---
kind: "section"
citation: "6 U.S.C. § 1504"
title: "6"
title_heading: "Domestic Security"
number: "1504"
heading: "Sharing of cyber threat indicators and defensive measures with the Federal Government"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/6/1504"
units:
  - "Chapter 6 — Cybersecurity"
  - "Subchapter I — Cybersecurity Information Sharing"
---

# §1504. Sharing of cyber threat indicators and defensive measures with the Federal Government

- (a) **Requirement for policies and procedures—**
  - (1) **Interim policies and procedures—** Not later than 60 days after December 18, 2015, the Attorney General and the [Secretary](/usc/6/101.md?p=16) of [Homeland](/usc/6/101.md?p=1) Security shall, in consultation with the heads of the [appropriate Federal entities](/usc/6/1501.md?p=3), jointly develop and submit to Congress interim policies and procedures relating to the receipt of [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) by the Federal Government.
  - (2) **Final policies and procedures—** Not later than 180 days after December 18, 2015, the Attorney General and the [Secretary](/usc/6/101.md?p=16) of [Homeland](/usc/6/101.md?p=1) Security shall, in consultation with the heads of the [appropriate Federal entities](/usc/6/1501.md?p=3), jointly issue and make publicly available final policies and procedures relating to the receipt of [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) by the Federal Government.
  - (3) **Requirements concerning policies and procedures—** Consistent with the guidelines required by [subsection (b)](#b), the policies and procedures developed or issued under this subsection shall—
    - (A) ensure that [cyber threat indicators](/usc/6/1501.md?p=6) shared with the Federal Government by any [non-Federal entity](/usc/6/1501.md?p=14-A) pursuant to [section 1503(c) of this title](/usc/6/1503.md?p=c) through the real-time process described in [subsection (c)](#c) of this section—
      - (i) are shared in an automated manner with all of the [appropriate Federal entities](/usc/6/1501.md?p=3);
      - (ii) are only subject to a delay, modification, or other action due to controls established for such real-time process that could impede real-time receipt by all of the [appropriate Federal entities](/usc/6/1501.md?p=3) when the delay, modification, or other action is due to controls—
        - (I) agreed upon unanimously by all of the heads of the [appropriate Federal entities](/usc/6/1501.md?p=3);
        - (II) carried out before any of the [appropriate Federal entities](/usc/6/1501.md?p=3) retains or uses the [cyber threat indicators](/usc/6/1501.md?p=6) or [defensive measures](/usc/6/1501.md?p=7); and
        - (III) uniformly applied such that each of the [appropriate Federal entities](/usc/6/1501.md?p=3) is subject to the same delay, modification, or other action; and
      - (iii) may be provided to other [Federal entities](/usc/6/1501.md?p=8);
    - (B) ensure that [cyber threat indicators](/usc/6/1501.md?p=6) shared with the Federal Government by any [non-Federal entity](/usc/6/1501.md?p=14-A) pursuant to [section 1503 of this title](/usc/6/1503.md) in a manner other than the real-time process described in [subsection (c)](#c) of this section—
      - (i) are shared as quickly as operationally practicable with all of the [appropriate Federal entities](/usc/6/1501.md?p=3);
      - (ii) are not subject to any unnecessary delay, interference, or any other action that could impede receipt by all of the [appropriate Federal entities](/usc/6/1501.md?p=3); and
      - (iii) may be provided to other [Federal entities](/usc/6/1501.md?p=8); and
    - (C) ensure there are—
      - (i) audit capabilities; and
      - (ii) appropriate sanctions in place for officers, employees, or agents of a [Federal entity](/usc/6/1501.md?p=8) who knowingly and willfully conduct activities under this subchapter in an unauthorized manner.
  - (4) **Guidelines for entities sharing cyber threat indicators with Federal Government—**
    - (A) **In general—** Not later than 60 days after December 18, 2015, the Attorney General and the [Secretary](/usc/6/101.md?p=16) of [Homeland](/usc/6/101.md?p=1) Security shall jointly develop and make publicly available guidance to assist [entities](/usc/6/301c.md?p=2) and promote sharing of [cyber threat indicators](/usc/6/1501.md?p=6) with [Federal entities](/usc/6/1501.md?p=8) under this subchapter.
    - (B) **Contents—** The guidelines developed and made publicly available under [subparagraph (A)](#a-4-A) shall include guidance on the following:
      - (i) Identification of types of information that would qualify as a [cyber threat indicator](/usc/6/1501.md?p=6) under this subchapter that would be unlikely to include information that—
        - (I) is not directly related to a [cybersecurity threat](/usc/6/1501.md?p=5); and
        - (II) is personal information of a specific individual or information that identifies a specific individual.
      - (ii) Identification of types of information protected under otherwise applicable privacy laws that are unlikely to be directly related to a [cybersecurity threat](/usc/6/1501.md?p=5).
      - (iii) Such other matters as the Attorney General and the [Secretary](/usc/6/101.md?p=16) of [Homeland](/usc/6/101.md?p=1) Security consider appropriate for [entities](/usc/6/301c.md?p=2) sharing [cyber threat indicators](/usc/6/1501.md?p=6) with [Federal entities](/usc/6/1501.md?p=8) under this subchapter.
- (b) **Privacy and civil liberties—**
  - (1) **Interim guidelines—** Not later than 60 days after December 18, 2015, the Attorney General and the [Secretary](/usc/6/101.md?p=16) of [Homeland](/usc/6/101.md?p=1) Security shall, in consultation with heads of the [appropriate Federal entities](/usc/6/1501.md?p=3) and in consultation with officers designated under [section 2000ee–1 of title 42](/usc/42/2000ee–1.md), jointly develop, submit to Congress, and make available to the public interim guidelines relating to privacy and civil liberties which shall govern the receipt, retention, use, and dissemination of [cyber threat indicators](/usc/6/1501.md?p=6) by a [Federal entity](/usc/6/1501.md?p=8) obtained in connection with activities authorized in this subchapter.
  - (2) **Final guidelines—**
    - (A) **In general—** Not later than 180 days after December 18, 2015, the Attorney General and the [Secretary](/usc/6/101.md?p=16) of [Homeland](/usc/6/101.md?p=1) Security shall, in coordination with heads of the [appropriate Federal entities](/usc/6/1501.md?p=3) and in consultation with officers designated under [section 2000ee–1 of title 42](/usc/42/2000ee–1.md) and such [private entities](/usc/6/1501.md?p=15-A) with industry expertise as the Attorney General and the [Secretary](/usc/6/101.md?p=16) consider relevant, jointly issue and make publicly available final guidelines relating to privacy and civil liberties which shall govern the receipt, retention, use, and dissemination of [cyber threat indicators](/usc/6/1501.md?p=6) by a [Federal entity](/usc/6/1501.md?p=8) obtained in connection with activities authorized in this subchapter.
    - (B) **Periodic review—** The Attorney General and the [Secretary](/usc/6/101.md?p=16) of [Homeland](/usc/6/101.md?p=1) Security shall, in coordination with heads of the [appropriate Federal entities](/usc/6/1501.md?p=3) and in consultation with officers and [private entities](/usc/6/1501.md?p=15-A) described in [subparagraph (A)](#b-2-A), periodically, but not less frequently than once every 2 years, jointly review the guidelines issued under [subparagraph (A)](#b-2-A).
  - (3) **Content—** The guidelines required by paragraphs [(1)](#b-1) and [(2)](#b-2) shall, consistent with the need to protect [information systems](/usc/6/1501.md?p=9) from [cybersecurity threats](/usc/6/1501.md?p=5) and mitigate [cybersecurity threats](/usc/6/1501.md?p=5)—
    - (A) limit the effect on privacy and civil liberties of activities by the Federal Government under this subchapter;
    - (B) limit the receipt, retention, use, and dissemination of [cyber threat indicators](/usc/6/1501.md?p=6) containing personal information of specific individuals or information that identifies specific individuals, including by establishing—
      - (i) a process for the timely destruction of such information that is known not to be directly related to uses authorized under this subchapter; and
      - (ii) specific limitations on the length of any period in which a [cyber threat indicator](/usc/6/1501.md?p=6) may be retained;
    - (C) include requirements to safeguard [cyber threat indicators](/usc/6/1501.md?p=6) containing personal information of specific individuals or information that identifies specific individuals from unauthorized access or acquisition, including appropriate sanctions for activities by officers, employees, or agents of the Federal Government in contravention of such guidelines;
    - (D) consistent with this subchapter, any other applicable provisions of law, and the fair information practice principles set forth in appendix A of the document entitled “National Strategy for Trusted Identities in Cyberspace” and published by the President in April 2011, govern the retention, use, and dissemination by the Federal Government of [cyber threat indicators](/usc/6/1501.md?p=6) shared with the Federal Government under this subchapter, including the extent, if any, to which such [cyber threat indicators](/usc/6/1501.md?p=6) may be used by the Federal Government;
    - (E) include procedures for notifying [entities](/usc/6/301c.md?p=2) and [Federal entities](/usc/6/1501.md?p=8) if information received pursuant to this section is known or determined by a [Federal entity](/usc/6/1501.md?p=8) receiving such information not to constitute a [cyber threat indicator](/usc/6/1501.md?p=6);
    - (F) protect the confidentiality of [cyber threat indicators](/usc/6/1501.md?p=6) containing personal information of specific individuals or information that identifies specific individuals to the greatest extent practicable and require recipients to be informed that such indicators may only be used for purposes authorized under this subchapter; and
    - (G) include steps that may be needed so that dissemination of [cyber threat indicators](/usc/6/1501.md?p=6) is consistent with the protection of classified and other sensitive national security information.
- (c) **Capability and process within the Department of Homeland Security—**
  - (1) **In general—** Not later than 90 days after December 18, 2015, the [Secretary](/usc/6/101.md?p=16) of [Homeland](/usc/6/101.md?p=1) Security, in coordination with the heads of the [appropriate Federal entities](/usc/6/1501.md?p=3), shall develop and implement a capability and process within the [Department](/usc/6/101.md?p=5) of [Homeland](/usc/6/101.md?p=1) Security that—
    - (A) shall accept from any [non-Federal entity](/usc/6/1501.md?p=14-A) in real time [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7), pursuant to this section;
    - (B) shall, upon submittal of the certification under [paragraph (2)](#c-2) that such capability and process fully and effectively operates as described in such paragraph, be the process by which the Federal Government receives [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) under this subchapter that are shared by a [non-Federal entity](/usc/6/1501.md?p=14-A) with the Federal Government through electronic mail or media, an interactive form on an Internet website, or a real time, automated process between [information systems](/usc/6/1501.md?p=9) except—
      - (i) consistent with [section 1503 of this title](/usc/6/1503.md), communications between a [Federal entity](/usc/6/1501.md?p=8) and a [non-Federal entity](/usc/6/1501.md?p=14-A) regarding a previously shared [cyber threat indicator](/usc/6/1501.md?p=6) to describe the relevant [cybersecurity threat](/usc/6/1501.md?p=5) or develop a [defensive measure](/usc/6/1501.md?p=7) based on such [cyber threat indicator](/usc/6/1501.md?p=6); and
      - (ii) communications by a regulated [non-Federal entity](/usc/6/1501.md?p=14-A) with such [entity](/usc/6/301c.md?p=2)’s Federal regulatory authority regarding a [cybersecurity threat](/usc/6/1501.md?p=5);
    - (C) ensures that all of the [appropriate Federal entities](/usc/6/1501.md?p=3) receive in an automated manner such [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) shared through the real-time process within the [Department](/usc/6/101.md?p=5) of [Homeland](/usc/6/101.md?p=1) Security;
    - (D) is in compliance with the policies, procedures, and guidelines required by this section; and
    - (E) does not limit or prohibit otherwise lawful disclosures of communications, records, or other information, including—
      - (i) reporting of known or suspected criminal activity, by a [non-Federal entity](/usc/6/1501.md?p=14-A) to any other [non-Federal entity](/usc/6/1501.md?p=14-A) or a [Federal entity](/usc/6/1501.md?p=8), including [cyber threat indicators](/usc/6/1501.md?p=6) or [defensive measures](/usc/6/1501.md?p=7) shared with a [Federal entity](/usc/6/1501.md?p=8) in furtherance of opening a Federal law enforcement investigation;
      - (ii) [voluntary](/usc/6/671.md?p=6-A) or legally compelled participation in a Federal investigation; and
      - (iii) providing [cyber threat indicators](/usc/6/1501.md?p=6) or [defensive measures](/usc/6/1501.md?p=7) as part of a statutory or authorized contractual requirement.
  - (2) **Certification and designation—**
    - (A) **Certification of capability and process—** Not later than 90 days after December 18, 2015, the [Secretary](/usc/6/101.md?p=16) of [Homeland](/usc/6/101.md?p=1) Security shall, in consultation with the heads of the [appropriate Federal entities](/usc/6/1501.md?p=3), submit to Congress a certification as to whether the capability and process required by [paragraph (1)](#c-1) fully and effectively operates—
      - (i) as the process by which the Federal Government receives from any [non-Federal entity](/usc/6/1501.md?p=14-A) a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) under this subchapter; and
      - (ii) in accordance with the interim policies, procedures, and guidelines developed under this subchapter.
    - (B) **Designation—**
      - (i) **In general—** At any time after certification is submitted under [subparagraph (A)](#c-2-A), the President may designate an appropriate [Federal entity](/usc/6/1501.md?p=8), other than the [Department](/usc/6/101.md?p=5) of Defense (including the National Security [Agency](/usc/6/1501.md?p=1)), to develop and implement a capability and process as described in [paragraph (1)](#c-1) in addition to the capability and process developed under such paragraph by the [Secretary](/usc/6/101.md?p=16) of [Homeland](/usc/6/101.md?p=1) Security, if, not fewer than 30 days before making such designation, the President submits to Congress a certification and explanation that—
        - (I) such designation is necessary to ensure that full, effective, and secure operation of a capability and process for the Federal Government to receive from any [non-Federal entity](/usc/6/1501.md?p=14-A) [cyber threat indicators](/usc/6/1501.md?p=6) or [defensive measures](/usc/6/1501.md?p=7) under this subchapter;
        - (II) the designated appropriate [Federal entity](/usc/6/1501.md?p=8) will receive and share [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) in accordance with the policies, procedures, and guidelines developed under this subchapter, including [subsection (a)(3)(A)](#a-3-A); and
        - (III) such designation is consistent with the mission of such appropriate [Federal entity](/usc/6/1501.md?p=8) and improves the ability of the Federal Government to receive, share, and use [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) as authorized under this subchapter.
      - (ii) **Application to additional capability and process—** If the President designates an appropriate [Federal entity](/usc/6/1501.md?p=8) to develop and implement a capability and process under [clause (i)](#c-2-B-i), the provisions of this subchapter that apply to the capability and process required by [paragraph (1)](#c-1) shall also be construed to apply to the capability and process developed and implemented under [clause (i)](#c-2-B-i).
  - (3) **Public notice and access—** The [Secretary](/usc/6/101.md?p=16) of [Homeland](/usc/6/101.md?p=1) Security shall ensure there is public notice of, and access to, the capability and process developed and implemented under [paragraph (1)](#c-1) so that—
    - (A) any [non-Federal entity](/usc/6/1501.md?p=14-A) may share [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) through such process with the Federal Government; and
    - (B) all of the [appropriate Federal entities](/usc/6/1501.md?p=3) receive such [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) in real time with receipt through the process within the [Department](/usc/6/101.md?p=5) of [Homeland](/usc/6/101.md?p=1) Security consistent with the policies and procedures issued under [subsection (a)](#a).
  - (4) **Other Federal entities—** The process developed and implemented under [paragraph (1)](#c-1) shall ensure that other [Federal entities](/usc/6/1501.md?p=8) receive in a timely manner any [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) shared with the Federal Government through such process.
- (d) **Information shared with or provided to the Federal Government—**
  - (1) **No waiver of privilege or protection—** The provision of [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) to the Federal Government under this subchapter shall not constitute a waiver of any applicable privilege or protection provided by law, including trade secret protection.
  - (2) **Proprietary information—** Consistent with [section 1503(c)(2) of this title](/usc/6/1503.md?p=c-2) and any other applicable provision of law, a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) provided by a [non-Federal entity](/usc/6/1501.md?p=14-A) to the Federal Government under this subchapter shall be considered the commercial, financial, and proprietary information of such [non-Federal entity](/usc/6/1501.md?p=14-A) when so designated by the originating [non-Federal entity](/usc/6/1501.md?p=14-A) or a third party acting in accordance with the written authorization of the originating [non-Federal entity](/usc/6/1501.md?p=14-A).
  - (3) **Exemption from disclosure—** A [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) shared with the Federal Government under this subchapter shall be—
    - (A) deemed voluntarily shared information and exempt from disclosure under [section 552 of title 5](/usc/5/552.md) and any [State](/usc/6/101.md?p=17), [tribal](/usc/6/1501.md?p=18), or local provision of law requiring disclosure of information or records; and
    - (B) withheld, without discretion, from the public under [section 552(b)(3)(B) of title 5](/usc/5/552.md?p=b-3-B) and any [State](/usc/6/101.md?p=17), [tribal](/usc/6/1501.md?p=18), or local provision of law requiring disclosure of information or records.
  - (4) **Ex parte communications—** The provision of a [cyber threat indicator](/usc/6/1501.md?p=6) or [defensive measure](/usc/6/1501.md?p=7) to the Federal Government under this subchapter shall not be subject to a rule of any [Federal agency](/usc/6/677a.md?p=4) or [department](/usc/6/101.md?p=5) or any judicial doctrine regarding ex parte communications with a decision-making official.
  - (5) **Disclosure, retention, and use—**
    - (A) **Authorized activities—** [Cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) provided to the Federal Government under this subchapter may be disclosed to, retained by, and used by, consistent with otherwise applicable provisions of Federal law, any [Federal agency](/usc/6/677a.md?p=4) or [department](/usc/6/101.md?p=5), component, officer, employee, or agent of the Federal Government solely for—
      - (i) a [cybersecurity purpose](/usc/6/1501.md?p=4);
      - (ii) the purpose of identifying—
        - (I) a [cybersecurity threat](/usc/6/1501.md?p=5), including the source of such [cybersecurity threat](/usc/6/1501.md?p=5); or
        - (II) a [security vulnerability](/usc/6/1501.md?p=17);
      - (iii) the purpose of responding to, or otherwise preventing or mitigating, a specific threat of death, a specific threat of serious bodily harm, or a specific threat of serious economic harm, including a terrorist act or a use of a weapon of mass destruction;
      - (iv) the purpose of responding to, investigating, prosecuting, or otherwise preventing or mitigating, a serious threat to a minor, including sexual exploitation and threats to physical safety; or
      - (v) the purpose of preventing, investigating, disrupting, or prosecuting an offense arising out of a threat described in [clause (iii)](#d-5-A-iii) or any of the offenses listed in—
        - (I) sections [1028](/usc/18/1028.md) through [1030](/usc/18/1030.md) of title 18 (relating to fraud and identity theft);
        - (II) chapter 37 of such title (relating to espionage and censorship); and
        - (III) chapter 90 of such title (relating to protection of trade secrets).
    - (B) **Prohibited activities—** [Cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) provided to the Federal Government under this subchapter shall not be disclosed to, retained by, or used by any [Federal agency](/usc/6/677a.md?p=4) or [department](/usc/6/101.md?p=5) for any use not permitted under [subparagraph (A)](#d-5-A).
    - (C) **Privacy and civil liberties—** [Cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) provided to the Federal Government under this subchapter shall be retained, used, and disseminated by the Federal Government—
      - (i) in accordance with the policies, procedures, and guidelines required by subsections [(a)](#a) and [(b)](#b);
      - (ii) in a manner that protects from unauthorized use or disclosure any [cyber threat indicators](/usc/6/1501.md?p=6) that may contain—
        - (I) personal information of a specific individual; or
        - (II) information that identifies a specific individual; and
      - (iii) in a manner that protects the confidentiality of [cyber threat indicators](/usc/6/1501.md?p=6) containing—
        - (I) personal information of a specific individual; or
        - (II) information that identifies a specific individual.
    - (D) **Federal regulatory authority—**
      - (i) **In general—** Except as provided in [clause (ii)](#d-5-D-ii), [cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) provided to the Federal Government under this subchapter shall not be used by any Federal, [State](/usc/6/101.md?p=17), [tribal](/usc/6/1501.md?p=18), or [local government](/usc/6/1501.md?p=10) to regulate, including an enforcement action, the lawful activities of any [non-Federal entity](/usc/6/1501.md?p=14-A) or any activities taken by a [non-Federal entity](/usc/6/1501.md?p=14-A) pursuant to mandatory standards, including activities relating to monitoring, operating [defensive measures](/usc/6/1501.md?p=7), or sharing [cyber threat indicators](/usc/6/1501.md?p=6).
      - (ii) **Exceptions—**
        - (I) **Regulatory authority specifically relating to prevention or mitigation of cybersecurity threats—** [Cyber threat indicators](/usc/6/1501.md?p=6) and [defensive measures](/usc/6/1501.md?p=7) provided to the Federal Government under this subchapter may, consistent with Federal or [State](/usc/6/101.md?p=17) regulatory authority specifically relating to the prevention or mitigation of [cybersecurity threats](/usc/6/1501.md?p=5) to [information systems](/usc/6/1501.md?p=9), inform the development or implementation of regulations relating to such [information systems](/usc/6/1501.md?p=9).
        - (II) **Procedures developed and implemented under this subchapter—** [Clause (i)](#d-5-D-i) shall not apply to procedures developed and implemented under this subchapter.

## Source credit

(Pub. L. 114–113, div. N, title I, § 105, Dec. 18, 2015, 129 Stat. 2943.)
