13
1
or acquisition of such cyber threat indicators or
2
defensive measures;
3
(E) include procedures that require a Fed-
4
eral entity, prior to the sharing of a cyber
5
threat indicator—
6
(i) to review such cyber threat indi-
7
cator to assess whether such cyber threat
8
indicator contains any information that
9
such Federal entity knows at the time of
10
sharing to be personal information or in-
11
formation that identifies a specific person
12
not directly related to a cybersecurity
13
threat and remove such information; or
14
(ii) to implement and utilize a tech-
15
nical capability configured to remove any
16
personal information or information that
17
identifies a specific person not directly re-
18
lated to a cybersecurity threat; and
19
(F) include procedures for notifying, in a
20
timely manner, any United States person whose
21
personal information is known or determined to
22
have been shared by a Federal entity in viola-
23
tion of this Act.
24
(2) COORDINATION.—In developing the proce-
25
dures required under this section, the Director of
† S 754 ES