Pub. L. 118-159, div. A, tit. XV, subtit. C, sec. 1522
MODERNIZATION OF THE DEPARTMENT OF DEFENSE’S AUTHORIZATION TO OPERATE PROCESSES.
SEC. 1522. 10 USC 2223 note.MODERNIZATION OF THE DEPARTMENT OF DEFENSE’S AUTHORIZATION TO OPERATE PROCESSES.(a) Active Directory of Authorizing Officials.—(1) Deadline.Update.In general.—Not later than 270 days after the date of the enactment of this Act, the Secretary of Defense, acting through the Chief Information Officer of the Department of Defense and in coordination with the Chief Information Officers of the military departments, shall establish and regularly update a digital directory of all authorizing officials in the military departments. (2) Contents.—The directory established under paragraph (1) shall include—(A) the most current contact information for such authorizing official; and (B) List.a list of each training required to perform the duties and responsibilities of an authorizing official completed by such authorizing official. (b) Presumption of Reciprocal Software Accrediting Standards.—(1) Policy required.Deadline.—Not later than 180 days after the date of the enactment of this Act, the Secretary of Defense, acting through the Chief Information Officer of the Department of Defense, shall implement a policy that requires authorizing officials to adopt the security analysis and artifacts, as appropriate, of a cloud-hosted platform, service, or application that has already been authorized by another authorizing official in the Department of Defense in order to more rapidly adopt and use such cloud-hosted platforms, services, and applications, at the corresponding classification level and in accordance with 138 STAT. 2146 the existing authorization conditions, without additional authorizations or reviews. (2) Elements.—The Secretary shall ensure that the policy implemented under paragraph (1)—(A) ensures the development of standardized and transparent documentation of the security, accreditation, performance, and operational capabilities of cloud-hosted platforms, services, and applications to enable decision making by mission owners of such cloud-hosted platforms, services, and applications; (B) provides for an intuitive and digital workflow to document acknowledgments among mission owners and system owners of use of the operational capabilities of cloud-hosted platforms, services, and applications; (C) Review.directs a review by mission owners of existing authorization information, at the appropriate classification level, regarding the status of the operational capabilities of cloud-hosted platforms, services, and applications, including through management dashboards or other management analytic capabilities; and (D) defines a process, including required timelines, to allow authorizing officials that disagree with the security analysis of a cloud-hosted platform, service, or application that such official would be required to adopt under such policy to present such disagreement to the Chief Information Officer of the Department of Defense, or such other individual or entity designated by the Chief Information Officer, for adjudication. (3) Applicability.—The policy implemented pursuant to subsection (a) shall apply to—(A) all authorizing officials in the Department of Defense, including in each military department, component, and agency of the Department; and (B) all operational capabilities of cloud-hosted platforms, services, and applications, including capabilities on public cloud infrastructure, as authorized through the Federal Risk and Authorization Management Program established under section 3608 of title 44, United States Code, and the Defense Information Systems Agency, and capabilities on private cloud landing zones managed by the Department of Defense that are authorized by Department accrediting officials. (c) Report.—Not later than 120 days after the date of the enactment of this Act, the Secretary shall submit to the congressional defense committees a report on the status of the implementation of subsections (a) and (b). (d) Definitions.—In this section—(1) the term “Authorization to Operate” has the meaning given such term in the Office of Management and Budget Circular A-130; (2) the term “authorizing official” means an officer who is authorized to assume responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the United States;138 STAT. 2147 (3) the term “military departments” has the meaning given such term in section 101(a) of title 10, United States Code; (4) the term “mission owner” means the user of a cloud-based platform, service, or application; and (5) the term “system owner” means the element of the Department of Defense responsible for acquiring a cloud-based platform, service, or application, but which is not a mission owner of such cloud-based platform, service, or application.