Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 114th Congress · H.R. 3305 (Introduced in House) — To help enhance American network security and mitigate cybersecurity risks, and for other purposes. · Sec. 2

Sec. 2. Protection of Federal civilian information systems

674 words·~3 min read·/bill/114/hr/3305/ih/section-2·

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

Subtitle C of title II of the Homeland Security Act of 2002 ( 6 U.S.C. 141 et seq. ) is amended by adding at the end the following new section: The Secretary shall deploy, operate, and maintain, to make available for use by any Federal agency, with or without reimbursement, capabilities to protect Federal agency information and Federal civilian information systems, including technologies to diagnose, detect, prevent, and mitigate against cybersecurity risks involving Federal agency information or Federal civilian information systems.
In carrying out this section, the Secretary may— access, and Federal agency heads may disclose to the Secretary or a private entity providing assistance to the Secretary under paragraph (2), information traveling to or from or stored on a Federal civilian information system, regardless of from where the Secretary or a private entity providing assistance to the Secretary under paragraph
(2)accesses such information, notwithstanding any other provision of law that would otherwise restrict or prevent Federal agency heads from disclosing such information to the Secretary or a private entity providing assistance to the Secretary under paragraph (2); enter into contracts or other agreements, or otherwise request and obtain the assistance of, private entities to deploy, operate, and maintain technologies in accordance with subsection (a); and retain, use, and disclose information obtained through the conduct of activities authorized under this section only to protect Federal agency information and Federal civilian information systems from cybersecurity risks or in furtherance of the national cybersecurity and communications integration center’s authority under the second section 226, or, with the approval of the Attorney General and if disclosure of such information is not otherwise prohibited by law, to law enforcement only to investigate, prosecute, disrupt, or otherwise respond to— a violation of section 1030 of title 18, United States Code; an imminent threat of death or serious bodily harm; a serious threat to a minor, including sexual exploitation or threats to physical safety; or an attempt, or conspiracy, to commit an offense described in any of subparagraphs
(A)through (C). Contracts or other agreements under subsection (b)(2) shall include appropriate provisions barring— the disclosure of information to any entity other than the Department or a Federal agency disclosing information in accordance with subsection (b)(1) that can be used to identify specific persons and is reasonably believed to be unrelated to a cybersecurity risk; and the use of any information to which such private entity gains access in accordance with this section for any purpose other than to protect Federal agency information and Federal civilian information systems against cybersecurity risks or to administer any such contract or other agreement. No cause of action shall lie in any court against a private entity for assistance provided to the Secretary in accordance with this section and a contract or agreement under subsection (b)(2). The term cybersecurity risk has the meaning given such term in the second section 226 (relating to the national cybersecurity and communications integration center). . Paragraphs
(1)and
(2)of the second section 226 of the Homeland Security Act of 2002 ( 6 U.S.C. 148 ; relating to the national cybersecurity and communications integration center) are amended to read as follows: except as provided in subparagraph (B), the term cybersecurity risk means threats to and vulnerabilities of information or information systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information or information systems, including such related consequences caused by an act of terrorism; and such term does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement; the term incident means an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system, or actually or imminently jeopardizes, without lawful authority, an information system; . The table of contents of the Homeland Security Act of 2002 is amended by adding at the end the following new item: Sec. 230. Available protection of Federal civilian information systems. .
Connectionstraces to 1
Traces to 1 document
1 reference not yet in our index
  • 6 USC 148
Citation graph
cites case law
Sec. 2
Protection of Federal civilian information systems
Cite6 USC 148
Cites 2Cited by 0 across 0 sources
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.