H. R. 2029—711
(1) IN GENERAL.—Not later than 2 years after the date
of the enactment of this Act and not less frequently than
once every 2 years thereafter, the inspectors general of the
appropriate Federal entities, in consultation with the Inspector
General of the Intelligence Community and the Council of
Inspectors General on Financial Oversight, shall jointly submit
to Congress an interagency report on the actions of the executive branch of the Federal Government to carry out this title
during the most recent 2-year period.
(2) CONTENTS.—Each report submitted under paragraph
(1) shall include, for the period covered by the report, the
following:
(A) An assessment of the sufficiency of the policies,
procedures, and guidelines relating to the sharing of cyber
threat indicators within the Federal Government, including
those policies, procedures, and guidelines relating to the
removal of information not directly related to a cybersecurity threat that is personal information of a specific individual or information that identifies a specific individual.
(B) An assessment of whether cyber threat indicators
or defensive measures have been properly classified and
an accounting of the number of security clearances authorized by the Federal Government for the purpose of sharing
cyber threat indicators or defensive measures with the
private sector.
(C) A review of the actions taken by the Federal
Government based on cyber threat indicators or defensive
measures shared with the Federal Government under this
title, including a review of the following:
(i) The appropriateness of subsequent uses and
disseminations of cyber threat indicators or defensive
measures.
(ii) Whether cyber threat indicators or defensive
measures were shared in a timely and adequate
manner with appropriate entities, or, if appropriate,
were made publicly available.
(D) An assessment of the cyber threat indicators or
defensive measures shared with the appropriate Federal
entities under this title, including the following:
(i) The number of cyber threat indicators or defensive measures shared through the capability and
process developed under section 105(c).
(ii) An assessment of any information not directly
related to a cybersecurity threat that is personal
information of a specific individual or information
identifying a specific individual and was shared by
a non-Federal government entity with the Federal
government in contravention of this title, or was shared
within the Federal Government in contravention of
the guidelines required by this title, including a
description of any significant violation of this title.
(iii) The number of times, according to the Attorney
General, that information shared under this title was
used by a Federal entity to prosecute an offense listed
in section 105(d)(5)(A).
(iv) A quantitative and qualitative assessment of
the effect of the sharing of cyber threat indicators