(1)
Authorization to operate— The term “authorization to operate” means an approval and accreditation, including a provisional authorization to operate, regarding the security and operational qualifications of a cloud computing service provider to offer secure, reliable cloud computing service to a covered agency, that may be issued by the Joint Authorization Board, any successor entity, or the head of a covered agency.
(2)
Cloud computing— The term “cloud computing” has the meaning given that term by the National Institute of Standards and Technology in NIST Special Publication 800–145 and any amendatory or superseding document thereto.
(3)
Cloud service provider— The term “cloud service provider” means an entity offering cloud computing infrastructure, platforms, or software for commercial and Government entities.
(4)
Covered agency— The term “covered agency” means each agency listed in section 901(b) of title 31, United States Code.
(5)
Director— The term “Director” means the Director of the Office of Management and Budget.
(6)
Federal risk and authorization management program office— The term “Federal Risk and Authorization Management Program Office” or “Program Management Office” means the Federal Risk and Authorization Management Program Office, or any successor thereto.
(7)
Information system— The term “information system” has the meaning given that term under section 3502 of title 44, United States Code.
(8)
Information technology— The term “information technology” has the meaning given that term under section 11101 of title 40, United States Code.
(9)
Legacy information technology system— The term “legacy information technology system” means an outdated or obsolete information technology that is no longer supported by the originating vendor or manufacturer.
(10)
National security system— The term “national security system” has the meaning given that term under section 3552 of title 44, United States Code.
(11)
Third party assessment organization— The term “third party assessment organization” means a third party accreditation body that conducts a conformity assessment of a cloud service data provider to ensure the provider meets security and operational guidelines issued by the Federal Risk and Authorization Management Program Office.