H. R. 2029—704
(A) IN GENERAL.—Not later than 60 days after the
date of the enactment of this Act, the Attorney General
and the Secretary of Homeland Security shall jointly
develop and make publicly available guidance to assist
entities and promote sharing of cyber threat indicators
with Federal entities under this title.
(B) CONTENTS.—The guidelines developed and made
publicly available under subparagraph (A) shall include
guidance on the following:
(i) Identification of types of information that would
qualify as a cyber threat indicator under this title
that would be unlikely to include information that—
(I) is not directly related to a cybersecurity
threat; and
(II) is personal information of a specific individual or information that identifies a specific individual.
(ii) Identification of types of information protected
under otherwise applicable privacy laws that are
unlikely to be directly related to a cybersecurity threat.
(iii) Such other matters as the Attorney General
and the Secretary of Homeland Security consider
appropriate for entities sharing cyber threat indicators
with Federal entities under this title.
(b) PRIVACY AND CIVIL LIBERTIES.—
(1) INTERIM GUIDELINES.—Not later than 60 days after
the date of the enactment of this Act, the Attorney General
and the Secretary of Homeland Security shall, in consultation
with heads of the appropriate Federal entities and in consultation with officers designated under section 1062 of the National
Security Intelligence Reform Act of 2004 (42 U.S.C. 2000ee–
1), jointly develop, submit to Congress, and make available
to the public interim guidelines relating to privacy and civil
liberties which shall govern the receipt, retention, use, and
dissemination of cyber threat indicators by a Federal entity
obtained in connection with activities authorized in this title.
(2) FINAL GUIDELINES.—
(A) IN GENERAL.—Not later than 180 days after the
date of the enactment of this Act, the Attorney General
and the Secretary of Homeland Security shall, in coordination with heads of the appropriate Federal entities and
in consultation with officers designated under section 1062
of the National Security Intelligence Reform Act of 2004
(42 U.S.C. 2000ee–1) and such private entities with
industry expertise as the Attorney General and the Secretary consider relevant, jointly issue and make publicly
available final guidelines relating to privacy and civil liberties which shall govern the receipt, retention, use, and
dissemination of cyber threat indicators by a Federal entity
obtained in connection with activities authorized in this
title.
(B) PERIODIC REVIEW.—The Attorney General and the
Secretary of Homeland Security shall, in coordination with
heads of the appropriate Federal entities and in consultation with officers and private entities described in subparagraph (A), periodically, but not less frequently than once