H. R. 2029—706
(A) shall accept from any non-Federal entity in real
time cyber threat indicators and defensive measures, pursuant to this section;
(B) shall, upon submittal of the certification under
paragraph (2) that such capability and process fully and
effectively operates as described in such paragraph, be
the process by which the Federal Government receives
cyber threat indicators and defensive measures under this
title that are shared by a non-Federal entity with the
Federal Government through electronic mail or media, an
interactive form on an Internet website, or a real time,
automated process between information systems except—
(i) consistent with section 104, communications
between a Federal entity and a non-Federal entity
regarding a previously shared cyber threat indicator
to describe the relevant cybersecurity threat or develop
a defensive measure based on such cyber threat indicator; and
(ii) communications by a regulated non-Federal
entity with such entity’s Federal regulatory authority
regarding a cybersecurity threat;
(C) ensures that all of the appropriate Federal entities
receive in an automated manner such cyber threat indicators and defensive measures shared through the real-time
process within the Department of Homeland Security;
(D) is in compliance with the policies, procedures, and
guidelines required by this section; and
(E) does not limit or prohibit otherwise lawful disclosures of communications, records, or other information,
including—
(i) reporting of known or suspected criminal
activity, by a non-Federal entity to any other nonFederal entity or a Federal entity, including cyber
threat indicators or defensive measures shared with
a Federal entity in furtherance of opening a Federal
law enforcement investigation;
(ii) voluntary or legally compelled participation in
a Federal investigation; and
(iii) providing cyber threat indicators or defensive
measures as part of a statutory or authorized contractual requirement.
(2) CERTIFICATION AND DESIGNATION.—
(A) CERTIFICATION OF CAPABILITY AND PROCESS.—Not
later than 90 days after the date of the enactment of
this Act, the Secretary of Homeland Security shall, in consultation with the heads of the appropriate Federal entities,
submit to Congress a certification as to whether the capability and process required by paragraph (1) fully and effectively operates—
(i) as the process by which the Federal Government
receives from any non-Federal entity a cyber threat
indicator or defensive measure under this title; and
(ii) in accordance with the interim policies, procedures, and guidelines developed under this title.
(B) DESIGNATION.—
(i) IN GENERAL.—At any time after certification
is submitted under subparagraph (A), the President