H. R. 2029—701
(d) PROTECTION AND USE OF INFORMATION.—
(1) SECURITY OF INFORMATION.—A non-Federal entity monitoring an information system, operating a defensive measure,
or providing or receiving a cyber threat indicator or defensive
measure under this section shall implement and utilize a security control to protect against unauthorized access to or acquisition of such cyber threat indicator or defensive measure.
(2) REMOVAL OF CERTAIN PERSONAL INFORMATION.—A nonFederal entity sharing a cyber threat indicator pursuant to
this title shall, prior to such sharing—
(A) review such cyber threat indicator to assess
whether such cyber threat indicator contains any information not directly related to a cybersecurity threat that
the non-Federal entity knows at the time of sharing to
be personal information of a specific individual or information that identifies a specific individual and remove such
information; or
(B) implement and utilize a technical capability configured to remove any information not directly related to
a cybersecurity threat that the non-Federal entity knows
at the time of sharing to be personal information of a
specific individual or information that identifies a specific
individual.
(3) USE OF CYBER THREAT INDICATORS AND DEFENSIVE MEASURES BY NON-FEDERAL ENTITIES.—
(A) IN GENERAL.—Consistent with this title, a cyber
threat indicator or defensive measure shared or received
under this section may, for cybersecurity purposes—
(i) be used by a non-Federal entity to monitor
or operate a defensive measure that is applied to—
(I) an information system of the non-Federal
entity; or
(II) an information system of another nonFederal entity or a Federal entity upon the written
consent of that other non-Federal entity or that
Federal entity; and
(ii) be otherwise used, retained, and further shared
by a non-Federal entity subject to—
(I) an otherwise lawful restriction placed by
the sharing non-Federal entity or Federal entity
on such cyber threat indicator or defensive
measure; or
(II) an otherwise applicable provision of law.
(B) CONSTRUCTION.—Nothing in this paragraph shall
be construed to authorize the use of a cyber threat indicator
or defensive measure other than as provided in this section.
(4) USE OF CYBER THREAT INDICATORS BY STATE, TRIBAL,
OR LOCAL GOVERNMENT.—
(A) LAW ENFORCEMENT USE.—A State, tribal, or local
government that receives a cyber threat indicator or defensive measure under this title may use such cyber threat
indicator or defensive measure for the purposes described
in section 105(d)(5)(A).
(B) EXEMPTION FROM DISCLOSURE.—A cyber threat
indicator or defensive measure shared by or with a State,
tribal, or local government, including a component of a