H. R. 2029—707
may designate an appropriate Federal entity, other
than the Department of Defense (including the
National Security Agency), to develop and implement
a capability and process as described in paragraph
(1) in addition to the capability and process developed
under such paragraph by the Secretary of Homeland
Security, if, not fewer than 30 days before making
such designation, the President submits to Congress
a certification and explanation that—
(I) such designation is necessary to ensure
that full, effective, and secure operation of a capability and process for the Federal Government to
receive from any non-Federal entity cyber threat
indicators or defensive measures under this title;
(II) the designated appropriate Federal entity
will receive and share cyber threat indicators and
defensive measures in accordance with the policies,
procedures, and guidelines developed under this
title, including subsection (a)(3)(A); and
(III) such designation is consistent with the
mission of such appropriate Federal entity and
improves the ability of the Federal Government
to receive, share, and use cyber threat indicators
and defensive measures as authorized under this
title.
(ii) APPLICATION TO ADDITIONAL CAPABILITY AND
PROCESS.—If the President designates an appropriate
Federal entity to develop and implement a capability
and process under clause (i), the provisions of this
title that apply to the capability and process required
by paragraph (1) shall also be construed to apply to
the capability and process developed and implemented
under clause (i).
(3) PUBLIC NOTICE AND ACCESS.—The Secretary of Homeland Security shall ensure there is public notice of, and access
to, the capability and process developed and implemented under
paragraph (1) so that—
(A) any non-Federal entity may share cyber threat
indicators and defensive measures through such process
with the Federal Government; and
(B) all of the appropriate Federal entities receive such
cyber threat indicators and defensive measures in real
time with receipt through the process within the Department of Homeland Security consistent with the policies
and procedures issued under subsection (a).
(4) OTHER FEDERAL ENTITIES.—The process developed and
implemented under paragraph (1) shall ensure that other Federal entities receive in a timely manner any cyber threat indicators and defensive measures shared with the Federal Government through such process.
(d) INFORMATION SHARED WITH OR PROVIDED TO THE FEDERAL
GOVERNMENT.—
(1) NO WAIVER OF PRIVILEGE OR PROTECTION.—The provision of cyber threat indicators and defensive measures to the
Federal Government under this title shall not constitute a
waiver of any applicable privilege or protection provided by
law, including trade secret protection.