H. R. 2029—699
measures in real time consistent with the protection of
classified information;
(B) incorporate, to the greatest extent practicable,
existing processes and existing roles and responsibilities
of Federal entities and non-Federal entities for information
sharing by the Federal Government, including sector specific information sharing and analysis centers;
(C) include procedures for notifying, in a timely
manner, Federal entities and non-Federal entities that
have received a cyber threat indicator or defensive measure
from a Federal entity under this title that is known or
determined to be in error or in contravention of the requirements of this title or another provision of Federal law
or policy of such error or contravention;
(D) include requirements for Federal entities sharing
cyber threat indicators or defensive measures to implement
and utilize security controls to protect against unauthorized
access to or acquisition of such cyber threat indicators
or defensive measures;
(E) include procedures that require a Federal entity,
prior to the sharing of a cyber threat indicator—
(i) to review such cyber threat indicator to assess
whether such cyber threat indicator contains any
information not directly related to a cybersecurity
threat that such Federal entity knows at the time
of sharing to be personal information of a specific individual or information that identifies a specific individual and remove such information; or
(ii) to implement and utilize a technical capability
configured to remove any information not directly
related to a cybersecurity threat that the Federal entity
knows at the time of sharing to be personal information
of a specific individual or information that identifies
a specific individual; and
(F) include procedures for notifying, in a timely
manner, any United States person whose personal information is known or determined to have been shared by a
Federal entity in violation of this title.
(2) CONSULTATION.—In developing the procedures required
under this section, the Director of National Intelligence, the
Secretary of Homeland Security, the Secretary of Defense, and
the Attorney General shall consult with appropriate Federal
entities, including the Small Business Administration and the
National Laboratories (as defined in section 2 of the Energy
Policy Act of 2005 (42 U.S.C. 15801)), to ensure that effective
protocols are implemented that will facilitate and promote the
sharing of cyber threat indicators by the Federal Government
in a timely manner.
(c) SUBMITTAL TO CONGRESS.—Not later than 60 days after
the date of the enactment of this Act, the Director of National
Intelligence, in consultation with the heads of the appropriate Federal entities, shall submit to Congress the procedures required
by subsection (a).
SEC. 104. AUTHORIZATIONS FOR PREVENTING, DETECTING, ANALYZING, AND MITIGATING CYBERSECURITY THREATS.
(a) AUTHORIZATION FOR MONITORING.—