H. R. 2029—703 (1) INTERIM POLICIES AND PROCEDURES.—Not later than 60 days after the date of the enactment of this Act, the Attorney General and the Secretary of Homeland Security shall, in consultation with the heads of the appropriate Federal entities, jointly develop and submit to Congress interim policies and procedures relating to the receipt of cyber threat indicators and defensive measures by the Federal Government. (2) FINAL POLICIES AND PROCEDURES.—Not later than 180 days after the date of the enactment of this Act, the Attorney General and the Secretary of Homeland Security shall, in consultation with the heads of the appropriate Federal entities, jointly issue and make publicly available final policies and procedures relating to the receipt of cyber threat indicators and defensive measures by the Federal Government. (3) REQUIREMENTS CONCERNING POLICIES AND PROCEDURES.—Consistent with the guidelines required by subsection (b), the policies and procedures developed or issued under this subsection shall— (A) ensure that cyber threat indicators shared with the Federal Government by any non-Federal entity pursuant to section 104(c) through the real-time process described in subsection (c) of this section— (i) are shared in an automated manner with all of the appropriate Federal entities; (ii) are only subject to a delay, modification, or other action due to controls established for such realtime process that could impede real-time receipt by all of the appropriate Federal entities when the delay, modification, or other action is due to controls— (I) agreed upon unanimously by all of the heads of the appropriate Federal entities; (II) carried out before any of the appropriate Federal entities retains or uses the cyber threat indicators or defensive measures; and (III) uniformly applied such that each of the appropriate Federal entities is subject to the same delay, modification, or other action; and (iii) may be provided to other Federal entities; (B) ensure that cyber threat indicators shared with the Federal Government by any non-Federal entity pursuant to section 104 in a manner other than the real-time process described in subsection (c) of this section— (i) are shared as quickly as operationally practicable with all of the appropriate Federal entities; (ii) are not subject to any unnecessary delay, interference, or any other action that could impede receipt by all of the appropriate Federal entities; and (iii) may be provided to other Federal entities; and (C) ensure there are— (i) audit capabilities; and (ii) appropriate sanctions in place for officers, employees, or agents of a Federal entity who knowingly and willfully conduct activities under this title in an unauthorized manner. (4) GUIDELINES FOR ENTITIES SHARING CYBER THREAT INDICATORS WITH FEDERAL GOVERNMENT.—

Select target paragraph3