H. R. 2029—710
of an information system and information under section 104(a)
that is conducted in accordance with this title.
(b) SHARING OR RECEIPT OF CYBER THREAT INDICATORS.—No
cause of action shall lie or be maintained in any court against
any private entity, and such action shall be promptly dismissed,
for the sharing or receipt of a cyber threat indicator or defensive
measure under section 104(c) if—
(1) such sharing or receipt is conducted in accordance with
this title; and
(2) in a case in which a cyber threat indicator or defensive
measure is shared with the Federal Government, the cyber
threat indicator or defensive measure is shared in a manner
that is consistent with section 105(c)(1)(B) and the sharing
or receipt, as the case may be, occurs after the earlier of—
(A) the date on which the interim policies and procedures are submitted to Congress under section 105(a)(1)
and guidelines are submitted to Congress under section
105(b)(1); or
(B) the date that is 60 days after the date of the
enactment of this Act.
(c) CONSTRUCTION.—Nothing in this title shall be construed—
(1) to create—
(A) a duty to share a cyber threat indicator or defensive
measure; or
(B) a duty to warn or act based on the receipt of
a cyber threat indicator or defensive measure; or
(2) to undermine or limit the availability of otherwise
applicable common law or statutory defenses.
SEC. 107. OVERSIGHT OF GOVERNMENT ACTIVITIES.
(a) REPORT ON IMPLEMENTATION.—
(1) IN GENERAL.—Not later than 1 year after the date
of the enactment of this title, the heads of the appropriate
Federal entities shall jointly submit to Congress a detailed
report concerning the implementation of this title.
(2) CONTENTS.—The report required by paragraph (1) may
include such recommendations as the heads of the appropriate
Federal entities may have for improvements or modifications
to the authorities, policies, procedures, and guidelines under
this title and shall include the following:
(A) An evaluation of the effectiveness of real-time
information sharing through the capability and process
developed under section 105(c), including any impediments
to such real-time sharing.
(B) An assessment of whether cyber threat indicators
or defensive measures have been properly classified and
an accounting of the number of security clearances authorized by the Federal Government for the purpose of sharing
cyber threat indicators or defensive measures with the
private sector.
(C) The number of cyber threat indicators or defensive
measures received through the capability and process
developed under section 105(c).
(D) A list of Federal entities that have received cyber
threat indicators or defensive measures under this title.
(b) BIENNIAL REPORT ON COMPLIANCE.—