H. R. 2029—698
(16) SECURITY CONTROL.—The term ‘‘security control’’
means the management, operational, and technical controls
used to protect against an unauthorized effort to adversely
affect the confidentiality, integrity, and availability of an
information system or its information.
(17) SECURITY VULNERABILITY.—The term ‘‘security vulnerability’’ means any attribute of hardware, software, process,
or procedure that could enable or facilitate the defeat of a
security control.
(18) TRIBAL.—The term ‘‘tribal’’ has the meaning given
the term ‘‘Indian tribe’’ in section 4 of the Indian Self-Determination and Education Assistance Act (25 U.S.C. 450b).
SEC. 103. SHARING OF INFORMATION BY THE FEDERAL GOVERNMENT.
(a) IN GENERAL.—Consistent with the protection of classified
information, intelligence sources and methods, and privacy and
civil liberties, the Director of National Intelligence, the Secretary
of Homeland Security, the Secretary of Defense, and the Attorney
General, in consultation with the heads of the appropriate Federal
entities, shall jointly develop and issue procedures to facilitate
and promote—
(1) the timely sharing of classified cyber threat indicators
and defensive measures in the possession of the Federal
Government with representatives of relevant Federal entities
and non-Federal entities that have appropriate security clearances;
(2) the timely sharing with relevant Federal entities and
non-Federal entities of cyber threat indicators, defensive measures, and information relating to cybersecurity threats or
authorized uses under this title, in the possession of the Federal
Government that may be declassified and shared at an unclassified level;
(3) the timely sharing with relevant Federal entities and
non-Federal entities, or the public if appropriate, of unclassified,
including controlled unclassified, cyber threat indicators and
defensive measures in the possession of the Federal Government;
(4) the timely sharing with Federal entities and non-Federal entities, if appropriate, of information relating to cybersecurity threats or authorized uses under this title, in the possession
of the Federal Government about cybersecurity threats to such
entities to prevent or mitigate adverse effects from such cybersecurity threats; and
(5) the periodic sharing, through publication and targeted
outreach, of cybersecurity best practices that are developed
based on ongoing analyses of cyber threat indicators, defensive
measures, and information relating to cybersecurity threats
or authorized uses under this title, in the possession of the
Federal Government, with attention to accessibility and
implementation challenges faced by small business concerns
(as defined in section 3 of the Small Business Act (15 U.S.C.
632)).
(b) DEVELOPMENT OF PROCEDURES.—
(1) IN GENERAL.—The procedures developed under subsection (a) shall—
(A) ensure the Federal Government has and maintains
the capability to share cyber threat indicators and defensive