H. R. 2029—700 (1) IN GENERAL.—Notwithstanding any other provision of law, a private entity may, for cybersecurity purposes, monitor— (A) an information system of such private entity; (B) an information system of another non-Federal entity, upon the authorization and written consent of such other entity; (C) an information system of a Federal entity, upon the authorization and written consent of an authorized representative of the Federal entity; and (D) information that is stored on, processed by, or transiting an information system monitored by the private entity under this paragraph. (2) CONSTRUCTION.—Nothing in this subsection shall be construed— (A) to authorize the monitoring of an information system, or the use of any information obtained through such monitoring, other than as provided in this title; or (B) to limit otherwise lawful activity. (b) AUTHORIZATION FOR OPERATION OF DEFENSIVE MEASURES.— (1) IN GENERAL.—Notwithstanding any other provision of law, a private entity may, for cybersecurity purposes, operate a defensive measure that is applied to— (A) an information system of such private entity in order to protect the rights or property of the private entity; (B) an information system of another non-Federal entity upon written consent of such entity for operation of such defensive measure to protect the rights or property of such entity; and (C) an information system of a Federal entity upon written consent of an authorized representative of such Federal entity for operation of such defensive measure to protect the rights or property of the Federal Government. (2) CONSTRUCTION.—Nothing in this subsection shall be construed— (A) to authorize the use of a defensive measure other than as provided in this subsection; or (B) to limit otherwise lawful activity. (c) AUTHORIZATION FOR SHARING OR RECEIVING CYBER THREAT INDICATORS OR DEFENSIVE MEASURES.— (1) IN GENERAL.—Except as provided in paragraph (2) and notwithstanding any other provision of law, a non-Federal entity may, for a cybersecurity purpose and consistent with the protection of classified information, share with, or receive from, any other non-Federal entity or the Federal Government a cyber threat indicator or defensive measure. (2) LAWFUL RESTRICTION.—A non-Federal entity receiving a cyber threat indicator or defensive measure from another non-Federal entity or a Federal entity shall comply with otherwise lawful restrictions placed on the sharing or use of such cyber threat indicator or defensive measure by the sharing non-Federal entity or Federal entity. (3) CONSTRUCTION.—Nothing in this subsection shall be construed— (A) to authorize the sharing or receiving of a cyber threat indicator or defensive measure other than as provided in this subsection; or (B) to limit otherwise lawful activity.

Select target paragraph3