17
1
mation, share with, or receive from, any other entity
2
or the Federal Government a cyber threat indicator
3
or defensive measure.
4
(2) LAWFUL
RESTRICTION.—An
entity receiving
5
a cyber threat indicator or defensive measure from
6
another entity or Federal entity shall comply with
7
otherwise lawful restrictions placed on the sharing or
8
use of such cyber threat indicator or defensive meas-
9
ure by the sharing entity or Federal entity.
10
11
(3) CONSTRUCTION.—Nothing in this subsection shall be construed—
12
(A) to authorize the sharing or receiving of
13
a cyber threat indicator or defensive measure
14
other than as provided in this subsection; or
15
(B) to limit otherwise lawful activity.
16
(d) PROTECTION AND USE OF INFORMATION.—
17
(1) SECURITY
OF INFORMATION.—An
entity
18
monitoring an information system, operating a de-
19
fensive measure, or providing or receiving a cyber
20
threat indicator or defensive measure under this sec-
21
tion shall implement and utilize a security control to
22
protect against unauthorized access to or acquisition
23
of such cyber threat indicator or defensive measure.
† S 754 ES