6 U.S.C. § 673
Protection of voluntarily shared critical infrastructure information
United States · Title 6 — DOMESTIC SECURITY · Status: effective
Cite this
- Citation
- 6 U.S.C. § 673, Protection of voluntarily shared critical infrastructure information, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/428175
- Permanent ID
ys:prov:428175@1- SHA-256
5e409f83fdb63a4bb89f80899f458ba976a0574e96e643f1602b9592d74d2033
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
Notwithstanding any other provision of law, critical infrastructure information (including the identity of the submitting person or entity) that is voluntarily submitted to a covered Federal agency for use by that agency regarding the security of critical infrastructure and protected systems, analysis, warning, interdependency study, recovery, reconstitution, or other informational purpose, when accompanied by an express statement specified in paragraph (2)—
shall not, without the written consent of the person or entity submitting such information, be used or disclosed by any officer or employee of the United States for purposes other than the purposes of this part, except—
when disclosure of the information would be—
shall not, if provided to a State or local government or government agency—
For purposes of paragraph (1), the term “express statement”, with respect to information or records, means—
No communication of critical infrastructure information to a covered Federal agency made pursuant to this part shall be considered to be an action subject to the requirements of chapter 10 of title 5.
Nothing in this section shall be construed to limit or otherwise affect the ability of a State, local, or Federal Government entity, agency, or authority, or any third party, under applicable law, to obtain critical infrastructure information in a manner not covered by subsection (a), including any information lawfully and properly disclosed generally or broadly to the public and to use such information in any manner permitted by law. For purposes of this section a permissible use of independently obtained information includes the disclosure of such information under section 2302(b)(8) of title 5.
The voluntary submittal to the Government of information or records that are protected from disclosure by this part shall not be construed to constitute compliance with any requirement to submit such information to a Federal agency under any other provision of law.
The Secretary of the Department of Homeland Security shall, in consultation with appropriate representatives of the National Security Council and the Office of Science and Technology Policy, establish uniform procedures for the receipt, care, and storage by Federal agencies of critical infrastructure information that is voluntarily submitted to the Government. The procedures shall be established not later than 90 days after November 25, 2002.
The procedures established under paragraph (1) shall include mechanisms regarding—
Whoever, being an officer or employee of the United States or of any department or agency thereof, knowingly publishes, divulges, discloses, or makes known in any manner or to any extent not authorized by law, any critical infrastructure information protected from disclosure by this part coming to him in the course of this employment or official duties or by reason of any examination or investigation made by, or return, report, or record made to or filed with, such department or agency or officer or employee thereof, shall be fined under title 18, imprisoned not more than 1 year, or both, and shall be removed from office or employment.
The Federal Government may provide advisories, alerts, and warnings to relevant companies, targeted sectors, other governmental entities, or the general public regarding potential threats to critical infrastructure as appropriate. In issuing a warning, the Federal Government shall take appropriate actions to protect from disclosure—
The President may delegate authority to a critical infrastructure protection program, designated under section 672 of this title, to enter into a voluntary agreement to promote critical infrastructure security, including with any Information Sharing and Analysis Organization, or a plan of action as otherwise defined in section 4558 of title 50.
Legislative history
The public laws that enacted or amended this section. Tallies are for the whole bill as it passed each chamber — often an omnibus covering far more than this provision — not a vote on this section alone.
- Homeland Security Act of 2002
- GAO Human Capital Reform Act of 2004House: 382–43Senate: no recorded tally
- Whistleblower Protection Enhancement Act of 2012House: no recorded tallySenate: no recorded tally
- Cybersecurity and Infrastructure Security Agency Act of 2018House: no recorded tallySenate: no recorded tally
- To make revisions in title 5, United States Code, as necessary to keep the title current, and to make technical amendments to improve the United States Code.House: 413–3Senate: no recorded tally