PoliticalRepoPoliticalRepo

United States · Bill · HR

H.R. 1560 (114th)

To improve cybersecurity in the United States through enhanced sharing of information about cybersecurity threats, to amend the Homeland Security Act of 2002 to enhance multi-directional sharing of information related to cybersecurity risks and strengthen privacy and civil liberties protections, and for other purposes.

referredUnited States· United States Congress· EN

Introduced

24 March 2015

Last action

Status

Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

Sponsors

Subjects

Discovery layer

Source updated

7 April 2025

Summary

Protecting Cyber Networks Act Amends the National Security Act of 1947 to require the Director of National Intelligence (DNI) to develop and promulgate procedures to promote: (1) the timely sharing of classified and declassified cyber threat indicators in possession of the federal government with private entities, non-federal government agencies, or state, tribal, or local governments; and (2) the sharing of imminent or ongoing cybersecurity threats with such entities to prevent or mitigate adverse impacts. Requires the procedures to provide for: (1) notification to entities when the federal government has shared indicators in error or in contravention of law; and (2) the federal government, prior to sharing indicators, to remove personal information of, or information identifying, a specific person not directly related to a cybersecurity threat. Permits private entities to monitor or operate defensive measures to prevent or mitigate cybersecurity threats or security vulnerabilities, or to identify the source of a threat, on: (1) their own information systems; and (2) with written authorization, the information systems of other private or government entities. Allows non-federal entities to share and receive indicators or defensive measures with other non-federal entities or appropriate federal entities, but does not permit non-federal entities to share directly with components of the Department of Defense (DOD), including the National Security Agency (NSA). Requires recipients to comply with lawful restrictions that sharing entities place on the sharing or use of shared indicators or defensive measures. Requires non-federal entities monitoring, operating, or sharing indicators or defensive measures: (1) to implement security controls to protect against unauthorized access or acquisitions; and (2) prior to sharing an indicator, to take reasonable efforts to remove personal information of, or information identifying, a specific person not directly related to a cybersecurity threat. Permits state, tribal, or local agencies to use shared indicators (with the consent of a non-federal entity sharing the indicators) to prevent, investigate, or prosecute a felonious criminal act. Directs the President to submit to Congress procedures for the receipt of cyber threat indicators and defensive measures by the federal government. Requires the procedures to ensure that: (1) cyber threat indicators shared by a non-federal entity with the Department of Commerce, the Department of Energy, the Department of Homeland Security, the Department of Justice (DOJ), the Department of the Treasury, and the DNI (but not DOD, including the NSA) are shared in real-time with all such appropriate federal entities; (2) such indicators are provided to other relevant federal entities; (3) there is an audit capability; and (4) there are appropriate sanctions for federal officers, employees, or agents who use shared indicators or defensive measures in an unauthorized manner. Requires DOJ to develop and periodically review privacy and civil liberties guidelines to govern the receipt, retention, use, and dissemination of cyber threat indicators by federal entities. Establishes within the Office of the Director of National Intelligence a Cyber Threat Intelligence Integration Center (CTIIC) to serve as the primary organization within the federal government for analyzing and integrating all intelligence possessed or acquired by the United States pertaining to cyber threats. Requires the CTIIC to: (1) ensure that appropriate agencies receive all-source intelligence support to execute cyber threat intelligence activities and perform independent, alternative analyses; (2) disseminate threat analysis to the President, federal agencies, and Congress; and (3) coordinate federal cyber threat intelligence activities and conduct strategic planning. Authorizes indicators or defensive measures to be disclosed to, retained by, and used by, consistent with otherwise applicable federal law, any agency or agent of the federal government solely for: protecting an information system or information that is stored on, processed by, or transiting an information system from a cybersecurity threat or security vulnerability or identifying the source of a cybersecurity threat; responding to, prosecuting, or otherwise preventing or mitigating a threat of death or serious bodily harm or an offense arising out of such a threat; responding to, or otherwise preventing or mitigating, a serious threat to a minor, including sexual exploitation and threats to physical safety; or preventing, investigating, disrupting, or prosecuting specified criminal offenses relating to fraud and identity theft, serious violent felonies, espionage and censorship, or trade secrets. Allows a person to bring a private cause of action against the federal government if an agency intentionally or willfully violates DOJ's privacy and civil liberties guidelines. Provides liability protections, if the following activities are conducted in good faith in accordance with this Act, to: (1) private entities monitoring information systems; or (2) non-federal entities sharing, receiving, or failing to act upon shared indicators or defensive measures. Prohibits this Act from being construed to: (1) authorize the federal government to conduct surveillance of a person or allow the intelligence community to target a person for surveillance; (2) limit lawful disclosures of communications or records, including reporting of known or suspected criminal activity, by a non-federal entity to another non-federal entity or the federal government; or (3) permit the federal government to require a non-federal entity to provide information to the federal government.

This text is taken from the official record. PoliticalRepo does not editorialize.

Timeline

No timeline events have been ingested for this record yet.

Votes

No vote records are attached yet.

Versions

No version snapshots stored. Document URLs remain at the source.

Documents

13 official files

Referred in Senate (text)

View fileDownload file

Sponsors

No sponsors or actors listed by the source.

Related records

No cross-record relationships stored yet.

Sources

PoliticalRepo is an index and interpretation layer, not the authoritative legal source.