H. R. 2029—732
‘‘(A) in coordination with the Director, and in consultation with Federal contractors as appropriate, establish
procedures governing the circumstances under which a
directive may be issued under this subsection, which shall
include—
‘‘(i) thresholds and other criteria;
‘‘(ii) privacy and civil liberties protections; and
‘‘(iii) providing notice to potentially affected third
parties;
‘‘(B) specify the reasons for the required action and
the duration of the directive;
‘‘(C) minimize the impact of a directive under this
subsection by—
‘‘(i) adopting the least intrusive means possible
under the circumstances to secure the agency information systems; and
‘‘(ii) limiting directives to the shortest period practicable;
‘‘(D) notify the Director and the head of any affected
agency immediately upon the issuance of a directive under
this subsection;
‘‘(E) consult with the Director of the National Institute
of Standards and Technology regarding any directive under
this subsection that implements standards and guidelines
developed by the National Institute of Standards and Technology;
‘‘(F) ensure that directives issued under this subsection
do not conflict with the standards and guidelines issued
under section 11331 of title 40;
‘‘(G) consider any applicable standards or guidelines
developed by the National Institute of Standards and Technology issued by the Secretary of Commerce under section
11331 of title 40; and
‘‘(H) not later than February 1 of each year, submit
to the appropriate congressional committees a report
regarding the specific actions the Secretary has taken
pursuant to paragraph (1)(A).
‘‘(3) IMMINENT THREATS.—
‘‘(A) IN GENERAL.—Notwithstanding section 3554, the
Secretary may authorize the use under this subsection
of the intrusion detection and prevention capabilities established under section 230(b)(1) of the Homeland Security
Act of 2002 for the purpose of ensuring the security of
agency information systems, if—
‘‘(i) the Secretary determines there is an imminent
threat to agency information systems;
‘‘(ii) the Secretary determines a directive under
subsection (b)(2)(C) or paragraph (1)(A) is not reasonably likely to result in a timely response to the threat;
‘‘(iii) the Secretary determines the risk posed by
the imminent threat outweighs any adverse consequences reasonably expected to result from the use
of the intrusion detection and prevention capabilities
under the control of the Secretary;
‘‘(iv) the Secretary provides prior notice to the
Director, and the head and chief information officer
(or equivalent official) of each agency to which specific