Federal Cloud Risk Management Improvements Act
A BILL
To amend chapter 36 of title 44, United States Code, to require reporting regarding the security of cloud computing products and services.
Sec. 2 Reporting regarding security of cloud computing products and services
“3607. Reporting regarding security of cloud computing products and services
“(a) Definitions—In this section:
“(1) Agency—The term agency has the meaning given the term in section 3502.
“(2) Cloud computing—The term cloud computing has the meaning given the term in Special Publication 800–145 of the National Institute of Standards and Technology, or any successor document.
“(3) Cloud service provider—The term cloud service provider means an entity offering cloud computing products or services to agencies.
“(b) Reporting—Not later than 1 year after the date of enactment of this section, and annually thereafter, the Administrator of General Services shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives a report that includes a review of measures taken under the Federal Risk and Authorization Management Program, or any successor thereto, to ensure the security of data stored or processed by cloud service providers, which may include—
“(1) geolocation restrictions for provided products or services;
“(2) disclosures of foreign elements of supply chains of acquired products or services;
“(3) regular disclosures of ownership of cloud service providers by foreign entities; and
“(4) encryption requirements for data processed, stored, or transmitted by cloud service providers.”