Federal Secure Cloud Improvement and Jobs Act of 2021

3/8/2023, 8:12 PM

Federal Secure Cloud Improvement and Jobs Act of 2021

This bill provides statutory authority for the Federal Risk and Authorization Management Program (FedRAMP) within the General Services Administration (GSA).

FedRAMP is a government-wide program that provides a standardized, reusable approach to security assessment and authorization for cloud computing products and services that process unclassified information used by agencies.

The bill establishes a FedRAMP Board to provide input and recommendations to the GSA regarding the requirements and guidelines for, and the prioritization of, security assessments of cloud computing products and services.

The GSA may determine whether FedRAMP may use an independent assessment service to analyze, validate, and attest to the quality and compliance of security assessment materials that pertain to cloud computing products and services. An independent assessment service that performs such work must annually report to GSA about any foreign interest in, influence of, or control of its service.

The Government Accountability Office must publish a report that, among other requirements, includes an assessment of the costs incurred by agencies and cloud service providers related to the issuance of FedRAMP authorizations.

The bill establishes the Federal Secure Cloud Advisory Committee.

Congress
117

Number
S - 3099

Introduced on
2021-10-28

# Amendments
0

Sponsors
+5

Cosponsors
+5

Variations and Revisions

5/24/2022

Status of Legislation

Bill Introduced
Introduced to House
House to Vote
Introduced to Senate
Senate to Vote

Purpose and Summary

Federal Secure Cloud Improvement and Jobs Act of 2021

This bill provides statutory authority for the Federal Risk and Authorization Management Program (FedRAMP) within the General Services Administration (GSA).

FedRAMP is a government-wide program that provides a standardized, reusable approach to security assessment and authorization for cloud computing products and services that process unclassified information used by agencies.

The bill establishes a FedRAMP Board to provide input and recommendations to the GSA regarding the requirements and guidelines for, and the prioritization of, security assessments of cloud computing products and services.

The GSA may determine whether FedRAMP may use an independent assessment service to analyze, validate, and attest to the quality and compliance of security assessment materials that pertain to cloud computing products and services. An independent assessment service that performs such work must annually report to GSA about any foreign interest in, influence of, or control of its service.

The Government Accountability Office must publish a report that, among other requirements, includes an assessment of the costs incurred by agencies and cloud service providers related to the issuance of FedRAMP authorizations.

The bill establishes the Federal Secure Cloud Advisory Committee.

Alternative Names
Official Title as IntroducedA bill to amend title 44, United States Code, to establish the Federal Risk and Authorization Management Program within the General Services Administration, and for other purposes.

Policy Areas
Government Operations and Politics

Potential Impact
Advisory bodies
Computer security and identity theft
Computers and information technology
Congressional oversight
Executive agency funding and structure
Government information and archives
Government studies and investigations
Performance measurement
Public contracts and procurement
Technology assessment

Comments

Recent Activity

Latest Summary8/27/2022

Federal Secure Cloud Improvement and Jobs Act of 2021

This bill provides statutory authority for the Federal Risk and Authorization Management Program (FedRAMP) within the General Services Administration (GSA).

...

Latest Action5/24/2022
Placed on Senate Legislative Calendar under General Orders. Calendar No. 383.