H. R. 2029—732 ‘‘(A) in coordination with the Director, and in consultation with Federal contractors as appropriate, establish procedures governing the circumstances under which a directive may be issued under this subsection, which shall include— ‘‘(i) thresholds and other criteria; ‘‘(ii) privacy and civil liberties protections; and ‘‘(iii) providing notice to potentially affected third parties; ‘‘(B) specify the reasons for the required action and the duration of the directive; ‘‘(C) minimize the impact of a directive under this subsection by— ‘‘(i) adopting the least intrusive means possible under the circumstances to secure the agency information systems; and ‘‘(ii) limiting directives to the shortest period practicable; ‘‘(D) notify the Director and the head of any affected agency immediately upon the issuance of a directive under this subsection; ‘‘(E) consult with the Director of the National Institute of Standards and Technology regarding any directive under this subsection that implements standards and guidelines developed by the National Institute of Standards and Technology; ‘‘(F) ensure that directives issued under this subsection do not conflict with the standards and guidelines issued under section 11331 of title 40; ‘‘(G) consider any applicable standards or guidelines developed by the National Institute of Standards and Technology issued by the Secretary of Commerce under section 11331 of title 40; and ‘‘(H) not later than February 1 of each year, submit to the appropriate congressional committees a report regarding the specific actions the Secretary has taken pursuant to paragraph (1)(A). ‘‘(3) IMMINENT THREATS.— ‘‘(A) IN GENERAL.—Notwithstanding section 3554, the Secretary may authorize the use under this subsection of the intrusion detection and prevention capabilities established under section 230(b)(1) of the Homeland Security Act of 2002 for the purpose of ensuring the security of agency information systems, if— ‘‘(i) the Secretary determines there is an imminent threat to agency information systems; ‘‘(ii) the Secretary determines a directive under subsection (b)(2)(C) or paragraph (1)(A) is not reasonably likely to result in a timely response to the threat; ‘‘(iii) the Secretary determines the risk posed by the imminent threat outweighs any adverse consequences reasonably expected to result from the use of the intrusion detection and prevention capabilities under the control of the Secretary; ‘‘(iv) the Secretary provides prior notice to the Director, and the head and chief information officer (or equivalent official) of each agency to which specific

Select target paragraph3