H. R. 2029—718
(C) by redesignating subparagraph (E) as subparagraph (F); and
(D) by inserting after subparagraph (D) the following:
‘‘(E) an entity that collaborates with State and local
governments on cybersecurity risks and incidents, and has
entered into a voluntary information sharing relationship
with the Center; and’’;
(4) in subsection (e)—
(A) in paragraph (1)—
(i) in subparagraph (A), by inserting ‘‘cyber threat
indicators, defensive measures, and’’ before ‘‘information’’;
(ii) in subparagraph (B), by inserting ‘‘cyber threat
indicators, defensive measures, and’’ before ‘‘information related’’;
(iii) in subparagraph (F)—
(I) by striking ‘‘cybersecurity risks’’ and
inserting ‘‘cyber threat indicators, defensive measures, cybersecurity risks,’’; and
(II) by striking ‘‘and’’ at the end;
(iv) in subparagraph (G), by striking ‘‘cybersecurity
risks and incidents’’ and inserting ‘‘cyber threat indicators, defensive measures, cybersecurity risks, and
incidents; and’’; and
(v) by adding at the end the following:
‘‘(H) the Center designates an agency contact for nonFederal entities;’’;
(B) in paragraph (2)—
(i) by striking ‘‘cybersecurity risks’’ and inserting
‘‘cyber threat indicators, defensive measures, cybersecurity risks,’’; and
(ii) by inserting ‘‘or disclosure’’ after ‘‘access’’; and
(C) in paragraph (3), by inserting before the period
at the end the following: ‘‘, including by working with
the Privacy Officer appointed under section 222 to ensure
that the Center follows the policies and procedures specified
in subsections (b) and (d)(5)(C) of section 105 of the Cybersecurity Act of 2015’’; and
(5) by adding at the end the following:
‘‘(g) AUTOMATED INFORMATION SHARING.—
‘‘(1) IN GENERAL.—The Under Secretary appointed under
section 103(a)(1)(H), in coordination with industry and other
stakeholders, shall develop capabilities making use of existing
information technology industry standards and best practices,
as appropriate, that support and rapidly advance the development, adoption, and implementation of automated mechanisms
for the sharing of cyber threat indicators and defensive measures in accordance with title I of the Cybersecurity Act of
2015.
‘‘(2) ANNUAL REPORT.—The Under Secretary appointed
under section 103(a)(1)(H) shall submit to the Committee on
Homeland Security and Governmental Affairs of the Senate
and the Committee on Homeland Security of the House of
Representatives an annual report on the status and progress
of the development of the capabilities described in paragraph
(1). Such reports shall be required until such capabilities are
fully implemented.