18 1 (2) REMOVAL OF CERTAIN PERSONAL INFORMA- 2 TION.—An 3 pursuant to this title shall, prior to such sharing— 4 (A) review such cyber threat indicator to 5 assess whether such cyber threat indicator con- 6 tains any information that the entity knows at 7 the time of sharing to be personal information 8 or information that identifies a specific person 9 not directly related to a cybersecurity threat 10 entity sharing a cyber threat indicator and remove such information; or 11 (B) implement and utilize a technical capa- 12 bility configured to remove any information 13 contained within such indicator that the entity 14 knows at the time of sharing to be personal in- 15 formation or information that identifies a spe- 16 cific person not directly related to a cybersecu- 17 rity threat. 18 (3) USE 19 OF CYBER THREAT INDICATORS AND DEFENSIVE MEASURES BY ENTITIES.— 20 (A) IN GENERAL.—Consistent with this 21 title, a cyber threat indicator or defensive meas- 22 ure shared or received under this section may, 23 for cybersecurity purposes— † S 754 ES

Select target paragraph3