H. R. 2029—700
(1) IN GENERAL.—Notwithstanding any other provision of
law, a private entity may, for cybersecurity purposes, monitor—
(A) an information system of such private entity;
(B) an information system of another non-Federal
entity, upon the authorization and written consent of such
other entity;
(C) an information system of a Federal entity, upon
the authorization and written consent of an authorized
representative of the Federal entity; and
(D) information that is stored on, processed by, or
transiting an information system monitored by the private
entity under this paragraph.
(2) CONSTRUCTION.—Nothing in this subsection shall be
construed—
(A) to authorize the monitoring of an information
system, or the use of any information obtained through
such monitoring, other than as provided in this title; or
(B) to limit otherwise lawful activity.
(b) AUTHORIZATION FOR OPERATION OF DEFENSIVE MEASURES.—
(1) IN GENERAL.—Notwithstanding any other provision of
law, a private entity may, for cybersecurity purposes, operate
a defensive measure that is applied to—
(A) an information system of such private entity in
order to protect the rights or property of the private entity;
(B) an information system of another non-Federal
entity upon written consent of such entity for operation
of such defensive measure to protect the rights or property
of such entity; and
(C) an information system of a Federal entity upon
written consent of an authorized representative of such
Federal entity for operation of such defensive measure
to protect the rights or property of the Federal Government.
(2) CONSTRUCTION.—Nothing in this subsection shall be
construed—
(A) to authorize the use of a defensive measure other
than as provided in this subsection; or
(B) to limit otherwise lawful activity.
(c) AUTHORIZATION FOR SHARING OR RECEIVING CYBER THREAT
INDICATORS OR DEFENSIVE MEASURES.—
(1) IN GENERAL.—Except as provided in paragraph (2) and
notwithstanding any other provision of law, a non-Federal
entity may, for a cybersecurity purpose and consistent with
the protection of classified information, share with, or receive
from, any other non-Federal entity or the Federal Government
a cyber threat indicator or defensive measure.
(2) LAWFUL RESTRICTION.—A non-Federal entity receiving
a cyber threat indicator or defensive measure from another
non-Federal entity or a Federal entity shall comply with otherwise lawful restrictions placed on the sharing or use of such
cyber threat indicator or defensive measure by the sharing
non-Federal entity or Federal entity.
(3) CONSTRUCTION.—Nothing in this subsection shall be
construed—
(A) to authorize the sharing or receiving of a cyber
threat indicator or defensive measure other than as provided in this subsection; or
(B) to limit otherwise lawful activity.