United States · Bill · HR
H.R. 1560 (114th)
To improve cybersecurity in the United States through enhanced sharing of information about cybersecurity threats, to amend the Homeland Security Act of 2002 to enhance multi-directional sharing of information related to cybersecurity risks and strengthen privacy and civil liberties protections, and for other purposes.
Introduced
24 March 2015
Last action
—
Status
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Sponsors
—
Subjects
Discovery layer
Source updated
7 April 2025
Summary
Protecting Cyber Networks Act Amends the National Security Act of 1947 to require the Director of National Intelligence (DNI) to develop and promulgate procedures to promote: (1) the timely sharing of classified and declassified cyber threat indicators in possession of the federal government with private entities, non-federal government agencies, or state, tribal, or local governments; and (2) the sharing of imminent or ongoing cybersecurity threats with such entities to prevent or mitigate adverse impacts. Requires the procedures to provide for: (1) notification to entities when the federal government has shared indicators in error or in contravention of law; and (2) the federal government, prior to sharing indicators, to remove personal information of, or information identifying, a specific person not directly related to a cybersecurity threat. Permits private entities to monitor or operate defensive measures to prevent or mitigate cybersecurity threats or security vulnerabilities, or to identify the source of a threat, on: (1) their own information systems; and (2) with written authorization, the information systems of other private or government entities. Allows non-federal entities to share and receive indicators or defensive measures with other non-federal entities or appropriate federal entities, but does not permit non-federal entities to share directly with components of the Department of Defense (DOD), including the National Security Agency (NSA). Requires recipients to comply with lawful restrictions that sharing entities place on the sharing or use of shared indicators or defensive measures. Requires non-federal entities monitoring, operating, or sharing indicators or defensive measures: (1) to implement security controls to protect against unauthorized access or acquisitions; and (2) prior to sharing an indicator, to take reasonable efforts to remove personal information of, or information identifying, a specific person not directly related to a cybersecurity threat. Permits state, tribal, or local agencies to use shared indicators (with the consent of a non-federal entity sharing the indicators) to prevent, investigate, or prosecute a felonious criminal act. Directs the President to submit to Congress procedures for the receipt of cyber threat indicators and defensive measures by the federal government. Requires the procedures to ensure that: (1) cyber threat indicators shared by a non-federal entity with the Department of Commerce, the Department of Energy, the Department of Homeland Security, the Department of Justice (DOJ), the Department of the Treasury, and the DNI (but not DOD, including the NSA) are shared in real-time with all such appropriate federal entities; (2) such indicators are provided to other relevant federal entities; (3) there is an audit capability; and (4) there are appropriate sanctions for federal officers, employees, or agents who use shared indicators or defensive measures in an unauthorized manner. Requires DOJ to develop and periodically review privacy and civil liberties guidelines to govern the receipt, retention, use, and dissemination of cyber threat indicators by federal entities. Establishes within the Office of the Director of National Intelligence a Cyber Threat Intelligence Integration Center (CTIIC) to serve as the primary organization within the federal government for analyzing and integrating all intelligence possessed or acquired by the United States pertaining to cyber threats. Requires the CTIIC to: (1) ensure that appropriate agencies receive all-source intelligence support to execute cyber threat intelligence activities and perform independent, alternative analyses; (2) disseminate threat analysis to the President, federal agencies, and Congress; and (3) coordinate federal cyber threat intelligence activities and conduct strategic planning. Authorizes indicators or defensive measures to be disclosed to, retained by, and used by, consistent with otherwise applicable federal law, any agency or agent of the federal government solely for: protecting an information system or information that is stored on, processed by, or transiting an information system from a cybersecurity threat or security vulnerability or identifying the source of a cybersecurity threat; responding to, prosecuting, or otherwise preventing or mitigating a threat of death or serious bodily harm or an offense arising out of such a threat; responding to, or otherwise preventing or mitigating, a serious threat to a minor, including sexual exploitation and threats to physical safety; or preventing, investigating, disrupting, or prosecuting specified criminal offenses relating to fraud and identity theft, serious violent felonies, espionage and censorship, or trade secrets. Allows a person to bring a private cause of action against the federal government if an agency intentionally or willfully violates DOJ's privacy and civil liberties guidelines. Provides liability protections, if the following activities are conducted in good faith in accordance with this Act, to: (1) private entities monitoring information systems; or (2) non-federal entities sharing, receiving, or failing to act upon shared indicators or defensive measures. Prohibits this Act from being construed to: (1) authorize the federal government to conduct surveillance of a person or allow the intelligence community to target a person for surveillance; (2) limit lawful disclosures of communications or records, including reporting of known or suspected criminal activity, by a non-federal entity to another non-federal entity or the federal government; or (3) permit the federal government to require a non-federal entity to provide information to the federal government.
This text is taken from the official record. PoliticalRepo does not editorialize.
Timeline
No timeline events have been ingested for this record yet.
Votes
No vote records are attached yet.
Versions
No version snapshots stored. Document URLs remain at the source.
Documents
13 official files
Referred in Senate (text)
Referred in Senate (text)
Referred in Senate · EN · 14 July 2016
Referred in Senate (PDF)
Referred in Senate · EN · 14 July 2016
Received in Senate (text)
Received in Senate · EN · 27 April 2015
Received in Senate (PDF)
Received in Senate · EN · 27 April 2015
Engrossed in House (text)
Engrossed in House · EN · 22 April 2015
Engrossed in House (PDF)
Engrossed in House · EN · 22 April 2015
Passed House amended
summary · EN · 22 April 2015
Reported in House (text)
Reported in House · EN · 13 April 2015
Reported in House (PDF)
Reported in House · EN · 13 April 2015
Reported to House with amendment(s)
summary · EN · 13 April 2015
Introduced in House (text)
Introduced in House · EN · 24 March 2015
Introduced in House (PDF)
Introduced in House · EN · 24 March 2015
Introduced in House
summary · EN · 24 March 2015
Sponsors
No sponsors or actors listed by the source.
Related records
No cross-record relationships stored yet.
Sources
PoliticalRepo is an index and interpretation layer, not the authoritative legal source.
- Official source: https://www.congress.gov/bill/114th-congress/house-bill/1560
- Open data entity: https://api.congress.gov/v3/bill/114/hr/1560