---
kind: "section"
citation: "6 U.S.C. § 1503"
title: "6"
title_heading: "Domestic Security"
number: "1503"
heading: "Authorizations for preventing, detecting, analyzing, and mitigating cybersecurity threats"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/6/1503"
units:
  - "Chapter 6 — Cybersecurity"
  - "Subchapter I — Cybersecurity Information Sharing"
---

# §1503. Authorizations for preventing, detecting, analyzing, and mitigating cybersecurity threats

- (a) **Authorization for monitoring—**
  - (1) **In general—** Notwithstanding any other provision of law, a [private entity](/usc/6/1501.md?p=15-A) may, for [cybersecurity purposes](/usc/6/1501.md?p=4), [monitor](/usc/6/1501.md?p=13)—
    - (A) an [information system](/usc/6/1501.md?p=9) of such [private entity](/usc/6/1501.md?p=15-A);
    - (B) an [information system](/usc/6/1501.md?p=9) of another [non-Federal entity](/usc/6/1501.md?p=14-A), upon the authorization and written consent of such other [entity](/usc/6/301c.md?p=2);
    - (C) an [information system](/usc/6/1501.md?p=9) of a [Federal entity](/usc/6/1501.md?p=8), upon the authorization and written consent of an authorized representative of the [Federal entity](/usc/6/1501.md?p=8); and
    - (D) information that is stored on, processed by, or transiting an [information system](/usc/6/1501.md?p=9) monitored by the [private entity](/usc/6/1501.md?p=15-A) under this paragraph.
  - (2) **Construction—** Nothing in this subsection shall be construed—
    - (A) to authorize the monitoring of an [information system](/usc/6/1501.md?p=9), or the use of any information obtained through such monitoring, other than as provided in this subchapter; or
    - (B) to limit otherwise lawful activity.
- (b) **Authorization for operation of defensive measures—**
  - (1) **In general—** Notwithstanding any other provision of law, a [private entity](/usc/6/1501.md?p=15-A) may, for [cybersecurity purposes](/usc/6/1501.md?p=4), operate a [defensive measure](/usc/6/1501.md?p=7) that is applied to—
    - (A) an [information system](/usc/6/1501.md?p=9) of such [private entity](/usc/6/1501.md?p=15-A) in order to protect the rights or property of the [private entity](/usc/6/1501.md?p=15-A);
    - (B) an [information system](/usc/6/1501.md?p=9) of another [non-Federal entity](/usc/6/1501.md?p=14-A) upon written consent of such [entity](/usc/6/301c.md?p=2) for operation of such [defensive measure](/usc/6/1501.md?p=7) to protect the rights or property of such [entity](/usc/6/301c.md?p=2); and
    - (C) an [information system](/usc/6/1501.md?p=9) of a [Federal entity](/usc/6/1501.md?p=8) upon written consent of an authorized representative of such [Federal entity](/usc/6/1501.md?p=8) for operation of such [defensive measure](/usc/6/1501.md?p=7) to protect the rights or property of the Federal Government.
  - (2) **Construction—** Nothing in this subsection shall be construed—
    - (A) to authorize the use of a [defensive measure](/usc/6/1501.md?p=7) other than as provided in this subsection; or
    - (B) to limit otherwise lawful activity.
- (c) **Authorization for sharing or receiving cyber threat indicators or defensive measures—**
  - (1) **In general—** Except as provided in [paragraph (2)](#c-2) and notwithstanding any other provision of law, a [non-Federal entity](/usc/6/1501.md?p=14-A) may, for a [cybersecurity purpose](/usc/6/1501.md?p=4) and consistent with the protection of classified information, share with, or receive from, any other [non-Federal entity](/usc/6/1501.md?p=14-A) or the Federal Government a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7).
  - (2) **Lawful restriction—** A [non-Federal entity](/usc/6/1501.md?p=14-A) receiving a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) from another [non-Federal entity](/usc/6/1501.md?p=14-A) or a [Federal entity](/usc/6/1501.md?p=8) shall comply with otherwise lawful restrictions placed on the sharing or use of such [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) by the sharing [non-Federal entity](/usc/6/1501.md?p=14-A) or [Federal entity](/usc/6/1501.md?p=8).
  - (3) **Construction—** Nothing in this subsection shall be construed—
    - (A) to authorize the sharing or receiving of a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) other than as provided in this subsection; or
    - (B) to limit otherwise lawful activity.
- (d) **Protection and use of information—**
  - (1) **Security of information—** A [non-Federal entity](/usc/6/1501.md?p=14-A) monitoring an [information system](/usc/6/1501.md?p=9), operating a [defensive measure](/usc/6/1501.md?p=7), or providing or receiving a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) under this section shall implement and utilize a [security control](/usc/6/1501.md?p=16) to protect against unauthorized access to or acquisition of such [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7).
  - (2) **Removal of certain personal information—** A [non-Federal entity](/usc/6/1501.md?p=14-A) sharing a [cyber threat indicator](/usc/6/1501.md?p=6) pursuant to this subchapter shall, prior to such sharing—
    - (A) review such [cyber threat indicator](/usc/6/1501.md?p=6) to assess whether such [cyber threat indicator](/usc/6/1501.md?p=6) contains any information not directly related to a [cybersecurity threat](/usc/6/1501.md?p=5) that the [non-Federal entity](/usc/6/1501.md?p=14-A) knows at the time of sharing to be personal information of a specific individual or information that identifies a specific individual and remove such information; or
    - (B) implement and utilize a technical capability configured to remove any information not directly related to a [cybersecurity threat](/usc/6/1501.md?p=5) that the [non-Federal entity](/usc/6/1501.md?p=14-A) knows at the time of sharing to be personal information of a specific individual or information that identifies a specific individual.
  - (3) **Use of cyber threat indicators and defensive measures by non-Federal entities—**
    - (A) **In general—** Consistent with this subchapter, a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) shared or received under this section may, for [cybersecurity purposes](/usc/6/1501.md?p=4)—
      - (i) be used by a [non-Federal entity](/usc/6/1501.md?p=14-A) to [monitor](/usc/6/1501.md?p=13) or operate a [defensive measure](/usc/6/1501.md?p=7) that is applied to—
        - (I) an [information system](/usc/6/1501.md?p=9) of the [non-Federal entity](/usc/6/1501.md?p=14-A); or
        - (II) an [information system](/usc/6/1501.md?p=9) of another [non-Federal entity](/usc/6/1501.md?p=14-A) or a [Federal entity](/usc/6/1501.md?p=8) upon the written consent of that other [non-Federal entity](/usc/6/1501.md?p=14-A) or that [Federal entity](/usc/6/1501.md?p=8); and
      - (ii) be otherwise used, retained, and further shared by a [non-Federal entity](/usc/6/1501.md?p=14-A) subject to—
        - (I) an otherwise lawful restriction placed by the sharing [non-Federal entity](/usc/6/1501.md?p=14-A) or [Federal entity](/usc/6/1501.md?p=8) on such [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7); or
        - (II) an otherwise applicable provision of law.
    - (B) **Construction—** Nothing in this paragraph shall be construed to authorize the use of a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) other than as provided in this section.
  - (4) **Use of cyber threat indicators by State, tribal, or local government—**
    - (A) **Law enforcement use—** A [State](/usc/6/101.md?p=17), [tribal](/usc/6/1501.md?p=18), or [local government](/usc/6/1501.md?p=10) that receives a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) under this subchapter may use such [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) for the purposes described in [section 1504(d)(5)(A) of this title](/usc/6/1504.md?p=d-5-A).
    - (B) **Exemption from disclosure—** A [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) shared by or with a [State](/usc/6/101.md?p=17), [tribal](/usc/6/1501.md?p=18), or [local government](/usc/6/1501.md?p=10), including a component of a [State](/usc/6/101.md?p=17), [tribal](/usc/6/1501.md?p=18), or [local government](/usc/6/1501.md?p=10) that is a [private entity](/usc/6/1501.md?p=15-A), under this section shall be—
      - (i) deemed voluntarily shared information; and
      - (ii) exempt from disclosure under any provision of [State](/usc/6/101.md?p=17), [tribal](/usc/6/1501.md?p=18), or local freedom of information law, open government law, open meetings law, open records law, sunshine law, or similar law requiring disclosure of information or records.
    - (C) **State, tribal, and local regulatory authority—**
      - (i) **In general—** Except as provided in [clause (ii)](#d-4-C-ii), a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) shared with a [State](/usc/6/101.md?p=17), [tribal](/usc/6/1501.md?p=18), or [local government](/usc/6/1501.md?p=10) under this subchapter shall not be used by any [State](/usc/6/101.md?p=17), [tribal](/usc/6/1501.md?p=18), or [local government](/usc/6/1501.md?p=10) to regulate, including an enforcement action, the lawful activity of any [non-Federal entity](/usc/6/1501.md?p=14-A) or any activity taken by a [non-Federal entity](/usc/6/1501.md?p=14-A) pursuant to mandatory standards, including an activity relating to monitoring, operating a [defensive measure](/usc/6/1501.md?p=7), or sharing of a [cyber threat indicator](/usc/6/1501.md?p=6).
      - (ii) **Regulatory authority specifically relating to prevention or mitigation of cybersecurity threats—** A [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) shared as described in [clause (i)](#d-4-C-i) may, consistent with a [State](/usc/6/101.md?p=17), [tribal](/usc/6/1501.md?p=18), or [local government](/usc/6/1501.md?p=10) regulatory authority specifically relating to the prevention or mitigation of [cybersecurity threats](/usc/6/1501.md?p=5) to [information systems](/usc/6/1501.md?p=9), inform the development or implementation of a regulation relating to such [information systems](/usc/6/1501.md?p=9).
- (e) **Antitrust exemption—**
  - (1) **In general—** Except as provided in [section 1507(e) of this title](/usc/6/1507.md?p=e), it shall not be considered a violation of any provision of [antitrust laws](/usc/6/1501.md?p=2) for 2 or more [private entities](/usc/6/1501.md?p=15-A) to exchange or provide a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7), or assistance relating to the prevention, investigation, or mitigation of a [cybersecurity threat](/usc/6/1501.md?p=5), for [cybersecurity purposes](/usc/6/1501.md?p=4) under this subchapter.
  - (2) **Applicability—** [Paragraph (1)](#e-1) shall apply only to information that is exchanged or assistance provided in order to assist with—
    - (A) facilitating the prevention, investigation, or mitigation of a [cybersecurity threat](/usc/6/1501.md?p=5) to an [information system](/usc/6/1501.md?p=9) or information that is stored on, processed by, or transiting an [information system](/usc/6/1501.md?p=9); or
    - (B) communicating or disclosing a [cyber threat indicator](/usc/6/1501.md?p=6) to help prevent, investigate, or mitigate the effect of a [cybersecurity threat](/usc/6/1501.md?p=5) to an [information system](/usc/6/1501.md?p=9) or information that is stored on, processed by, or transiting an [information system](/usc/6/1501.md?p=9).
- (f) **No right or benefit—** The sharing of a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) with a [non-Federal entity](/usc/6/1501.md?p=14-A) under this subchapter shall not create a right or benefit to similar information by such [non-Federal entity](/usc/6/1501.md?p=14-A) or any other [non-Federal entity](/usc/6/1501.md?p=14-A).

## Source credit

(Pub. L. 114–113, div. N, title I, § 104, Dec. 18, 2015, 129 Stat. 2940.)
