<section xmlns="http://xml.house.gov/schemas/uslm/1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" style="-uslm-lc:I80" id="id1b00e190-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502"><num value="1502">§ 1502.</num><heading> Sharing of information by the Federal Government</heading><subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id1b00e191-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/a"><num value="a" class="bold">(a)</num><heading class="bold"> In general</heading><chapeau>Consistent with the protection of classified information, intelligence sources and methods, and privacy and civil liberties, the Director of National Intelligence, the Secretary of Homeland Security, the Secretary of Defense, and the Attorney General, in consultation with the heads of the appropriate Federal entities, shall jointly develop and issue procedures to facilitate and promote—</chapeau><paragraph style="-uslm-lc:I12" class="indent1" id="id1b00e192-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/a/1"><num value="1">(1)</num><content> the timely sharing of classified cyber threat indicators and defensive measures in the possession of the Federal Government with representatives of relevant Federal entities and non-Federal entities that have appropriate security clearances;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id1b00e193-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/a/2"><num value="2">(2)</num><content> the timely sharing with relevant Federal entities and non-Federal entities of cyber threat indicators, defensive measures, and information relating to cybersecurity threats or authorized uses under this subchapter, in the possession of the Federal Government that may be declassified and shared at an unclassified level;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id1b00e194-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/a/3"><num value="3">(3)</num><content> the timely sharing with relevant Federal entities and non-Federal entities, or the public if appropriate, of unclassified, including controlled unclassified, cyber threat indicators and defensive measures in the possession of the Federal Government;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id1b035195-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/a/4"><num value="4">(4)</num><content> the timely sharing with Federal entities and non-Federal entities, if appropriate, of information relating to cybersecurity threats or authorized uses under this subchapter, in the possession of the Federal Government about cybersecurity threats to such entities to prevent or mitigate adverse effects from such cybersecurity threats; and</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id1b035196-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/a/5"><num value="5">(5)</num><content> the periodic sharing, through publication and targeted outreach, of cybersecurity best practices that are developed based on ongoing analyses of cyber threat indicators, defensive measures, and information relating to cybersecurity threats or authorized uses under this subchapter, in the possession of the Federal Government, with attention to accessibility and implementation challenges faced by small business concerns (as defined in <ref href="/us/usc/t15/s632">section 632 of title 15</ref>).</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id1b035197-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/b"><num value="b" class="bold">(b)</num><heading class="bold"> Development of procedures</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id1b035198-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/b/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><chapeau>The procedures developed under subsection (a) shall—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id1b035199-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/b/1/A"><num value="A">(A)</num><content> ensure the Federal Government has and maintains the capability to share cyber threat indicators and defensive measures in real time consistent with the protection of classified information;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id1b03519a-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/b/1/B"><num value="B">(B)</num><content> incorporate, to the greatest extent practicable, existing processes and existing roles and responsibilities of Federal entities and non-Federal entities for information sharing by the Federal Government, including sector specific information sharing and analysis centers;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id1b03519b-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/b/1/C"><num value="C">(C)</num><content> include procedures for notifying, in a timely manner, Federal entities and non-Federal entities that have received a cyber threat indicator or defensive measure from a Federal entity under this subchapter that is known or determined to be in error or in contravention of the requirements of this subchapter or another provision of Federal law or policy of such error or contravention;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id1b03519c-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/b/1/D"><num value="D">(D)</num><content> include requirements for Federal entities sharing cyber threat indicators or defensive measures to implement and utilize security controls to protect against unauthorized access to or acquisition of such cyber threat indicators or defensive measures;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id1b03519d-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/b/1/E"><num value="E">(E)</num><chapeau> include procedures that require a Federal entity, prior to the sharing of a cyber threat indicator—</chapeau><clause style="-uslm-lc:I14" class="indent3" id="id1b03519e-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/b/1/E/i"><num value="i">(i)</num><content> to review such cyber threat indicator to assess whether such cyber threat indicator contains any information not directly related to a cybersecurity threat that such Federal entity knows at the time of sharing to be personal information of a specific individual or information that identifies a specific individual and remove such information; or</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="id1b03519f-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/b/1/E/ii"><num value="ii">(ii)</num><content> to implement and utilize a technical capability configured to remove any information not directly related to a cybersecurity threat that the Federal entity knows at the time of sharing to be personal information of a specific individual or information that identifies a specific individual; and</content>
</clause>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id1b0351a0-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/b/1/F"><num value="F">(F)</num><content> include procedures for notifying, in a timely manner, any United States person whose personal information is known or determined to have been shared by a Federal entity in violation of this subchapter.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id1b0351a1-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/b/2"><num value="2" class="bold">(2)</num><heading class="bold"> Consultation</heading><content><p style="-uslm-lc:I12" class="indent1">In developing the procedures required under this section, the Director of National Intelligence, the Secretary of Homeland Security, the Secretary of Defense, and the Attorney General shall consult with appropriate Federal entities, including the Small Business Administration and the National Laboratories (as defined in <ref href="/us/usc/t42/s15801">section 15801 of title 42</ref>), to ensure that effective protocols are implemented that will facilitate and promote the sharing of cyber threat indicators by the Federal Government in a timely manner.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id1b0351a2-a3d3-11e9-be6e-e752deae1f00" identifier="/us/usc/t6/s1502/c"><num value="c" class="bold">(c)</num><heading class="bold"> Submittal to Congress</heading><content><p style="-uslm-lc:I11" class="indent0">Not later than 60 days after <date date="2015-12-18">December 18, 2015</date>, the Director of National Intelligence, in consultation with the heads of the appropriate Federal entities, shall submit to Congress the procedures required by subsection (a).</p>
</content>
</subsection>
<sourceCredit id="id1b0351a3-a3d3-11e9-be6e-e752deae1f00">(<ref href="/us/pl/114/113/dN/tI/s103">Pub. L. 114–113, div. N, title I, § 103</ref>, <date date="2015-12-18">Dec. 18, 2015</date>, <ref href="/us/stat/129/2939">129 Stat. 2939</ref>.)</sourceCredit>
</section>