Policy Directive-1 of February 13, 2009 (Organization of the National Security Council
System), or any successor.
Sec. 4. Cybersecurity Information Sharing. (a) It is the policy of the United States
Government to increase the volume, timeliness, and quality of cyber threat information
shared with U.S. private sector entities so that these entities may better protect and
defend themselves against cyber threats. Within 120 days of the date of this order, the
Attorney General, the Secretary of Homeland Security (the "Secretary"), and the Director
of National Intelligence shall each issue instructions consistent with their authorities and
with the requirements of section 12(c) of this order to ensure the timely production of
unclassified reports of cyber threats to the U.S. homeland that identify a specific targeted
entity. The instructions shall address the need to protect intelligence and law enforcement
sources, methods, operations, and investigations.
(b) The Secretary and the Attorney General, in coordination with the Director of National
Intelligence, shall establish a process that rapidly disseminates the reports produced
pursuant to section 4(a) of this order to the targeted entity. Such process shall also,
consistent with the need to protect national security information, include the
dissemination of classified reports to critical infrastructure entities authorized to receive
them. The Secretary and the Attorney General, in coordination with the Director of
National Intelligence, shall establish a system for tracking the production, dissemination,
and disposition of these reports.
(c) To assist the owners and operators of critical infrastructure in protecting their systems
from unauthorized access, exploitation, or harm, the Secretary, consistent with 6 U.S.C.
143 and in collaboration with the Secretary of Defense, shall, within 120 days of the date
of this order, establish procedures to expand the Enhanced Cybersecurity Services
program to all critical infrastructure sectors. This voluntary information sharing program
will provide classified cyber threat and technical information from the Government to
eligible critical infrastructure companies or commercial service providers that offer
security services to critical infrastructure.
(d) The Secretary, as the Executive Agent for the Classified National Security Information
Program created under Executive Order 13549 of August 18, 2010 (Classified National
Security Information Program for State, Local, Tribal, and Private Sector Entities), shall
expedite the processing of security clearances to appropriate personnel employed by
critical infrastructure owners and operators, prioritizing the critical infrastructure
identified in section 9 of this order.
(e) In order to maximize the utility of cyber threat information sharing with the private
sector, the Secretary shall expand the use of programs that bring private sector subjectmatter experts into Federal service on a temporary basis. These subject matter experts
should provide advice regarding the content, structure, and types of information most
useful to critical infrastructure owners and operators in reducing and mitigating cyber
risks.
2/8