H. R. 2029—719
‘‘(h) VOLUNTARY INFORMATION SHARING PROCEDURES.—
‘‘(1) PROCEDURES.—
‘‘(A) IN GENERAL.—The Center may enter into a voluntary information sharing relationship with any consenting non-Federal entity for the sharing of cyber threat
indicators and defensive measures for cybersecurity purposes in accordance with this section. Nothing in this subsection may be construed to require any non-Federal entity
to enter into any such information sharing relationship
with the Center or any other entity. The Center may terminate a voluntary information sharing relationship under
this subsection, at the sole and unreviewable discretion
of the Secretary, acting through the Under Secretary
appointed under section 103(a)(1)(H), for any reason,
including if the Center determines that the non-Federal
entity with which the Center has entered into such a
relationship has violated the terms of this subsection.
‘‘(B) NATIONAL SECURITY.—The Secretary may decline
to enter into a voluntary information sharing relationship
under this subsection, at the sole and unreviewable discretion of the Secretary, acting through the Under Secretary
appointed under section 103(a)(1)(H), for any reason,
including if the Secretary determines that such is appropriate for national security.
‘‘(2) VOLUNTARY INFORMATION SHARING RELATIONSHIPS.—
A voluntary information sharing relationship under this subsection may be characterized as an agreement described in
this paragraph.
‘‘(A) STANDARD AGREEMENT.—For the use of a nonFederal entity, the Center shall make available a standard
agreement, consistent with this section, on the Department’s website.
‘‘(B) NEGOTIATED AGREEMENT.—At the request of a nonFederal entity, and if determined appropriate by the
Center, at the sole and unreviewable discretion of the Secretary, acting through the Under Secretary appointed
under section 103(a)(1)(H), the Department shall negotiate
a non-standard agreement, consistent with this section.
‘‘(C) EXISTING AGREEMENTS.—An agreement between
the Center and a non-Federal entity that is entered into
before the date of enactment of this subsection, or such
an agreement that is in effect before such date, shall be
deemed in compliance with the requirements of this subsection, notwithstanding any other provision or requirement of this subsection. An agreement under this subsection shall include the relevant privacy protections as
in effect under the Cooperative Research and Development
Agreement for Cybersecurity Information Sharing and
Collaboration, as of December 31, 2014. Nothing in this
subsection may be construed to require a non-Federal entity
to enter into either a standard or negotiated agreement
to be in compliance with this subsection.
‘‘(i) DIRECT REPORTING.—The Secretary shall develop policies
and procedures for direct reporting to the Secretary by the Director
of the Center regarding significant cybersecurity risks and incidents.