H. R. 2029—705
every 2 years, jointly review the guidelines issued under
subparagraph (A).
(3) CONTENT.—The guidelines required by paragraphs (1)
and (2) shall, consistent with the need to protect information
systems from cybersecurity threats and mitigate cybersecurity
threats—
(A) limit the effect on privacy and civil liberties of
activities by the Federal Government under this title;
(B) limit the receipt, retention, use, and dissemination
of cyber threat indicators containing personal information
of specific individuals or information that identifies specific
individuals, including by establishing—
(i) a process for the timely destruction of such
information that is known not to be directly related
to uses authorized under this title; and
(ii) specific limitations on the length of any period
in which a cyber threat indicator may be retained;
(C) include requirements to safeguard cyber threat
indicators containing personal information of specific
individuals or information that identifies specific individuals from unauthorized access or acquisition, including
appropriate sanctions for activities by officers, employees,
or agents of the Federal Government in contravention of
such guidelines;
(D) consistent with this title, any other applicable
provisions of law, and the fair information practice principles set forth in appendix A of the document entitled
‘‘National Strategy for Trusted Identities in Cyberspace’’
and published by the President in April 2011, govern the
retention, use, and dissemination by the Federal Government of cyber threat indicators shared with the Federal
Government under this title, including the extent, if any,
to which such cyber threat indicators may be used by
the Federal Government;
(E) include procedures for notifying entities and Federal entities if information received pursuant to this section
is known or determined by a Federal entity receiving such
information not to constitute a cyber threat indicator;
(F) protect the confidentiality of cyber threat indicators
containing personal information of specific individuals or
information that identifies specific individuals to the
greatest extent practicable and require recipients to be
informed that such indicators may only be used for purposes authorized under this title; and
(G) include steps that may be needed so that dissemination of cyber threat indicators is consistent with the
protection of classified and other sensitive national security
information.
(c) CAPABILITY AND PROCESS WITHIN THE DEPARTMENT OF
HOMELAND SECURITY.—
(1) IN GENERAL.—Not later than 90 days after the date
of the enactment of this Act, the Secretary of Homeland Security, in coordination with the heads of the appropriate Federal
entities, shall develop and implement a capability and process
within the Department of Homeland Security that—