S.Amdt. 3715Senate119th Congress (2025-2027)
S.Amdt. 3715
Sponsored by
Sen. Tom Cotton (R-AR)
Submitted September 2, 2025
Legislative Activity
Stay on top of the latest movement without scrolling through every action
Floor
Latest Action
Senate amendment submitted
September 2, 2025
Text
Submitted
SA 3715. Mr. COTTON submitted an amendment intended to be proposed by him to the bill S. 2296, to authorize appropriations for fiscal year 2026 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes; which was ordered to lie on the table; as follows: At the appropriate place in title XVI, insert the following: SEC. 16__. PROHIBITION ON ACCESS TO DEPARTMENT OF DEFENSE CLOUD-BASED RESOURCES BY INDIVIDUALS WHO ARE NOT CITIZENS OF THE UNITED STATES OR ALLIED COUNTRIES. (a) Maintenance, Administration, Operation, and Access.-- (1) In general.--An individual not described in paragraph (2) may not maintain, administer, operate, use, receive information about, or directly access or indirectly access, irrespective of whether the individual is supervised by a citizen of the United States, any Department of Defense cloud computing system or cloud-based software, Department data, or Department-related data. (2) Individual described.--An individual is described in this paragraph if the individual-- (A) has the requisite security clearance or authorization required to access the applicable system, software, or data; and (B)(i) is person described in paragraph (1) or (2) of section 504(b) of title 10, United States Code; or (ii) is a citizen of a member country of the Five Eyes intelligence-sharing alliance or of a country that is an ally or partner of the United States that has a similar agreement in effect. (3) Safeguards.--The Secretary of Defense shall establish regulations to carry out this subsection, including safeguards to ensure that only individuals described in paragraph (2) maintain, administer, operate, access, and use the systems, software, and data described in paragraph (1). (b) Department of Defense Guidance, Directives, Procedures, Requirements, and Regulations.--The Secretary shall-- (1) review all relevant guidance, directives, procedures, requirements, and regulations of the Department of Defense, including the Cloud Computing Security Requirements Guide, the Security Technical Implementation Guides, and related Department instructions; and (2) make such revisions as may be necessary to ensure conformity and compliance with subsection (a). (c) Review and Report.--The Secretary shall-- (1) conduct a review of all cloud computing contracts in effect for the Department-- (A) for any violations of section 252.225-7058 of the Defense Federal Acquisition Regulation Supplement and recommended penalties; and (B) to determine-- (i) which contracts have allowed individuals not described in paragraph (2) to maintain, administer, operate, or directly access or indirectly access, whether supervised or unsupervised by a United States citizen, any Government cloud computing system or cloud-based software, Government data, or Government-related data; and [[Page S5647]] (ii) how many of the individuals described in clause (i) are citizens of foreign countries of concern; and (2) submit to the Committee on Armed Services of the Senate and the Committee on Armed Services of the House of Representatives a report on the findings of the Secretary with respect to the review conducted pursuant to paragraph (1). (d) Definitions.--ln this section: (1) The term ``cloud computing'' has the meaning given such term in section 239.7601 of the Defense Federal Acquisition Regulation Supplement, or successor regulation. (2) The term ``cloud-based software'' means a software application, platform, or computational service that is-- (A) delivered to end users via internet-based cloud computing infrastructure; (B) hosted, operated, maintained, and controlled by a third-party service provider; and (C) accessed remotely by users without requiring local installation or deployment of the software on user devices or Department-controlled systems. (3) The terms ``Department data'' and ``Department-related data'' have the meanings given the terms ``Government data'' and ``Government-related data'', respectively, in section 239.7601 of the Defense Federal Acquisition Regulation Supplement, or successor regulation, except in this section, such terms apply only to the Department of Defense. (4) The term ``directly access'', with respect to a system, software, or data, means-- (A) to physically access the system, software, or data; or (B) to logically access the system, software, or data, through proxy, virtual, administrative, or programmatic means such that an individual can modify, alter, control, administer, configure, or deploy the system, software, or data. (5) The term ``Five Eyes intelligence-sharing alliance'' includes the following: (A) The Commonwealth of Australia. (B) Canada. (C) New Zealand. (D) The United Kingdom of Great Britain and Northern Ireland. (E) The United States of America. (6) The term ``foreign country of concern'' has the meaning given that term in section 9901 of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (15 U.S.C. 4651). (7) The term ``indirectly access'', with respect to a system, software, or data, means to obtain, receive, collect, or derive information from the system, software, or data regarding technical details, operational characteristics, or security-related attributes, including-- (A) system configurations; (B) network architecture; (C) security controls; (D) data schemas; (E) performance metrics; and (F) access logs or other information that could compromise the confidentiality, integrity, or availability of the system, software, or data. ______