H. R. 2029—702
State, tribal, or local government that is a private entity,
under this section shall be—
(i) deemed voluntarily shared information; and
(ii) exempt from disclosure under any provision
of State, tribal, or local freedom of information law,
open government law, open meetings law, open records
law, sunshine law, or similar law requiring disclosure
of information or records.
(C) STATE, TRIBAL, AND LOCAL REGULATORY
AUTHORITY.—
(i) IN GENERAL.—Except as provided in clause (ii),
a cyber threat indicator or defensive measure shared
with a State, tribal, or local government under this
title shall not be used by any State, tribal, or local
government to regulate, including an enforcement
action, the lawful activity of any non-Federal entity
or any activity taken by a non-Federal entity pursuant
to mandatory standards, including an activity relating
to monitoring, operating a defensive measure, or
sharing of a cyber threat indicator.
(ii)
REGULATORY
AUTHORITY
SPECIFICALLY
RELATING TO PREVENTION OR MITIGATION OF CYBERSECURITY THREATS.—A cyber threat indicator or defensive
measure shared as described in clause (i) may, consistent with a State, tribal, or local government regulatory authority specifically relating to the prevention
or mitigation of cybersecurity threats to information
systems, inform the development or implementation
of a regulation relating to such information systems.
(e) ANTITRUST EXEMPTION.—
(1) IN GENERAL.—Except as provided in section 108(e), it
shall not be considered a violation of any provision of antitrust
laws for 2 or more private entities to exchange or provide
a cyber threat indicator or defensive measure, or assistance
relating to the prevention, investigation, or mitigation of a
cybersecurity threat, for cybersecurity purposes under this title.
(2) APPLICABILITY.—Paragraph (1) shall apply only to
information that is exchanged or assistance provided in order
to assist with—
(A) facilitating the prevention, investigation, or mitigation of a cybersecurity threat to an information system
or information that is stored on, processed by, or transiting
an information system; or
(B) communicating or disclosing a cyber threat indicator to help prevent, investigate, or mitigate the effect
of a cybersecurity threat to an information system or
information that is stored on, processed by, or transiting
an information system.
(f) NO RIGHT OR BENEFIT.—The sharing of a cyber threat indicator or defensive measure with a non-Federal entity under this
title shall not create a right or benefit to similar information by
such non-Federal entity or any other non-Federal entity.
SEC. 105. SHARING OF CYBER THREAT INDICATORS AND DEFENSIVE
MEASURES WITH THE FEDERAL GOVERNMENT.
(a) REQUIREMENT FOR POLICIES AND PROCEDURES.—