6
1
(E) malicious cyber command and control;
2
(F) the actual or potential harm caused by
3
an incident, including a description of the infor-
4
mation exfiltrated as a result of a particular cy-
5
bersecurity threat;
6
(G) any other attribute of a cybersecurity
7
threat, if disclosure of such attribute is not oth-
8
erwise prohibited by law; or
9
(H) any combination thereof.
10
(7) DEFENSIVE
11
(A) IN
MEASURE.—
GENERAL.—Except
as provided in
12
subparagraph (B), the term ‘‘defensive meas-
13
ure’’ means an action, device, procedure, signa-
14
ture, technique, or other measure applied to an
15
information system or information that is
16
stored on, processed by, or transiting an infor-
17
mation system that detects, prevents, or miti-
18
gates a known or suspected cybersecurity threat
19
or security vulnerability.
20
(B) EXCLUSION.—The term ‘‘defensive
21
measure’’ does not include a measure that de-
22
stroys, renders unusable, provides unauthorized
23
access to, or substantially harms an information
24
system or data on an information system not
25
belonging to—
† S 754 ES