6 1 (E) malicious cyber command and control; 2 (F) the actual or potential harm caused by 3 an incident, including a description of the infor- 4 mation exfiltrated as a result of a particular cy- 5 bersecurity threat; 6 (G) any other attribute of a cybersecurity 7 threat, if disclosure of such attribute is not oth- 8 erwise prohibited by law; or 9 (H) any combination thereof. 10 (7) DEFENSIVE 11 (A) IN MEASURE.— GENERAL.—Except as provided in 12 subparagraph (B), the term ‘‘defensive meas- 13 ure’’ means an action, device, procedure, signa- 14 ture, technique, or other measure applied to an 15 information system or information that is 16 stored on, processed by, or transiting an infor- 17 mation system that detects, prevents, or miti- 18 gates a known or suspected cybersecurity threat 19 or security vulnerability. 20 (B) EXCLUSION.—The term ‘‘defensive 21 measure’’ does not include a measure that de- 22 stroys, renders unusable, provides unauthorized 23 access to, or substantially harms an information 24 system or data on an information system not 25 belonging to— † S 754 ES

Select target paragraph3