62 1 ‘‘(6) shall periodically update the privacy im- 2 pact assessment required under section 208(b) of 3 the E-Government Act of 2002 (44 U.S.C. 3501 4 note); and 5 ‘‘(7) shall ensure that— 6 ‘‘(A) activities carried out under this sec- 7 tion are reasonably necessary for the purpose of 8 protecting agency information and agency infor- 9 mation systems from a cybersecurity risk; 10 ‘‘(B) information accessed by the Secretary 11 will be retained no longer than reasonably nec- 12 essary for the purpose of protecting agency in- 13 formation and agency information systems from 14 a cybersecurity risk; 15 ‘‘(C) notice has been provided to users of 16 an agency information system concerning access 17 to communications of users of the agency infor- 18 mation system for the purpose of protecting 19 agency information and the agency information 20 system; and 21 ‘‘(D) the activities are implemented pursu- 22 ant to policies and procedures governing the op- 23 eration of the intrusion detection and preven- 24 tion capabilities. 25 ‘‘(d) PRIVATE ENTITIES.— † S 754 ES

Select target paragraph3