’’. 5
(d) GAO R
EVIEW.—Not later than 1 year after the 6
date of the enactment of this Act, and annually thereafter, 7
the Comptroller General of the United States shall review, 8
verify, and audit the compliance of covered agencies with 9
the minimum requirements established pursuant to section 10
834(b)(1) of the Carl Levin and Howard P. ‘‘Buck’’ 11
McKeon National Defense Authorization Act for Fiscal 12
Year 2015 (44 U.S.C. 3601 note; Public Law 113–291) 13
for new data centers and subsection (b)(3) of that Act for 14
existing data centers, as appropriate. 15
VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00010 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00011 Fmt 6652 Sfmt 6201 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB Calendar No. 
39 
118
TH
CONGRESS 
1
ST
S
ESSION
 
S. 933 
[Report No. 118–15] 
A BILL 
To amend the Carl Levin and Howard P. ‘‘Buck’’ 
McKeon National Defense Authorization Act for 
Fiscal Year 2015 to modify requirements relating 
to data centers of certain Federal agencies, and 
for other purposes. 
A
PRIL
27, 2023 
Reported without amendment 
VerDate Sep 11 2014 21:39 Apr 27, 2023 Jkt 039200 PO 00000 Frm 00012 Fmt 6651 Sfmt 6651 E:\BILLS\S933.RS S933
pbinns on DSKJLVW7X2PROD with $$_JOB