30
1
be directly related to uses authorized under
2
this title; and
3
(ii) specific limitations on the length
4
of any period in which a cyber threat indi-
5
cator may be retained;
6
(C) include requirements to safeguard
7
cyber threat indicators containing personal in-
8
formation or information that identifies specific
9
persons from unauthorized access or acquisi-
10
tion, including appropriate sanctions for activi-
11
ties by officers, employees, or agents of the
12
Federal Government in contravention of such
13
guidelines;
14
(D) include procedures for notifying enti-
15
ties and Federal entities if information received
16
pursuant to this section is known or determined
17
by a Federal entity receiving such information
18
not to constitute a cyber threat indicator;
19
(E) protect the confidentiality of cyber
20
threat indicators containing personal informa-
21
tion or information that identifies specific per-
22
sons to the greatest extent practicable and re-
23
quire recipients to be informed that such indica-
24
tors may only be used for purposes authorized
25
under this title; and
† S 754 ES