Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · U.S. Code · Title 44 - PUBLIC PRINTING AND DOCUMENTS · CHAPTER 36— MANAGEMENT AND PROMOTION OF ELECTRONIC GOVERNMENT SERVICES · § 3613

§ 3613. Roles and responsibilities of agencies

570 words·~3 min read·/usc/title-44/section-3613

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

(a)In General.— In implementing the requirements of FedRAMP, the head of each agency shall, consistent with guidance issued by the Director pursuant to section 3614—
(1)promote the use of cloud computing products and services that meet FedRAMP security requirements and other risk-based performance requirements as determined by the Director, in consultation with the Secretary;
(2)confirm whether there is a FedRAMP authorization in the secure mechanism provided under section 3609(a)(8) before beginning the process of granting a FedRAMP authorization for a cloud computing product or service;
(3)to the extent practicable, for any cloud computing product or service the agency seeks to authorize that has received a FedRAMP authorization, use the existing assessments of security controls and materials within any FedRAMP authorization package for that cloud computing product or service; and
(4)provide to the Director data and information required by the Director pursuant to section 3614 to determine how agencies are meeting metrics established by the Administrator.
(b)Attestation.— Upon completing an assessment or authorization activity with respect to a particular cloud computing product or service, if an agency determines that the information and data the agency has reviewed under paragraph
(2)or
(3)of subsection
(a)is wholly or substantially deficient for the purposes of performing an authorization of the cloud computing product or service, the head of the agency shall document as part of the resulting FedRAMP authorization package the reasons for this determination.
(c)Submission of Authorizations to Operate Required.— Upon issuance of an agency authorization to operate based on a FedRAMP authorization, the head of the agency shall provide a copy of its authorization to operate letter and any supplementary information required pursuant to section 3609(a) to the Administrator.
(d)Submission of Policies Required.— Not later than 180 days after the date on which the Director issues guidance in accordance with section 3614(1), the head of each agency, acting through the chief information officer of the agency, shall submit to the Director all agency policies relating to the authorization of cloud computing products and services.
(e)Presumption of Adequacy.—
(1)In general.— The assessment of security controls and materials within the authorization package for a FedRAMP authorization shall be presumed adequate for use in an agency authorization to operate cloud computing products and services.
(2)Information security requirements.— The presumption under paragraph
(1)does not modify or alter—
(A)the responsibility of any agency to ensure compliance with subchapter II of chapter 35 for any cloud computing product or service used by the agency; or
(B)the authority of the head of any agency to make a determination that there is a demonstrable need for additional security requirements beyond the security requirements included in a FedRAMP authorization for a particular control implementation.
(Added Pub. L. 117–263, div. E, title LIX, § 5921(b), Dec. 23, 2022, 136 Stat. 3453.)
Repeal of Section
For repeal of section by section 5921(d)(1) of Pub. L. 117–263, see Effective Date of Repeal note below.
Connections3 cite this · traces to 2
2 references not yet in our index
  • 136 Stat. 3453
  • 136 Stat. 3458
Citation graph
cites case law
§ 3613
Roles and responsibilities of agencies
Pub. L.×1
Stat. Comp.×1
Stat.×1
Stat.136 Stat. 3453
Stat.136 Stat. 3458
Cites 4Cited by 3 across 3 sources
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.