Authorizations for preventing, detecting, analyzing, and mitigating cybersecurity threats
Authorization for monitoring
In general
Notwithstanding any other provision of law, a private entity may, for cybersecurity purposes, monitor—
an information system of such private entity;
an information system of another non-Federal entity, upon the authorization and written consent of such other entity;
an information system of a Federal entity, upon the authorization and written consent of an authorized representative of the Federal entity; and
information that is stored on, processed by, or transiting an information system monitored by the private entity under this paragraph.
Construction
Nothing in this subsection shall be construed—
to authorize the monitoring of an information system, or the use of any information obtained through such monitoring, other than as provided in this subchapter; or
to limit otherwise lawful activity.
Authorization for operation of defensive measures
In general
Notwithstanding any other provision of law, a private entity may, for cybersecurity purposes, operate a defensive measure that is applied to—
an information system of such private entity in order to protect the rights or property of the private entity;
an information system of another non-Federal entity upon written consent of such entity for operation of such defensive measure to protect the rights or property of such entity; and
an information system of a Federal entity upon written consent of an authorized representative of such Federal entity for operation of such defensive measure to protect the rights or property of the Federal Government.
Construction
Nothing in this subsection shall be construed—
to authorize the use of a defensive measure other than as provided in this subsection; or
to limit otherwise lawful activity.
Authorization for sharing or receiving cyber threat indicators or defensive measures
In general
Lawful restriction
Construction
Nothing in this subsection shall be construed—
to authorize the sharing or receiving of a cyber threat indicator or defensive measure other than as provided in this subsection; or
to limit otherwise lawful activity.
Protection and use of information
Security of information
Removal of certain personal information
A non-Federal entity sharing a cyber threat indicator pursuant to this subchapter shall, prior to such sharing—
review such cyber threat indicator to assess whether such cyber threat indicator contains any information not directly related to a cybersecurity threat that the non-Federal entity knows at the time of sharing to be personal information of a specific individual or information that identifies a specific individual and remove such information; or
implement and utilize a technical capability configured to remove any information not directly related to a cybersecurity threat that the non-Federal entity knows at the time of sharing to be personal information of a specific individual or information that identifies a specific individual.
Use of cyber threat indicators and defensive measures by non-Federal entities
In general
Consistent with this subchapter, a cyber threat indicator or defensive measure shared or received under this section may, for cybersecurity purposes—
be used by a non-Federal entity to monitor or operate a defensive measure that is applied to—
an information system of the non-Federal entity; or
an information system of another non-Federal entity or a Federal entity upon the written consent of that other non-Federal entity or that Federal entity; and
be otherwise used, retained, and further shared by a non-Federal entity subject to—
an otherwise lawful restriction placed by the sharing non-Federal entity or Federal entity on such cyber threat indicator or defensive measure; or
an otherwise applicable provision of law.
Construction
Use of cyber threat indicators by State, tribal, or local government
Law enforcement use
Exemption from disclosure
A cyber threat indicator or defensive measure shared by or with a State, tribal, or local government, including a component of a State, tribal, or local government that is a private entity, under this section shall be—
deemed voluntarily shared information; and
exempt from disclosure under any provision of State, tribal, or local freedom of information law, open government law, open meetings law, open records law, sunshine law, or similar law requiring disclosure of information or records.
State, tribal, and local regulatory authority
In general
Regulatory authority specifically relating to prevention or mitigation of cybersecurity threats
Antitrust exemption
In general
Applicability
Paragraph (1) shall apply only to information that is exchanged or assistance provided in order to assist with—
facilitating the prevention, investigation, or mitigation of a cybersecurity threat to an information system or information that is stored on, processed by, or transiting an information system; or
communicating or disclosing a cyber threat indicator to help prevent, investigate, or mitigate the effect of a cybersecurity threat to an information system or information that is stored on, processed by, or transiting an information system.