<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>S. 2102</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20120213">February 13, 2012</action-date>
			<action-desc><sponsor name-id="S221">Mrs. Feinstein</sponsor> (for
			 herself and <cosponsor name-id="S182">Ms. Mikulski</cosponsor>) introduced the
			 following bill; which was read twice and referred to the
			 <committee-name committee-id="SSGA00">Committee on Homeland Security and
			 Governmental Affairs</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To provide the authority to monitor and defend against
		  cyber threats, to improve the sharing of cybersecurity information, and for
		  other purposes.</official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short
			 title</header><text display-inline="no-display-inline">This Act may be cited as
			 the <quote><short-title>Cybersecurity Information Sharing
			 Act of 2012</short-title></quote>.</text>
		</section><section id="IDd5342ddffbab4db290fb7f2015dde10e"><enum>2.</enum><header>Affirmative
			 authority to monitor and defend against cybersecurity threats</header><text display-inline="no-display-inline">Notwithstanding chapter 119, 121, or 206 of
			 title 18, United States Code, the Foreign Intelligence Surveillance Act of 1978
			 (50 U.S.C. 1801 et seq.), and the Communications Act of 1934 (47 U.S.C. 151 et
			 seq.), any private entity may—</text>
			<paragraph id="id0d4f7a153bf14f7eac1a06c5c718bd9c"><enum>(1)</enum><text>monitor its
			 information systems and information that is stored on, processed by, or
			 transiting such information systems for cybersecurity threats;</text>
			</paragraph><paragraph id="id935cae35762744dfbedb7426dda4f1e5"><enum>(2)</enum><text>monitor a third
			 party’s information systems and information that is stored on, processed by, or
			 transiting such information systems for cybersecurity threats, if the third
			 party lawfully authorizes such monitoring;</text>
			</paragraph><paragraph id="id4c4737371c284ed2821b19d7fa75accc"><enum>(3)</enum><text>operate
			 countermeasures on its information systems to protect its information systems
			 and information that is stored on, processed by, or transiting such information
			 systems; and</text>
			</paragraph><paragraph id="id144104d0fe594e53b7eb73980662551a"><enum>(4)</enum><text>operate
			 countermeasures on a third party’s information systems to protect the third
			 party’s information systems and information that is stored on, processed by, or
			 transiting such information systems, if the third party lawfully authorizes
			 such countermeasures.</text>
			</paragraph></section><section id="ID84e73de7bcc04171ab187627f413d2d1"><enum>3.</enum><header>Voluntary
			 disclosure of cybersecurity threat indicators among private entities</header>
			<subsection id="idCF4BA9E59899419A9AACA22F0E58CC2C"><enum>(a)</enum><header>Authority To
			 disclose</header><text>Notwithstanding any other provision of law, any private
			 entity may disclose lawfully obtained cybersecurity threat indicators to any
			 other private entity.</text>
			</subsection><subsection id="id74CF354C0C134F9DBA39134DA0827DDA"><enum>(b)</enum><header>Use and
			 protection of information</header><text>A private entity disclosing or
			 receiving cybersecurity threat indicators pursuant to subsection (a)—</text>
				<paragraph id="id6C5DCFC13E424BD2AF7BABBCBEA56CF4"><enum>(1)</enum><text>shall make
			 reasonable efforts to safeguard communications, records, system traffic, or
			 other information that can be used to identify specific persons from
			 unauthorized access or acquisition;</text>
				</paragraph><paragraph id="id40BABCB1A8824A4C876C0FA1AD7DB789"><enum>(2)</enum><text>shall comply with
			 any lawful restrictions placed on the disclosure or use of cybersecurity threat
			 indicators by the disclosing entity, including, if requested, the removal of
			 information that may be used to identify specific persons from such
			 indicators;</text>
				</paragraph><paragraph id="id0D5EC1A9D835429C8F60B2D6E015106E"><enum>(3)</enum><text>may not use the
			 cybersecurity threat indicators to gain an unfair competitive advantage to the
			 detriment of the entity that authorized such sharing; and</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idE040E349FBEC49118340C920A433ECDF"><enum>(4)</enum><text>may only use,
			 retain, or further disclose such cybersecurity threat indicators for the
			 purpose of protecting an information system or information that is stored on,
			 processed by, or transiting an information system from cybersecurity threats or
			 mitigating such threats.</text>
				</paragraph></subsection></section><section id="id197B9EF984624059AE1816A06C1E41DD"><enum>4.</enum><header>Cybersecurity
			 exchanges</header>
			<subsection id="idbde1012f9f114ee88ad3d73ff47e621a"><enum>(a)</enum><header>Designation of
			 cybersecurity exchanges</header><text>The Secretary of Homeland Security, in
			 consultation with the Director of National Intelligence, the Attorney General,
			 and the Secretary of Defense, shall establish—</text>
				<paragraph id="id560677bc96ca4876a52f07f4478a290d"><enum>(1)</enum><text>a process for
			 designating appropriate Federal entities, such as 1 or more Federal
			 cybersecurity centers, and non-Federal entities as cybersecurity
			 exchanges;</text>
				</paragraph><paragraph id="idefcf940992ba4baeb8fa76424635212a"><enum>(2)</enum><text>procedures to
			 facilitate and encourage the sharing of classified and unclassified
			 cybersecurity threat indicators with designated cybersecurity exchanges and
			 other appropriate Federal entities and non-Federal entities; and</text>
				</paragraph><paragraph id="idc3068f506aba406cb27edeb1dea64f76"><enum>(3)</enum><text>a process for
			 identifying certified entities to receive classified cybersecurity threat
			 indicators in accordance with paragraph (2).</text>
				</paragraph></subsection><subsection id="id539b3f40bb5e46128c6ac3c1923aba35"><enum>(b)</enum><header>Purpose</header><text>The
			 purpose of a cybersecurity exchange is to efficiently receive and distribute
			 cybersecurity threat indicators as provided in this Act.</text>
			</subsection><subsection id="id02a5c4eaf02a4bd0866e3cabfecf1961"><enum>(c)</enum><header>Requirement for
			 a lead Federal cybersecurity exchange</header>
				<paragraph id="id555a3048bd734b6193c60ed7c0266ae3"><enum>(1)</enum><header>In
			 general</header><text>The Secretary of Homeland Security, in consultation with
			 the Director of National Intelligence, the Attorney General, and the Secretary
			 of Defense, shall designate a Federal entity as the lead cybersecurity exchange
			 to serve as the focal point within the Federal Government for cybersecurity
			 information sharing among Federal entities and with non-Federal
			 entities.</text>
				</paragraph><paragraph id="id2d0bc1c12f7c43bfaabbbb775f2bf7c4"><enum>(2)</enum><header>Responsibilities</header><text>The
			 lead cybersecurity exchange designated under paragraph (1) shall—</text>
					<subparagraph id="id2145c0e3b38b4d1d87fccc92c8f7fa1a"><enum>(A)</enum><text>receive and
			 distribute cybersecurity threat indicators in accordance with this Act;</text>
					</subparagraph><subparagraph id="id2880D2575B774790BA47115B18F1C8B1"><enum>(B)</enum><text>facilitate
			 information sharing, interaction, and collaboration among and between—</text>
						<clause id="id939cdf45377a46cab7d699c3799b13a2"><enum>(i)</enum><text>Federal
			 entities;</text>
						</clause><clause id="idcc86dca3a2c24d27acc22044b134f539"><enum>(ii)</enum><text>State, local,
			 tribal, and territorial governments;</text>
						</clause><clause id="id96169b03f4e245dda43227ab2fa9c415"><enum>(iii)</enum><text>private
			 entities;</text>
						</clause><clause id="ideba88eec951946789550589b9e2fa065"><enum>(iv)</enum><text>academia;</text>
						</clause><clause id="id313623629c9f4e2d84bdbdcd149131dd"><enum>(v)</enum><text>international
			 partners, in consultation with the Secretary of State; and</text>
						</clause><clause id="id4bdb8a3961d2437c93fc44057ab7ac98"><enum>(vi)</enum><text>other
			 cybersecurity exchanges;</text>
						</clause></subparagraph><subparagraph id="id4d0e8096f1ff4549a5a1fb26c4923065"><enum>(C)</enum><text>disseminate
			 timely and actionable cybersecurity threat, vulnerability, mitigation, and
			 warning information, including alerts, advisories, indicators, signatures, and
			 mitigation and response measures, to improve the security and protection of
			 information systems;</text>
					</subparagraph><subparagraph id="IDbe15fa34fb804b3e8131663e1064b9b8"><enum>(D)</enum><text>coordinate with
			 other Federal and non-Federal entities, as appropriate, to integrate
			 information from Federal and non-Federal entities, including Federal
			 cybersecurity centers, non-Federal network or security operation centers, other
			 cybersecurity exchanges, and non-Federal entities that disclose cybersecurity
			 threat indicators under section 5(a) to provide situational awareness of the
			 United States information security posture and foster information security
			 collaboration among information system owners and operators;</text>
					</subparagraph><subparagraph id="IDa56e740a34cd4b4d8ac0ae602a1eaa7d"><enum>(E)</enum><text>conduct, in
			 consultation with private entities and relevant Federal and other governmental
			 entities, regular assessments of existing and proposed information sharing
			 models to eliminate bureaucratic obstacles to information sharing and identify
			 best practices for such sharing; and</text>
					</subparagraph><subparagraph id="ID7d27ccce8b154120ac5f9aa80a54833d"><enum>(F)</enum><text>coordinate with
			 other Federal entities, as appropriate, to compile and analyze information
			 about risks and incidents that threaten information systems, including
			 information voluntarily submitted in accordance with section 5(a) or otherwise
			 in accordance with applicable laws.</text>
					</subparagraph></paragraph><paragraph id="ida5a18211600744819f9264197e6936a6"><enum>(3)</enum><header>Schedule for
			 designation</header>
					<subparagraph id="id0425E2B7753F441EA11B373556513C61"><enum>(A)</enum><header>Initial
			 designation</header><text>The initial designation of a lead cybersecurity
			 exchange under paragraph (1) shall be made not later than 60 days after the
			 date of the enactment of this Act.</text>
					</subparagraph><subparagraph id="id1229F593784A4A00A820F2E5913B1DD1"><enum>(B)</enum><header>Interim
			 designation</header><text>The National Cybersecurity and Communications
			 Integration Center of the Department of Homeland Security shall serve as the
			 interim lead cybersecurity exchange until the initial designation is made
			 pursuant to subparagraph (A).</text>
					</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ide68ed01f221e416f9ad3977ef4f194ed"><enum>(d)</enum><header>Additional
			 Federal cybersecurity exchanges</header><text>In accordance with the process
			 and procedures established in subsection (a), the Secretary of Homeland
			 Security, in consultation with the Director of National Intelligence, the
			 Attorney General, and the Secretary of Defense, may designate additional
			 existing Federal entities as cybersecurity exchanges, if such cybersecurity
			 exchanges are subject to the requirements for use, retention, and disclosure of
			 information by a cybersecurity exchange under section 5(b) and the special
			 requirements for Federal entities under section 5(g).</text>
			</subsection><subsection id="ida64f2326022f4a30afd6e8c373107c85"><enum>(e)</enum><header>Requirements
			 for non-Federal cybersecurity exchanges</header>
				<paragraph id="id944e480c39d842d98d4b90e00539ccc2"><enum>(1)</enum><header>In
			 general</header><text>In considering whether to designate a non-Federal entity
			 as a cybersecurity exchange to receive cybersecurity threat indicators under
			 section 5(a), and what entity to designate, the Secretary of Homeland Security
			 shall consider the following factors:</text>
					<subparagraph id="id04e08aef4bcc43dfb48a982e3fde7e69"><enum>(A)</enum><text>The net effect
			 that an additional cybersecurity exchange would have on the overall
			 cybersecurity of the United States.</text>
					</subparagraph><subparagraph id="idfdb97355dd2144ecb6c3838e4579f9c6"><enum>(B)</enum><text>Whether such
			 designation could substantially improve such overall cybersecurity by serving
			 as a hub for receiving and sharing cybersecurity threat indicators, including
			 the capacity of the non-Federal entity for performing those functions.</text>
					</subparagraph><subparagraph id="idc8c4d69da46049388da222e542d25f20"><enum>(C)</enum><text>The capacity of
			 such non-Federal entity to safeguard cybersecurity threat indicators from
			 unauthorized disclosure and use.</text>
					</subparagraph><subparagraph id="idcf8fd6dd6ca542a2b6925429855e7e7a"><enum>(D)</enum><text>The adequacy of
			 the policies and procedures of such non-Federal entity to protect personally
			 identifiable information from unauthorized disclosure and use.</text>
					</subparagraph><subparagraph id="id254dec8164d84d29b6fff64959fa380d"><enum>(E)</enum><text>The ability of
			 the non-Federal entity to sustain operations using entirely non-Federal sources
			 of funding.</text>
					</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4e59c023c9a54244af07069ad2eec8e3"><enum>(2)</enum><header>Regulations</header><text>The
			 Secretary of Homeland Security may promulgate regulations as may be necessary
			 to carry out this subsection.</text>
				</paragraph></subsection><subsection id="idca4c81c97d4d4ec7aecfbfcfe8376ed9"><enum>(f)</enum><header>Construction
			 with other authorities</header><text>Nothing in this section may be construed
			 to alter the authorities of a Federal cybersecurity center, unless such
			 cybersecurity center is acting in its capacity as a designated cybersecurity
			 exchange.</text>
			</subsection><subsection id="IDa4ae402bc06643c1b14074a4d5e31964"><enum>(g)</enum><header>No new
			 bureaucracies</header><text>Nothing in this section may be construed to
			 authorize additional layers of Federal bureaucracy for the receipt and
			 disclosure of cybersecurity threat indicators.</text>
			</subsection><subsection id="id34159d3b0010413d81fa6938c6f87354"><enum>(h)</enum><header>Report on
			 designation of cybersecurity exchanges</header><text>Not later than 90 days
			 after the date the Secretary of Homeland Security designates the initial
			 cybersecurity exchange under this section, the Secretary of Homeland Security,
			 the Director of National Intelligence, the Attorney General, and the Secretary
			 of Defense shall jointly submit to Congress a written report that—</text>
				<paragraph id="idbf88c32c2f2f4dc88654d50ff6ec70d0"><enum>(1)</enum><text>describes the
			 processes established to designate cybersecurity exchanges under subsection
			 (a);</text>
				</paragraph><paragraph id="id63de9272984b473f9047022350386051"><enum>(2)</enum><text>summarizes the
			 policies and procedures established under section 5(g); and</text>
				</paragraph><paragraph id="idd48787ecd47f432da6c1110986f39c1c"><enum>(3)</enum><text>if none of the
			 cybersecurity exchanges are non-Federal entities, provides recommendations
			 concerning the advisability of designating non-Federal entities as
			 cybersecurity exchanges.</text>
				</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="idB54F8C1704E043DB8C102745ECC682DC"><enum>5.</enum><header>Voluntary
			 disclosure of cybersecurity threat indicators to a cybersecurity
			 exchange</header>
			<subsection id="IDe99f19e77c814aca815b0d9c98ef9768"><enum>(a)</enum><header>Authority To
			 disclose</header><text>Notwithstanding any other provision of law, a
			 non-Federal entity may disclose lawfully obtained cybersecurity threat
			 indicators to a cybersecurity exchange.</text>
			</subsection><subsection id="ID2642c2d1cc92421b9336e2009172b05c"><enum>(b)</enum><header>Use, retention,
			 and disclosure of information by a cybersecurity exchange</header><text>Except
			 as provided in subsection (g), a cybersecurity exchange may only use, retain,
			 or further disclose information provided pursuant to subsection (a) in order to
			 protect information systems from cybersecurity threats or mitigate
			 cybersecurity threats.</text>
			</subsection><subsection id="ID04206b1906974257be73c6b751f08216"><enum>(c)</enum><header>Use and
			 protection of information received from a cybersecurity
			 exchange</header><text>A non-Federal entity receiving cybersecurity threat
			 indicators from a cybersecurity exchange—</text>
				<paragraph id="ID33b7197cafcb4611b661aef85fdf28a6"><enum>(1)</enum><text>shall make
			 reasonable efforts to safeguard communications, records, system traffic, or
			 other information that can be used to identify specific persons from
			 unauthorized access or acquisition;</text>
				</paragraph><paragraph id="ID620aee217e6b4107be283481253cd1c3"><enum>(2)</enum><text>shall comply with
			 any lawful restrictions placed on the disclosure or use of cybersecurity threat
			 indicators by the cybersecurity exchange or a third party, if the cybersecurity
			 exchange received such information from the third party, including, if
			 requested, the removal of information that can be used to identify specific
			 persons from such indicators;</text>
				</paragraph><paragraph id="ID0f73cb491e6f4a098ef69efc67def67c"><enum>(3)</enum><text>may not use the
			 cybersecurity threat indicators to gain an unfair competitive advantage to the
			 detriment of the third party that authorized such sharing; and</text>
				</paragraph><paragraph id="ID3ecc0b1174474189907b1aae52e41794"><enum>(4)</enum><text>may only use,
			 retain, or further disclose such cybersecurity threat indicators for the
			 purpose of protecting an information system or information that is stored on,
			 processed by, or transiting an information system from cybersecurity threats or
			 mitigating such threats.</text>
				</paragraph></subsection><subsection id="ID175a5422fffe4d6c972d5631e803dcbe"><enum>(d)</enum><header>Exemption from
			 public disclosure</header><text>Any cybersecurity threat indicator disclosed by
			 a non-Federal entity to a cybersecurity exchange pursuant to subsection (a)
			 shall be—</text>
				<paragraph id="idC2C302B223CA41EB89A218D500A0CA4F"><enum>(1)</enum><text>exempt from
			 disclosure under section 552(b)(3) of title 5, United States Code, or any
			 comparable State law; and</text>
				</paragraph><paragraph id="id8E1A987CDA174667A795FDAC26E0027A"><enum>(2)</enum><text>treated as
			 voluntarily shared information under section 552 of title 5, United States
			 Code, or any comparable State law.</text>
				</paragraph></subsection><subsection id="IDfb7c12fd2ba14fc6b04086749ab83558"><enum>(e)</enum><header>Exemption from
			 ex parte limitations</header><text display-inline="yes-display-inline">Any
			 cybersecurity threat indicator disclosed by a non-Federal entity to a
			 cybersecurity exchange pursuant to subsection (a) shall not be subject to the
			 rules of any governmental entity or judicial doctrine regarding ex parte
			 communications with a decisionmaking official.</text>
			</subsection><subsection id="ID5147159a8f454bbfba0af38faca2b062"><enum>(f)</enum><header>Exemption from
			 waiver of privilege</header><text display-inline="yes-display-inline">Any
			 cybersecurity threat indicator disclosed by a non-Federal entity to a
			 cybersecurity exchange pursuant to subsection (a) may not be construed to be a
			 waiver of any applicable privilege or protection provided under Federal, State,
			 tribal, or territorial law, including any trade secret protection.</text>
			</subsection><subsection id="IDb97cfea87e9942608a9a1dc88bcb7e8a"><enum>(g)</enum><header>Special
			 requirements for Federal entities</header>
				<paragraph id="ID2ca94d26062e492c808e2909b30d2f6f"><enum>(1)</enum><header>Permitted
			 disclosures</header><text>Notwithstanding any other provision of law and
			 consistent with the requirements of this subsection, a Federal entity that
			 lawfully intercepts, acquires, or otherwise obtains or possesses any
			 communication, record, or other information from its electronic communications
			 system, may disclose that communication, record, or other information
			 if—</text>
					<subparagraph id="idA29F9CDAC3994E46B7037575E42C0E54"><enum>(A)</enum><text>the disclosure is
			 made for the purpose of—</text>
						<clause id="id0A3C2751499B441A9688C599BFF8A6B5"><enum>(i)</enum><text>protecting the
			 information system of a Federal entity from cybersecurity threats; or</text>
						</clause><clause id="id5CB9E860688F4C2A8F7CC9B980FD09F2"><enum>(ii)</enum><text>mitigating
			 cybersecurity threats to—</text>
							<subclause id="IDd0cc51d5b2c14f27bc02636fb8dd1791"><enum>(I)</enum><text>another
			 component, officer, employee, or agent of such Federal entity with
			 cybersecurity responsibilities;</text>
							</subclause><subclause id="IDb92b246e7c9747e592a0b559ad7ba466"><enum>(II)</enum><text>any
			 cybersecurity exchange; or</text>
							</subclause><subclause id="ID729cdbc95447437590d8a17792fe1136"><enum>(III)</enum><text>a private
			 entity that is acting as a provider of electronic communication services,
			 remote computing service, or cybersecurity services to a Federal entity;
			 and</text>
							</subclause></clause></subparagraph><subparagraph id="id12F6173FE18E4401ADE72B8E02EA96D3"><enum>(B)</enum><text>the recipient of
			 the communication, record, or other information has agreed to comply with such
			 Federal entity’s lawful requirements regarding the protection and further
			 disclosure of such information, except to the extent such requirements are
			 inconsistent with the policies and procedures developed by the Secretary of
			 Homeland Security and approved by the Attorney General under paragraph
			 (4).</text>
					</subparagraph></paragraph><paragraph id="id4c5a418d1ffb4d6a863d3284a63b7f73"><enum>(2)</enum><header>Disclosure to
			 law enforcement</header><text>A cybersecurity exchange that is a Federal entity
			 may disclose cybersecurity threat indicators received pursuant to subsection
			 (a) to a law enforcement entity if—</text>
					<subparagraph id="id16686ea87d5143ccb7d29e577d1c22e7"><enum>(A)</enum><text>the information
			 appears to pertain to a crime which has been, is being, or is about to be
			 committed; and</text>
					</subparagraph><subparagraph id="id531996272a38400abb040d15d7b9865f"><enum>(B)</enum><text>the disclosure is
			 permitted under the procedures developed by the Secretary and approved by the
			 Attorney General under paragraph (4).</text>
					</subparagraph></paragraph><paragraph id="id22a563069035436fa99ff7804c07158e"><enum>(3)</enum><header>Further
			 disclosure and use of information by a Federal entity</header>
					<subparagraph id="idcc551c7a14db4a1298e195751f188b4f"><enum>(A)</enum><header>Authority to
			 receive cybersecurity threat indicators</header><text>A Federal entity that is
			 not a cybersecurity exchange may receive cybersecurity threat indicators from a
			 cybersecurity exchange pursuant to section 4, but shall only use or retain such
			 cybersecurity threat indicators in a manner that is consistent with this
			 subsection in order—</text>
						<clause id="idC3A176AC4BE9421597B8424A3083894E"><enum>(i)</enum><text>to
			 protect information systems from cybersecurity threats and to mitigate
			 cybersecurity threats; or</text>
						</clause><clause id="id09025975D386475683E9B1751053C82E"><enum>(ii)</enum><text>to
			 disclose such cybersecurity threat indicators to law enforcement pursuant to
			 paragraph (2).</text>
						</clause></subparagraph><subparagraph id="id0dae811b2f9d4aa8a85e8a67d2e59169"><enum>(B)</enum><header>Authority to
			 use cybersecurity threat indicators</header><text>A Federal entity that is not
			 a cybersecurity exchange shall ensure, by written agreement, that if disclosing
			 cybersecurity threat indicators to a non-Federal entity under this section,
			 such non-Federal entity shall use or retain such cybersecurity threat
			 indicators in a manner that is consistent with the requirements in—</text>
						<clause id="id5A3E97CFFA1B410D952B26B966A044C2"><enum>(i)</enum><text>section 3(b) on
			 the use and protection of information; and</text>
						</clause><clause id="id8C0F928B8D3647D78998A7BE63052CCB"><enum>(ii)</enum><text>paragraph (2) of
			 this subsection.</text>
						</clause></subparagraph></paragraph><paragraph id="id76b63dd074fb45f19272ef8ce9500a0a"><enum>(4)</enum><header>Privacy and
			 civil liberties</header>
					<subparagraph id="id2b0eee3b617345d79840bf752cfc70c1"><enum>(A)</enum><header>Requirement for
			 policies and procedures</header><text>In consultation with privacy and civil
			 liberties experts, the Director of National Intelligence, and the Secretary of
			 Defense, the Secretary of Homeland Security shall develop and periodically
			 review policies and procedures governing the receipt, retention, use, and
			 disclosure of cybersecurity threat indicators by a Federal entity obtained in
			 connection with activities authorized in this Act. Such policies and procedures
			 shall—</text>
						<clause id="idee80cb7aec634e04b8d7bf1a90390217"><enum>(i)</enum><text>minimize the
			 impact on privacy and civil liberties, consistent with the need to protect
			 information systems from cybersecurity threats and mitigate cybersecurity
			 threats;</text>
						</clause><clause id="id520012f86d5440188a3cd972cb2e5c21"><enum>(ii)</enum><text>reasonably limit
			 the receipt, retention, use and disclosure of cybersecurity threat indicators
			 associated with specific persons consistent with the need to carry out the
			 responsibilities of this Act, including establishing a process for the timely
			 destruction of cybersecurity threat indicators that are received pursuant to
			 this section that do not reasonably appear to be related to protecting
			 information systems from cybersecurity threats and mitigating cybersecurity
			 threats, unless such indicators appear to pertain to a crime which has been, is
			 being, or is about to be committed;</text>
						</clause><clause id="id2e37ca70898042778a6a3fe4935a6438"><enum>(iii)</enum><text>include
			 requirements to safeguard cybersecurity threat indicators that can be used to
			 identify specific persons from unauthorized access or acquisition; and</text>
						</clause><clause id="ida5c374c0392048079ff07151da7dbbb8"><enum>(iv)</enum><text>protect the
			 confidentiality of cybersecurity threat indicators associated with specific
			 persons to the greatest extent practicable and require recipients to be
			 informed that such indicators may only be used for protecting information
			 systems against cybersecurity threats, mitigating against cybersecurity
			 threats, or disclosed to law enforcement pursuant to paragraph (2).</text>
						</clause></subparagraph><subparagraph id="id39314531ecd64f92bd1304bd22592da6"><enum>(B)</enum><header>Adoption of
			 policies and procedures</header><text>The head of an agency responsible for a
			 Federal entity designated as a cybersecurity exchange under section 4 shall
			 adopt and comply with the policies and procedures developed under this
			 paragraph.</text>
					</subparagraph><subparagraph id="id3e3a3c497e6a4d05b1689b7217dfb22d"><enum>(C)</enum><header>Review by the
			 attorney general</header><text>Not later than 1 year after the date of the
			 enactment of this Act, the policies and procedures developed under this
			 subsection shall be reviewed and approved by the Attorney General.</text>
					</subparagraph><subparagraph id="id2400bd122b8b4e4c95257e4b63f72e01"><enum>(D)</enum><header>Provision to
			 Congress</header><text>The policies and procedures issued under this Act and
			 any amendments to such policies and procedures shall be provided to
			 Congress.</text>
					</subparagraph></paragraph><paragraph id="id5e948c96bb5c43569163a8c5d2ee8313"><enum>(5)</enum><header>Oversight</header>
					<subparagraph id="id956191beeae64c66a4f92da2a079128d"><enum>(A)</enum><header>Requirement for
			 oversight</header><text>The Secretary of Homeland Security and the Attorney
			 General shall establish a mandatory program to monitor and oversee compliance
			 with the policies and procedures issued under this subsection.</text>
					</subparagraph><subparagraph id="id8efc83299a3a49dc8e066ebc5c481120"><enum>(B)</enum><header>Notification of
			 the Attorney General</header><text>The head of each Federal entity that
			 receives information under this Act shall—</text>
						<clause id="idFDFBF8C9147B44FFA962BAE00EEF0FE7"><enum>(i)</enum><text>comply with the
			 policies and procedures developed by the Secretary of Homeland Security and
			 approved by the Attorney General under paragraph (4);</text>
						</clause><clause id="id8c35cd1dec0b4e2d91a55feac5ecd35e"><enum>(ii)</enum><text>promptly notify
			 the Attorney General of significant violations of such policies and procedures;
			 and</text>
						</clause><clause id="ideb1d916771ce4b66b9194d195bd17fc7"><enum>(iii)</enum><text>provide the
			 Attorney General with any information relevant to the violation that any
			 Attorney General requires.</text>
						</clause></subparagraph><subparagraph id="id6be4596b7065401abfd8b0fbe28d1ba4"><enum>(C)</enum><header>Annual
			 report</header><text>On an annual basis, the Chief Privacy and Civil Liberties
			 Officer of the Department of Justice and the Department of Homeland Security,
			 in consultation with the most senior privacy and civil liberties officer or
			 officers of any appropriate agencies, shall jointly submit to Congress a report
			 assessing the privacy and civil liberties impact of the governmental activities
			 conducted pursuant to this Act.</text>
					</subparagraph></paragraph><paragraph id="IDd921a8a63e2d4bbdbc3454a12abbf9c1"><enum>(6)</enum><header>Privacy and
			 Civil Liberties Oversight Board report</header><text>Not later than two years
			 after the date of the enactment of this Act, the Privacy and Civil Liberties
			 Oversight Board shall submit to Congress and the President a report
			 providing—</text>
					<subparagraph id="idAB5696FD3934466F9627E3BC0789A8E6"><enum>(A)</enum><text>an assessment of
			 the privacy and civil liberties impact of the activities carried out by the
			 Federal entities under this Act; and</text>
					</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idCC5ED525C0EC4E9E94D3E7200D9F810A"><enum>(B)</enum><text>recommendations
			 for improvements to or modifications of the law to address privacy and civil
			 liberties concerns.</text>
					</subparagraph></paragraph><paragraph id="ID9bf2f5181ec7435895fb50c072f6e2d5"><enum>(7)</enum><header>Sanctions</header><text>The
			 heads of Federal entities shall develop and enforce appropriate sanctions for
			 officers, employees, or agents of the Federal entities who conduct activities
			 under this Act—</text>
					<subparagraph id="ID25c006b3253145a89da048040ea8d51c"><enum>(A)</enum><text>outside the
			 normal course of their specified duties;</text>
					</subparagraph><subparagraph id="ID9d1b73b4a909454a999018339c4d543b"><enum>(B)</enum><text>in a manner
			 inconsistent with the discharge of the responsibilities of such governmental
			 entities; or</text>
					</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID99957d2ea4974c4580193c85dc46e211"><enum>(C)</enum><text>in contravention
			 of the requirements, policies and procedures required by this
			 subsection.</text>
					</subparagraph></paragraph></subsection></section><section id="id7c2f9dec40a84141ad77295948597c1c"><enum>6.</enum><header>Sharing of
			 classified cybersecurity threat indicators</header>
			<subsection id="idCD515E905C39486283D9365E34ED9D7B"><enum>(a)</enum><header>Sharing of
			 classified cybersecurity threat indicators</header><text>The procedures
			 established under section 4(a)(2) shall provide that classified cybersecurity
			 threat indicators may only be—</text>
				<paragraph id="id11a65ee7a1264aaab305fd2e390b0d02"><enum>(1)</enum><text>shared with
			 certified entities;</text>
				</paragraph><paragraph id="id8c990595f5a5455fabd289b37ccf5f49"><enum>(2)</enum><text>shared in a
			 manner that is consistent with the need to protect the national security of the
			 United States;</text>
				</paragraph><paragraph id="id9affb8dc4f2e4e6591b9b7f6f7bff053"><enum>(3)</enum><text>shared with a
			 person with an appropriate security clearance to receive such cybersecurity
			 threat indicators; and</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id0f2c4d936dfa4beba0c6c4069f4412f7"><enum>(4)</enum><text>used by a
			 certified entity in a manner that protects such cybersecurity threat indicators
			 from unauthorized disclosure.</text>
				</paragraph></subsection><subsection id="ide42d3dfd6d964804bab1511fb0a94631"><enum>(b)</enum><header>Requirement for
			 guidelines</header><text>Not later than 60 days after the date of the enactment
			 of this Act, the Director of National Intelligence shall issue guidelines
			 providing that appropriate Federal officials may, as the Director considers
			 necessary to carry out this Act—</text>
				<paragraph id="id9c6526216bed4d04ba72d981a4af471c"><enum>(1)</enum><text>grant a security
			 clearance on a temporary or permanent basis to an employee of a certified
			 entity;</text>
				</paragraph><paragraph id="id49394ba9a62b43c4b9ad4fac1b25b29e"><enum>(2)</enum><text>grant a security
			 clearance on a temporary or permanent basis to a certified entity and approval
			 to use appropriate facilities; or</text>
				</paragraph><paragraph id="id52a0994d2ff54dcaa976f7237cf384fe"><enum>(3)</enum><text>expedite the
			 security clearance process for such an employee or entity, if appropriate, in a
			 manner consistent with the need to protect the national security of the United
			 States.</text>
				</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idf46424992ba640b7bb335908c6dba196"><enum>(c)</enum><header>Distribution of
			 procedures and guidelines</header><text>Following the establishment of the
			 procedures under section 4(a)(2) and the issuance of the guidelines under
			 subsection (b), the Secretary of Homeland Security and the Director of National
			 Intelligence shall expeditiously distribute such procedures and guidelines
			 to—</text>
				<paragraph commented="no" display-inline="no-display-inline" id="id4E3CB23E1939423E841B53E1C0D073D8"><enum>(1)</enum><text>appropriate
			 governmental entities and private entities;</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id0C5567E6ACCD40D291733D7C2A91DE15"><enum>(2)</enum><text>the Committee on
			 Armed Services, the Committee on Commerce, Science, and Transportation, the
			 Committee on Homeland Security and Governmental Affairs, the Committee on the
			 Judiciary, and the Select Committee on Intelligence of the Senate; and</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id15257A3B2B8B48A9B9B6A90316544722"><enum>(3)</enum><text>the Committee on
			 Armed Services, the Committee on Energy and Commerce, the Committee on Homeland
			 Security, the Committee on the Judiciary, and the Permanent Select Committee on
			 Intelligence of the House of Representatives.</text>
				</paragraph></subsection></section><section id="id5db0ba5454d14fd3ae4fdb1b584ce947"><enum>7.</enum><header>Limitation on
			 liability and good faith defense for cybersecurity activities</header>
			<subsection id="ide8ae26f695de415395b49983025306e9"><enum>(a)</enum><header>In
			 general</header><text>No civil or criminal cause of action shall lie or be
			 maintained in any Federal or State court against any entity, and any such
			 action shall be dismissed promptly, based on—</text>
				<paragraph id="id7de00c3871ed4d129cb8ac0f57e04108"><enum>(1)</enum><text>the cybersecurity
			 monitoring activities authorized by paragraph (1) or (2) of section 2;
			 or</text>
				</paragraph><paragraph id="id70906880cb2e453e813e88fa5186ddc2"><enum>(2)</enum><text>the voluntary
			 disclosure of a lawfully obtained cybersecurity threat indicator—</text>
					<subparagraph id="id717caa39df07442582bf784bc0d0c1cb"><enum>(A)</enum><text>to a
			 cybersecurity exchange pursuant to section 5(a);</text>
					</subparagraph><subparagraph id="idc0f05407626f44e5bd238f4042b59f1c"><enum>(B)</enum><text>by a provider of
			 cybersecurity services to a customer of that provider;</text>
					</subparagraph><subparagraph id="id5658d100fb85427baed77ef1e79e9aae"><enum>(C)</enum><text>to a private
			 entity or governmental entity that provides or manages critical infrastructure
			 (as that term is used in section 1016 of the Critical Infrastructures
			 Protection Act of 2001 (42 U.S.C. 5195c)); or</text>
					</subparagraph><subparagraph id="id18859378fa5848b6b286d8de0516e32d"><enum>(D)</enum><text>to any other
			 private entity under section 3(a), if the cybersecurity threat indicator is
			 also disclosed within a reasonable time to a cybersecurity exchange.</text>
					</subparagraph></paragraph></subsection><subsection id="id324d9f8bd9b74d7aa50178e8442f40d7"><enum>(b)</enum><header>Good faith
			 defense</header><text>If a civil or criminal cause of action is not barred
			 under subsection (a), good faith reliance that this Act permitted the conduct
			 complained of is a complete defense against any civil or criminal action
			 brought under this Act or any other law.</text>
			</subsection><subsection id="idE4682A866FBE48FAB38F2C5205D685B7"><enum>(c)</enum><header>Limitation on
			 use of cybersecurity threat indicators for regulatory enforcement
			 actions</header><text>No Federal entity may use a cybersecurity threat
			 indicator received pursuant to this Act as evidence in a regulatory enforcement
			 action against the entity that lawfully shared the cybersecurity threat
			 indicator with a cybersecurity exchange that is a Federal entity.</text>
			</subsection><subsection id="id789cd183b163497f9f2544ca82f1bfa0"><enum>(d)</enum><header>Delay of
			 notification authorized for law enforcement or national security
			 purposes</header><text>No civil or criminal cause of action shall lie or be
			 maintained in any Federal or State court against any entity, and any such
			 action shall be dismissed promptly, for a failure to disclose a cybersecurity
			 threat indicator if—</text>
				<paragraph id="id2064c5698a9d4a01a6f346bb080d194b"><enum>(1)</enum><text>the Attorney
			 General determines that disclosure of a cybersecurity threat indicator would
			 impede a civil or criminal investigation and submits a written request to delay
			 notification for up to 30 days, except that the Attorney General may, by a
			 subsequent written request, revoke such delay or extend the period of time set
			 forth in the original request made under this paragraph if further delay is
			 necessary; or</text>
				</paragraph><paragraph id="idc8a1ca41bb624d048ad5c13f6f3cb252"><enum>(2)</enum><text>the Secretary of
			 Homeland Security, the Attorney General, or the Director of National
			 Intelligence determines that disclosure of a cybersecurity threat indicator
			 would threaten national or homeland security and submits a written request to
			 delay notification, except that the Secretary, the Attorney General, or the
			 Director may, by a subsequent written request, revoke such delay or extend the
			 period of time set forth in the original request made under this paragraph if
			 further delay is necessary.</text>
				</paragraph></subsection><subsection id="idb1e4382053254349a1c5cd687238200b"><enum>(e)</enum><header>Limitation on
			 liability for failure To act</header><text>No civil or criminal cause of action
			 shall lie or be maintained in any Federal or State court against any private
			 entity, or any officer, employee, or agent of such an entity, and any such
			 action shall be dismissed promptly, for the reasonable failure to act on
			 information received under this Act.</text>
			</subsection><subsection id="id8124d6b9e8b4470ab426fec2cc8a1b1d"><enum>(f)</enum><header>Limitation on
			 protections</header><text>Any person who knowingly and willfully violates
			 restrictions under this Act shall not receive the protections of this
			 Act.</text>
			</subsection><subsection id="idf84d276185bc4a34b8e266d70fa28d45"><enum>(g)</enum><header>Private right
			 of action</header><text>Nothing in this Act may be construed to limit liability
			 for a failure to comply with the requirements of section 3(b) and section 5(c)
			 on the use and protection of information.</text>
			</subsection><subsection id="id44d6dcaafa74485a81885ba78f264922"><enum>(h)</enum><header>Defense for
			 breach of contract</header><text>Compliance with lawful restrictions placed on
			 the disclosure or use of cybersecurity threat indicators is a complete defense
			 to any tort or breach of contract claim originating in a failure to disclose
			 cybersecurity threat indicators to a third party.</text>
			</subsection></section><section id="ID261299eeb21648118056c1b0b9f04e88"><enum>8.</enum><header>Construction and
			 Federal preemption</header>
			<subsection id="ID2c43ac63463c46ccaff7e6e863591c19"><enum>(a)</enum><header>Construction</header><text>Nothing
			 in this Act may be construed—</text>
				<paragraph id="IDae3dd3f6b74b4b218b153b5875193e4c"><enum>(1)</enum><text display-inline="yes-display-inline">to permit the unauthorized disclosure
			 of—</text>
					<subparagraph id="id62608015DAD94A99A431791FD9E49A27"><enum>(A)</enum><text>information that
			 has been determined by the Federal Government pursuant to an Executive order or
			 statute to require protection against unauthorized disclosure for reasons of
			 national defense or foreign relations;</text>
					</subparagraph><subparagraph id="idECF562B9B99F4478B219AAE496F5DCA9"><enum>(B)</enum><text>any restricted
			 data (as that term is defined in paragraph (y) of section 11 of the Atomic
			 Energy Act of 1954 (42 U.S.C. 2014));</text>
					</subparagraph><subparagraph id="id222962C38B524DAAB29E3DDCCE74F6A0"><enum>(C)</enum><text>information
			 related to intelligence sources and methods; or</text>
					</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idCAB12A46DFCC4589B11045A6CED3CC2F"><enum>(D)</enum><text>information that
			 is specifically subject to a court order or a certification, directive, or
			 other authorization by the Attorney General precluding such disclosure;</text>
					</subparagraph></paragraph><paragraph id="id8CCFB1BD232341CA8644636D3FC4DFCA"><enum>(2)</enum><text>to limit or
			 prohibit otherwise lawful disclosures of communications, records, or
			 information by a private entity to a cybersecurity exchange or any other
			 governmental or private entity not conducted under this Act;</text>
				</paragraph><paragraph id="ida86770e12f8744a4af60701cf1582a26"><enum>(3)</enum><text>to limit the
			 ability of a private entity or governmental entity to receive data about its
			 information systems, including lawfully obtained cybersecurity threat
			 indicators;</text>
				</paragraph><paragraph id="ID2076333a48214e6aa50c480be75ed0e5"><enum>(4)</enum><text>to authorize or
			 prohibit any law enforcement, homeland security, or intelligence activities not
			 otherwise authorized or prohibited under another provision of law;</text>
				</paragraph><paragraph id="ID913c7bd6104d4fcdb8e92f4b47a7154b"><enum>(5)</enum><text>to permit
			 price-fixing, allocating a market between competitors, monopolizing or
			 attempting to monopolize a market, boycotting, or exchanges of price or cost
			 information, customer lists, or information regarding future competitive
			 planning; or</text>
				</paragraph><paragraph id="ID63817002b62346b48ada148e03491f7a"><enum>(6)</enum><text>to prevent a
			 governmental entity from using information not acquired through a cybersecurity
			 exchange for regulatory purposes.</text>
				</paragraph></subsection><subsection id="idbaa0a7b84e114f2b90469564a0c7d684"><enum>(b)</enum><header>Federal
			 preemption</header><text>This Act supersedes any law or requirement of a State
			 or political subdivision of a State that restricts or otherwise expressly
			 regulates the provision of cybersecurity services or the acquisition,
			 interception, retention, use or disclosure of communications, records, or other
			 information by private entities to the extent such law contains requirements
			 inconsistent with this Act.</text>
			</subsection><subsection id="id5d8accdfea5744b3981aac706ea8c1a2"><enum>(c)</enum><header>Preservation of
			 other State law</header><text>Except as expressly provided, nothing in this Act
			 shall be construed to preempt the applicability of any other State law or
			 requirement.</text>
			</subsection><subsection id="id5cad23d4809849c8998b1070819b0e41"><enum>(d)</enum><header>No creation of
			 a right to information</header><text>The provision of information to a
			 non-Federal entity under this Act may not create a right or benefit to similar
			 information by any other non-Federal entity.</text>
			</subsection><subsection id="idbfd0c0d535534829937b7a7e4cc2d1f9"><enum>(e)</enum><header>Prohibition on
			 requirement To provide information to the Federal
			 Government</header><text>Nothing in this Act may be construed to permit a
			 Federal entity—</text>
				<paragraph id="id7cd6c1d36d8d4ceb8b82eb330baa1356"><enum>(1)</enum><text>to require a
			 non-Federal entity to share information with the Federal Government; or</text>
				</paragraph><paragraph id="ide0597cbd55e74521b0b111002989998b"><enum>(2)</enum><text>to condition the
			 disclosure of unclassified or classified cybersecurity threat indicators
			 pursuant to this Act with a non-Federal entity on the provision of
			 cybersecurity threat information to the Federal Government.</text>
				</paragraph></subsection><subsection id="id6ecd413d01804c65a48511e5f9ddfb64"><enum>(f)</enum><header>Limitation on
			 use of information</header><text>No cybersecurity threat indicators obtained
			 pursuant to this Act may be used, retained, or disclosed by a Federal entity or
			 non-Federal entity, except as authorized under this Act.</text>
			</subsection><subsection id="id02C031D8C12040FD8F9C65DE270D8243"><enum>(g)</enum><header>Declassification
			 and sharing of information</header><text>Consistent with the exemptions from
			 public disclosure of section 5(d), the Director of National Intelligence, in
			 consultation with the Secretary of Homeland Security, shall facilitate the
			 declassification and sharing of information in the possession of a Federal
			 entity that is related to cybersecurity threats, as the Director deems
			 appropriate.</text>
			</subsection><subsection id="id58f957c3441a4d51b14a7662a11169be"><enum>(h)</enum><header>Report on
			 implementation</header><text>Not later than two years after the date of the
			 enactment of this Act, the Secretary of Homeland Security, the Director of
			 National Intelligence, the Attorney General, and the Secretary of Defense shall
			 jointly submit to Congress a report that—</text>
				<paragraph id="idd420674236ae42d683b82b16566f5197"><enum>(1)</enum><text>describes the
			 extent to which the authorities conferred by this Act have enabled the Federal
			 Government and the private sector to mitigate cybersecurity threats;</text>
				</paragraph><paragraph id="id3732b73395dd45e599b72dd727c91ca8"><enum>(2)</enum><text>discloses any
			 significant acts of noncompliance by a non-Federal entity with this Act, with
			 special emphasis on privacy and civil liberties, and any measures taken by the
			 Federal Government to uncover such noncompliance;</text>
				</paragraph><paragraph id="id07f471821f4d47fe84700dc63dfc70eb"><enum>(3)</enum><text>describes in
			 general terms the nature and quantity of information disclosed and received by
			 governmental entities and private entities under this Act; and</text>
				</paragraph><paragraph id="idb67007eb528b4f7da962f88cd052a11b"><enum>(4)</enum><text>proposes changes
			 to the law, including the definitions, authorities and requirements of this
			 Act, that are necessary to ensure the law keeps pace with the threat while
			 protecting privacy and civil liberties.</text>
				</paragraph></subsection><subsection id="ID75e17acd102c4cd4b346f1afc5b7bbea"><enum>(i)</enum><header>Requirement for
			 annual report</header><text display-inline="yes-display-inline">On an annual
			 basis, the Director of National Intelligence shall provide a report to the
			 Select Committee on Intelligence of the Senate and the Permanent Select
			 Committee on Intelligence of the House of Representatives on the implementation
			 of section 6 of this Act. Such report, which shall be submitted in a classified
			 and in an unclassified form, shall include a list of private entities that
			 receive classified cybersecurity threat indicators under this Act, except that
			 the unclassified report shall not contain information that may be used to
			 identify specific private entities unless such private entities consent to such
			 identification.</text>
			</subsection></section><section id="IDf0f6a68507684320b1a50674eab0c5ca"><enum>9.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
			<paragraph id="ida5db74677b554293819c7fc88c8ab46c"><enum>(1)</enum><header>Certified
			 entity</header><text>The term <term>certified entity</term> means a protected
			 entity, a self-protected entity, or a provider of cybersecurity services
			 that—</text>
				<subparagraph id="id1620e32aadd3434c8190b393d1881f04"><enum>(A)</enum><text>possesses or is
			 eligible to obtain a security clearance, as determined by the Director of
			 National Intelligence; and</text>
				</subparagraph><subparagraph id="ida5dbf5fcb0844ed19356e69d77057933"><enum>(B)</enum><text>is able to
			 demonstrate to the Director of National Intelligence that such provider or such
			 entity can appropriately protect and use classified cybersecurity threat
			 indicators.</text>
				</subparagraph></paragraph><paragraph id="id5f357745092343a6b8dd648155e03422"><enum>(2)</enum><header>Countermeasure</header><text>The
			 term <term>countermeasure</term> means automated or manual actions with
			 defensive intent to modify or block data packets associated with electronic or
			 wire communications, internet traffic, program code, or other system traffic
			 transiting to or from or stored on an information system for the purpose of
			 protecting the information system from cybersecurity threats, conducted on an
			 information system owned or operated by or on behalf of the party to be
			 protected or operated by a private entity acting as a provider of electronic
			 communication services, remote computing services, or cybersecurity services to
			 the party to be protected.</text>
			</paragraph><paragraph id="ID66e50dfbe134493590c2e3c5bd92a675"><enum>(3)</enum><header>Cybersecurity
			 exchange</header><text>The term <term>cybersecurity exchange</term> means any
			 governmental entity or private entity designated by the Secretary of Homeland
			 Security, in consultation with the Director of National Intelligence, the
			 Attorney General, and the Secretary of Defense, to receive and distribute
			 cybersecurity threat indicators under section 4(a).</text>
			</paragraph><paragraph id="ID4fae87b80a0f4b0fb51cbbb70abcf56f"><enum>(4)</enum><header>Cybersecurity
			 services</header><text>The term <term>cybersecurity services</term> means
			 products, goods, or services intended to detect, mitigate, or prevent
			 cybersecurity threats.</text>
			</paragraph><paragraph id="IDd6231fbe231c4c18b8c307d08d162bd9"><enum>(5)</enum><header>Cybersecurity
			 threat</header><text>The term <term>cybersecurity threat</term> means any
			 action that may result in unauthorized access to, exfiltration of, manipulation
			 of, or impairment to the integrity, confidentiality, or availability of an
			 information system or information that is stored on, processed by, or
			 transiting an information system.</text>
			</paragraph><paragraph commented="no" id="IDb1f4ffa6714f4133a1fe652fd3775071"><enum>(6)</enum><header>Cybersecurity
			 threat indicator</header><text>The term <term>cybersecurity threat
			 indicator</term> means information—</text>
				<subparagraph id="id5a3e21f63d304d778e5ed9444247ca7c"><enum>(A)</enum><text>that may be
			 indicative of or describe—</text>
					<clause id="idd57c2cf4bcf64fc98de4ff97ac5ee5c6"><enum>(i)</enum><text>malicious
			 reconnaissance, including anomalous patterns of communications that reasonably
			 appear to be transmitted for the purpose of gathering technical information
			 related to a cybersecurity threat;</text>
					</clause><clause id="idf73e8b27867b48a7a38ea447a82b3442"><enum>(ii)</enum><text>a
			 method of defeating a technical control;</text>
					</clause><clause id="id37323b8aa9af43ce8afcd551c7f8ace5"><enum>(iii)</enum><text>a
			 technical vulnerability;</text>
					</clause><clause id="id57c007477a654f83999e4bd3ae44f8bd"><enum>(iv)</enum><text>a
			 method of defeating an operational control;</text>
					</clause><clause id="idab3f20b87edd44d3a890e6edfb5c6c0e"><enum>(v)</enum><text>a
			 method of causing a user with legitimate access to an information system or
			 information that is stored on, processed by, or transiting an information
			 system to unwittingly enable the defeat of a technical control or an
			 operational control;</text>
					</clause><clause id="id2c5023ffce7a4f9e9b6a93d11a57f37a"><enum>(vi)</enum><text>malicious cyber
			 command and control;</text>
					</clause><clause id="idf1ced2ffc8a346f5966fc83bf5ceb82a"><enum>(vii)</enum><text>the actual or
			 potential harm caused by an incident, including information exfiltrated as a
			 result of subverting a technical control when it is necessary in order to
			 identify or describe a cybersecurity threat;</text>
					</clause><clause id="id5f940c93006a422bb04f2edaf2d1a6b6"><enum>(viii)</enum><text>any other
			 attribute of a cybersecurity threat, if disclosure of such attribute is not
			 otherwise prohibited by law; or</text>
					</clause><clause id="id73b8a34533794e758695bd1f7f8eab5d"><enum>(ix)</enum><text>any combination
			 thereof; and</text>
					</clause></subparagraph><subparagraph id="id56289e9afc9c495abf07312d90121938"><enum>(B)</enum><text>from which
			 reasonable efforts have been made to remove information that can be used to
			 identify specific persons unrelated to the cybersecurity threat.</text>
				</subparagraph></paragraph><paragraph id="idc2a1eb2cfbab4e5b99f84f939f79ca03"><enum>(7)</enum><header>Federal
			 cybersecurity center</header><text>The term <term>Federal cybersecurity
			 center</term> means the Department of Defense Cyber Crime Center, the
			 Intelligence Community Incident Response Center, the United States Cyber
			 Command Joint Operations Center, the National Cyber Investigative Joint Task
			 Force, the National Security Agency/Central Security Service Threat Operations
			 Center, or the United States Computer Emergency Readiness Team, or any
			 successor to such a center.</text>
			</paragraph><paragraph id="id8d3af17772f249b0893d5e133c6be302"><enum>(8)</enum><header>Federal
			 entity</header><text>The term <term>Federal entity</term> means an agency or
			 department of the United States, or any component, officer, employee, or agent
			 of such an agency or department.</text>
			</paragraph><paragraph id="idc0aeb5a30d734f2788310a56fb0d589c"><enum>(9)</enum><header>Governmental
			 entity</header><text>The term <term>governmental entity</term> means any
			 Federal entity and agency or department of a State, local, tribal, or
			 territorial government other than an educational institution, or any component,
			 officer, employee, or agent of such an agency or department.</text>
			</paragraph><paragraph id="idd648c6f0072c4a348cc4ed3b786d0618"><enum>(10)</enum><header>Information
			 system</header><text>The term <term>information system</term> means a discrete
			 set of information resources organized for the collection, processing,
			 maintenance, use, sharing, dissemination, or disposition of information,
			 including communications with, or commands to, specialized systems such as
			 industrial and process control systems, telephone switching and private branch
			 exchange, and environmental control systems.</text>
			</paragraph><paragraph id="id518a73ad754f42b1a76132cab68c1268"><enum>(11)</enum><header>Malicious
			 cyber command and control</header><text>The term <term>malicious cyber command
			 and control</term> means a method for remote identification of, access to, or
			 use of, an information system or information that is stored on, processed by,
			 or transiting an information system associated with a known or suspected
			 cybersecurity threat.</text>
			</paragraph><paragraph id="id3fef01cedf224849bb4d090934f0802b"><enum>(12)</enum><header>Malicious
			 reconnaissance</header><text>The term <term>malicious reconnaissance</term>
			 means a method for actively probing or passively monitoring an information
			 system for the purpose of discerning technical vulnerabilities of the
			 information system, if such method is associated with a known or suspected
			 cybersecurity threat.</text>
			</paragraph><paragraph id="id812b0d59f6624e1cba6a776914312630"><enum>(13)</enum><header>Monitor</header><text>The
			 term <term>monitor</term> means the interception, acquisition, or collection of
			 information that is stored on, processed by, or transiting an information
			 system for the purpose of identifying cybersecurity threats.</text>
			</paragraph><paragraph id="id55664905b85c473f8438108ae6b2721b"><enum>(14)</enum><header>Non-Federal
			 entity</header><text>The term <term>non-Federal entity</term> means a private
			 entity or a governmental entity other than a Federal entity.</text>
			</paragraph><paragraph id="id9bd22fc0dd6d4e088efb53c1f1788e38"><enum>(15)</enum><header>Operational
			 control</header><text>The term <term>operational control</term> means a
			 security control for an information system that primarily is implemented and
			 executed by people.</text>
			</paragraph><paragraph id="idca7ffd238bf24a91838109691abe5a74"><enum>(16)</enum><header>Private
			 entity</header><text>The term <term>private entity</term> has the meaning given
			 the term <term>person</term> in section 1 of title 1, United States Code, and
			 does not include a governmental entity.</text>
			</paragraph><paragraph id="id0bd369393b6e4cd3acdfdafcd492a9e5"><enum>(17)</enum><header>Protect</header><text>The
			 term <term>protect</term> means actions undertaken to secure, defend, or reduce
			 the vulnerabilities of an information system, mitigate cybersecurity threats,
			 or otherwise enhance information security or the resiliency of information
			 systems or assets.</text>
			</paragraph><paragraph id="ida028ca54cdbe4d9aa4070752d7f71ec4"><enum>(18)</enum><header>Protected
			 entity</header><text>The term <term>protected entity</term> means an entity,
			 other than an individual, that contracts with a provider of cybersecurity
			 services for goods or services to be used for cybersecurity purposes.</text>
			</paragraph><paragraph id="id0632a082fc8143ac896526561a30e424"><enum>(19)</enum><header>Self-protected
			 entity</header><text>The term <term>self-protected entity</term> means an
			 entity, other than an individual, that provides cybersecurity services to
			 itself.</text>
			</paragraph><paragraph id="idc7cbcd912e2a47c7aaf7fe14f1eaeb2e"><enum>(20)</enum><header>Technical
			 control</header><text>The term <term>technical control</term> means a hardware
			 or software restriction on, or audit of, access or use of an information system
			 or information that is stored on, processed by, or transiting an information
			 system that is intended to ensure the confidentiality, integrity, or
			 availability of that system.</text>
			</paragraph><paragraph id="id6d741965bed049a09475e59352d03221"><enum>(21)</enum><header>Technical
			 vulnerability</header><text>The term <term>technical vulnerability</term> means
			 any attribute of hardware or software that could enable or facilitate the
			 defeat of a technical control.</text>
			</paragraph><paragraph id="id5f49e1cce113475693799abd325780d0"><enum>(22)</enum><header>Third
			 party</header><text>The term <quote>third party</quote> includes Federal
			 entities and non-Federal entities.</text>
			</paragraph></section></legis-body>
</bill>
