15
1
(B) an information system of another enti-
2
ty, upon the authorization and written consent
3
of such other entity;
4
(C) an information system of a Federal en-
5
tity, upon the authorization and written consent
6
of an authorized representative of the Federal
7
entity; and
8
(D) information that is stored on, proc-
9
essed by, or transiting an information system
10
monitored by the private entity under this para-
11
graph.
12
(2) CONSTRUCTION.—Nothing in this sub-
13
section shall be construed—
14
(A) to authorize the monitoring of an in-
15
formation system, or the use of any information
16
obtained through such monitoring, other than
17
as provided in this title; or
18
19
(B) to limit otherwise lawful activity.
(b) AUTHORIZATION
FOR
OPERATION
OF
DEFENSIVE
20 MEASURES.—
21
(1) IN
GENERAL.—Notwithstanding
any other
22
provision of law, a private entity may, for cybersecu-
23
rity purposes, operate a defensive measure that is
24
applied to—
† S 754 ES