17 1 mation, share with, or receive from, any other entity 2 or the Federal Government a cyber threat indicator 3 or defensive measure. 4 (2) LAWFUL RESTRICTION.—An entity receiving 5 a cyber threat indicator or defensive measure from 6 another entity or Federal entity shall comply with 7 otherwise lawful restrictions placed on the sharing or 8 use of such cyber threat indicator or defensive meas- 9 ure by the sharing entity or Federal entity. 10 11 (3) CONSTRUCTION.—Nothing in this subsection shall be construed— 12 (A) to authorize the sharing or receiving of 13 a cyber threat indicator or defensive measure 14 other than as provided in this subsection; or 15 (B) to limit otherwise lawful activity. 16 (d) PROTECTION AND USE OF INFORMATION.— 17 (1) SECURITY OF INFORMATION.—An entity 18 monitoring an information system, operating a de- 19 fensive measure, or providing or receiving a cyber 20 threat indicator or defensive measure under this sec- 21 tion shall implement and utilize a security control to 22 protect against unauthorized access to or acquisition 23 of such cyber threat indicator or defensive measure. † S 754 ES

Select target paragraph3