H. R. 2029—703
(1) INTERIM POLICIES AND PROCEDURES.—Not later than
60 days after the date of the enactment of this Act, the Attorney
General and the Secretary of Homeland Security shall, in consultation with the heads of the appropriate Federal entities,
jointly develop and submit to Congress interim policies and
procedures relating to the receipt of cyber threat indicators
and defensive measures by the Federal Government.
(2) FINAL POLICIES AND PROCEDURES.—Not later than 180
days after the date of the enactment of this Act, the Attorney
General and the Secretary of Homeland Security shall, in consultation with the heads of the appropriate Federal entities,
jointly issue and make publicly available final policies and
procedures relating to the receipt of cyber threat indicators
and defensive measures by the Federal Government.
(3) REQUIREMENTS CONCERNING POLICIES AND PROCEDURES.—Consistent with the guidelines required by subsection
(b), the policies and procedures developed or issued under this
subsection shall—
(A) ensure that cyber threat indicators shared with
the Federal Government by any non-Federal entity pursuant to section 104(c) through the real-time process
described in subsection (c) of this section—
(i) are shared in an automated manner with all
of the appropriate Federal entities;
(ii) are only subject to a delay, modification, or
other action due to controls established for such realtime process that could impede real-time receipt by
all of the appropriate Federal entities when the delay,
modification, or other action is due to controls—
(I) agreed upon unanimously by all of the
heads of the appropriate Federal entities;
(II) carried out before any of the appropriate
Federal entities retains or uses the cyber threat
indicators or defensive measures; and
(III) uniformly applied such that each of the
appropriate Federal entities is subject to the same
delay, modification, or other action; and
(iii) may be provided to other Federal entities;
(B) ensure that cyber threat indicators shared with
the Federal Government by any non-Federal entity pursuant to section 104 in a manner other than the real-time
process described in subsection (c) of this section—
(i) are shared as quickly as operationally practicable with all of the appropriate Federal entities;
(ii) are not subject to any unnecessary delay, interference, or any other action that could impede receipt
by all of the appropriate Federal entities; and
(iii) may be provided to other Federal entities;
and
(C) ensure there are—
(i) audit capabilities; and
(ii) appropriate sanctions in place for officers,
employees, or agents of a Federal entity who knowingly
and willfully conduct activities under this title in an
unauthorized manner.
(4) GUIDELINES FOR ENTITIES SHARING CYBER THREAT
INDICATORS WITH FEDERAL GOVERNMENT.—