PoliticalRepoPoliticalRepo

United States · Bill · HR

H.R. 1731 (114th)

National Cybersecurity Protection Advancement Act of 2015

openUnited States· United States Congress· EN

Introduced

13 April 2015

Last action

Status

Pursuant to the provisions of H. Res. 212, H.R. 1731 is laid on the table.

Sponsors

Subjects

Discovery layer

Source updated

7 April 2025

Summary

National Cybersecurity Protection Advancement Act of 2015 Amends the Homeland Security Act of 2002 to allow the Department of Homeland Security's (DHS's) national cybersecurity and communications integration center (NCCIC) to include tribal governments, information sharing and analysis centers, and private entities among its non-federal representatives. Expands the composition of the NCCIC to include: a collaborator with state and local governments on cybersecurity risks and incidents; a U.S. Computer Emergency Readiness Team that coordinates and shares information in a timely manner and provides technical assistance, upon request, to information system owners and operators; the Industrial Control System Cyber Emergency Response Team that coordinates with owners and operators of industrial control systems and provides requested training; and a National Coordinating Center for Communications that coordinates the protection, response, and recovery of emergency communications. Requires the NCCIC to be the lead federal civilian interface for multi-directional and cross-sector sharing of information related to cyber threat indicators, defensive measures, and cybersecurity risks for federal and non-federal entities. Expands the NCCIC's functions to include: global cybersecurity with international partners, information sharing across critical infrastructure sectors, notification to Congress regarding any significant violations of retention or disclosure policies, and notification to non-federal entities of indicators or defensive measures shared in error or in contravention of specified requirements. Directs the NCCIC to: (1) safeguard cybersecurity information against unauthorized disclosure, and (2) work with the Chief Privacy Officer to follow appropriate privacy procedures. Requires the Under Secretary for Cybersecurity and Infrastructure Protection to adopt industry standards for the timely sharing of indicators and defensive measures to and from the NCCIC and with federal agencies designated as sector specific agencies for critical infrastructure sectors. Authorizes the NCCIC to enter voluntary information sharing relationships with consenting non-federal entities. Allows non-federal entities, for cybersecurity purposes, to share with other non-federal entities or the NCCIC any indicators or defensive measures obtained from: (1) their own information systems; or (2) the information systems of other federal or non-federal entities, with written consent. Authorizes non-federal entities (excluding state, local, or tribal governments) to conduct network awareness to scan, identify, acquire, monitor, log, or analyze the information, or to operate defensive measures, on the information systems of entities that provide consent. Requires federal and non-federal entities, prior to sharing, to take reasonable efforts to: (1) remove information that can be used to identify specific persons and that is unrelated to cybersecurity risks or incidents, and (2) safeguard information that can be used to identify specific persons from unintended disclosure or unauthorized access or acquisition. Directs the Under Secretary to establish and annually review procedures governing the receipt, retention, use, and disclosure of cybersecurity information shared with the NCCIC. Provides liability protections to non-federal entities (excluding state, local, or tribal governments) acting in good faith in accordance with this Act that: (1) conduct network awareness, or (2) share indicators or defensive measures or fail to act based on such sharing. Establishes a private cause of action that a person may bring against the federal government if a federal agency intentionally or willfully violates restrictions on the use and protection of voluntarily shared indicators or defensive measures. Prohibits this Act from being construed to permit the federal government to require a non-federal entity to provide information to a federal entity. Expands the purpose of information sharing and analysis organizations to include responsibilities for disseminating information about cybersecurity risks and incidents. Redesignates DHS's National Protection and Programs Directorate as the Cybersecurity and Infrastructure Protection. Codifies positions for the following officers: (1) the Under Secretary, to be appointed by the President with the advice and consent of the Senate, and (2) the Deputy Under Secretaries for Cybersecurity and for Infrastructure Protection, to be appointed by the President without the advice and consent of the Senate. Requires the Under Secretary to report to Congress regarding the feasibility of becoming an operational component.

This text is taken from the official record. PoliticalRepo does not editorialize.

Timeline

No timeline events have been ingested for this record yet.

Votes

No vote records are attached yet.

Versions

No version snapshots stored. Document URLs remain at the source.

Documents

7 official files

Reported in House (text)

View fileDownload file

Sponsors

No sponsors or actors listed by the source.

Related records

No cross-record relationships stored yet.

Sources

PoliticalRepo is an index and interpretation layer, not the authoritative legal source.