H. R. 2029—714
(j) USE AND RETENTION OF INFORMATION.—Nothing in this title
shall be construed to authorize, or to modify any existing authority
of, a department or agency of the Federal Government to retain
or use any information shared under this title for any use other
than permitted in this title.
(k) FEDERAL PREEMPTION.—
(1) IN GENERAL.—This title supersedes any statute or other
provision of law of a State or political subdivision of a State
that restricts or otherwise expressly regulates an activity
authorized under this title.
(2) STATE LAW ENFORCEMENT.—Nothing in this title shall
be construed to supersede any statute or other provision of
law of a State or political subdivision of a State concerning
the use of authorized law enforcement practices and procedures.
(l) REGULATORY AUTHORITY.—Nothing in this title shall be construed—
(1) to authorize the promulgation of any regulations not
specifically authorized to be issued under this title;
(2) to establish or limit any regulatory authority not specifically established or limited under this title; or
(3) to authorize regulatory actions that would duplicate
or conflict with regulatory requirements, mandatory standards,
or related processes under another provision of Federal law.
(m) AUTHORITY OF SECRETARY OF DEFENSE TO RESPOND TO
MALICIOUS CYBER ACTIVITY CARRIED OUT BY FOREIGN POWERS.—
Nothing in this title shall be construed to limit the authority
of the Secretary of Defense under section 130g of title 10, United
States Code.
(n) CRIMINAL PROSECUTION.—Nothing in this title shall be construed to prevent the disclosure of a cyber threat indicator or
defensive measure shared under this title in a case of criminal
prosecution, when an applicable provision of Federal, State, tribal,
or local law requires disclosure in such case.
SEC. 109. REPORT ON CYBERSECURITY THREATS.
(a) REPORT REQUIRED.—Not later than 180 days after the date
of the enactment of this Act, the Director of National Intelligence,
in coordination with the heads of other appropriate elements of
the intelligence community, shall submit to the Select Committee
on Intelligence of the Senate and the Permanent Select Committee
on Intelligence of the House of Representatives a report on cybersecurity threats, including cyber attacks, theft, and data breaches.
(b) CONTENTS.—The report required by subsection (a) shall
include the following:
(1) An assessment of the current intelligence sharing and
cooperation relationships of the United States with other countries regarding cybersecurity threats, including cyber attacks,
theft, and data breaches, directed against the United States
and which threaten the United States national security
interests and economy and intellectual property, specifically
identifying the relative utility of such relationships, which elements of the intelligence community participate in such relationships, and whether and how such relationships could be
improved.
(2) A list and an assessment of the countries and nonstate
actors that are the primary threats of carrying out a cybersecurity threat, including a cyber attack, theft, or data breach,