[Congressional Record Volume 161, Number 125 (Tuesday, August 4, 2015)]
[Senate]
[Pages S6321-S6322]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2611. Ms. KLOBUCHAR submitted an amendment intended to be proposed 
by her to the bill S. 754, to improve cybersecurity in the United 
States through enhanced sharing of information about cybersecurity 
threats, and for other purposes; which was ordered to lie on the table; 
as follows:


[[Page S6322]]


  

       At the appropriate place, insert the following:

     SEC. __. GAO REPORT ON IMPLEMENTATION.

       (a) Study.--The Comptroller General of the United States 
     shall conduct a study on the implementation of the 
     information sharing system developed under this Act.
       (b) Report.--Not later than 1 year after the date on which 
     the information sharing procedures described in this Act are 
     implemented, the Comptroller General shall submit to Congress 
     a report on the study conducted under subsection (a), which 
     shall include an assessment of--
       (1) the effectiveness of the information sharing system in 
     sharing cyber threat indicators, including an approximate 
     number of cyber threat indicators shared;
       (2) the extent to which the information sharing procedures 
     described in this Act--
       (A) are used by private entities; and
       (B) are effective at screening out personal information or 
     information that identifies a specific person not directly 
     related to a cybersecurity threat;
       (3) the extent to which private entities have implemented 
     procedures to remove personal information or information that 
     identifies a specific person not directly related to a 
     cybersecurity threat prior to sharing cyber threat indicators 
     with a Federal entity, consistent with the requirements of 
     this Act;
       (4) the extent to which the Department of Homeland Security 
     has implemented procedures to remove personal information or 
     information that identifies a specific person not directly 
     related to a cybersecurity threat prior to sharing cyber 
     threat indicators with private entities or other Federal 
     entities, consistent with the requirements of this Act; and
       (5) the effectiveness of data security implemented by 
     Federal entities that are involved in the sharing of cyber 
     threat indicators.
                                 ______