Federal Data Center Enhancement Act of 2022
A BILL
To amend the Carl Levin and Howard P. Buck McKeon National Defense Authorization Act for Fiscal Year 2015 to modify requirements relating to data centers of certain Federal agencies, and for other purposes.
2. Federal Data Center Consolidation Initiative Amendments
“(3) New data center—The term new data center means a—
“(A)
“(i) a data center or a portion thereof that is owned, operated, or maintained by a covered agency; or
“(ii) to the extent practicable, a data center or portion thereof—
“(I) that is owned, operated, or maintained by a contractor on behalf of a covered agency on the date on which the contract between the covered agency and the contractor expires; and
“(II) with respect to which the covered agency extends the contract, or enters into a new contract, with the contractor; and
“(B) on or after the date that is 180 days after the date of enactment of the Federal Data Center Enhancement Act of 2022, a data center or portion thereof that is—
“(i) established; or
“(ii) substantially upgraded or expanded.”
“(b) Minimum requirements for new data centers
“(1) In general—Not later than 180 days after the date of enactment of the Federal Data Center Enhancement Act of 2022, the Administrator shall establish minimum requirements for new data centers in consultation with the Administrator of General Services and the Federal Chief Information Officers Council.
“(2) Contents
“(A) In general—The minimum requirements established under paragraph (1) shall include requirements relating to—
“(i) the availability of new data centers;
“(ii) the use of new data centers;
“(iii) the use of sustainable energy sources;
“(iv) uptime percentage;
“(v) protections against power failures, including on-site energy generation and access to multiple transmission paths;
“(vi) protections against physical intrusions and natural disasters;
“(vii) information security protections required by subchapter II of chapter 35 of title 44, United States Code, and other applicable law and policy; and
“(viii) any other requirements the Administrator determines appropriate.
“(B) Consultation—In establishing the requirements described in subparagraph (A)(vii), the Administrator shall consult with the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director.
“(3) Use of existing standards—The Administrator may incorporate the minimum requirements established under paragraph (1) into the appropriate requirements of any agency data center existing as of the date of enactment of the Federal Data Center Enhancement Act of 2022.
“(4) Review of standards—The Administrator, in consultation with the Administrator of General Services and the Federal Chief Information Officers Council, shall review, update, and modify the minimum requirements established under paragraph (1), as necessary.
“(5) Report on new data centers—During the development and planning lifecycle of a new data center, if the head of a covered agency determines that the covered agency is likely to make a management or financial decision relating to the new data center, the head of the covered agency shall—
“(A) notify—
“(i) the Administrator;
“(ii) Committee on Homeland Security and Governmental Affairs of the Senate; and
“(iii) Committee on Oversight and Reform of the House of Representatives; and
“(B) describe in the notification with sufficient detail how the covered agency intends to comply with the minimum requirements established under paragraph (1).
“(6) Use of technology—In determining whether to establish or continue to operate a data center, the head of a covered agency shall—
“(A) regularly assess the application portfolio of the covered agency and ensure that each legacy application is updated, replaced, or modernized, as appropriate, to take advantage of modern technologies; and
“(B) prioritize and, to the greatest extent possible, leverage commercial cloud environments rather than acquiring, overseeing, or managing custom data center infrastructure.”
“(1) In general—The head of a covered agency shall oversee and manage the data center portfolio and the information technology strategy of the covered agency in accordance with Federal cybersecurity guidelines and directives, including—
“(A) information security standards and guidelines promulgated by the Director of the National Institute of Standards and Technology;
“(B) applicable provisions found within the Federal Risk and Authorization Management Program; and
“(C) directives issued by the Secretary of Homeland Security under section 3553 of title 44, United States Code.”