18
1
(2) REMOVAL
OF CERTAIN PERSONAL INFORMA-
2
TION.—An
3
pursuant to this title shall, prior to such sharing—
4
(A) review such cyber threat indicator to
5
assess whether such cyber threat indicator con-
6
tains any information that the entity knows at
7
the time of sharing to be personal information
8
or information that identifies a specific person
9
not directly related to a cybersecurity threat
10
entity sharing a cyber threat indicator
and remove such information; or
11
(B) implement and utilize a technical capa-
12
bility configured to remove any information
13
contained within such indicator that the entity
14
knows at the time of sharing to be personal in-
15
formation or information that identifies a spe-
16
cific person not directly related to a cybersecu-
17
rity threat.
18
(3) USE
19
OF CYBER THREAT INDICATORS AND
DEFENSIVE MEASURES BY ENTITIES.—
20
(A) IN
GENERAL.—Consistent
with this
21
title, a cyber threat indicator or defensive meas-
22
ure shared or received under this section may,
23
for cybersecurity purposes—
† S 754 ES