6 U.S.C. § 1503
Authorizations for preventing, detecting, analyzing, and mitigating cybersecurity threats
United States · Title 6 — DOMESTIC SECURITY · Status: effective
Cite this
- Citation
- 6 U.S.C. § 1503, Authorizations for preventing, detecting, analyzing, and mitigating cybersecurity threats, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/428383
- Permanent ID
ys:prov:428383@1- SHA-256
492e3dd18db8e8ed8c40c3552065b0639160063ab7f78771b43e76fe15ce107e
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
Notwithstanding any other provision of law, a private entity may, for cybersecurity purposes, monitor—
Nothing in this subsection shall be construed—
Notwithstanding any other provision of law, a private entity may, for cybersecurity purposes, operate a defensive measure that is applied to—
Nothing in this subsection shall be construed—
Except as provided in paragraph (2) and notwithstanding any other provision of law, a non-Federal entity may, for a cybersecurity purpose and consistent with the protection of classified information, share with, or receive from, any other non-Federal entity or the Federal Government a cyber threat indicator or defensive measure.
A non-Federal entity receiving a cyber threat indicator or defensive measure from another non-Federal entity or a Federal entity shall comply with otherwise lawful restrictions placed on the sharing or use of such cyber threat indicator or defensive measure by the sharing non-Federal entity or Federal entity.
Nothing in this subsection shall be construed—
A non-Federal entity monitoring an information system, operating a defensive measure, or providing or receiving a cyber threat indicator or defensive measure under this section shall implement and utilize a security control to protect against unauthorized access to or acquisition of such cyber threat indicator or defensive measure.
A non-Federal entity sharing a cyber threat indicator pursuant to this subchapter shall, prior to such sharing—
Consistent with this subchapter, a cyber threat indicator or defensive measure shared or received under this section may, for cybersecurity purposes—
be used by a non-Federal entity to monitor or operate a defensive measure that is applied to—
be otherwise used, retained, and further shared by a non-Federal entity subject to—
Nothing in this paragraph shall be construed to authorize the use of a cyber threat indicator or defensive measure other than as provided in this section.
A State, tribal, or local government that receives a cyber threat indicator or defensive measure under this subchapter may use such cyber threat indicator or defensive measure for the purposes described in section 1504(d)(5)(A) of this title.
A cyber threat indicator or defensive measure shared by or with a State, tribal, or local government, including a component of a State, tribal, or local government that is a private entity, under this section shall be—
Except as provided in clause (ii), a cyber threat indicator or defensive measure shared with a State, tribal, or local government under this subchapter shall not be used by any State, tribal, or local government to regulate, including an enforcement action, the lawful activity of any non-Federal entity or any activity taken by a non-Federal entity pursuant to mandatory standards, including an activity relating to monitoring, operating a defensive measure, or sharing of a cyber threat indicator.
A cyber threat indicator or defensive measure shared as described in clause (i) may, consistent with a State, tribal, or local government regulatory authority specifically relating to the prevention or mitigation of cybersecurity threats to information systems, inform the development or implementation of a regulation relating to such information systems.
Except as provided in section 1507(e) of this title, it shall not be considered a violation of any provision of antitrust laws for 2 or more private entities to exchange or provide a cyber threat indicator or defensive measure, or assistance relating to the prevention, investigation, or mitigation of a cybersecurity threat, for cybersecurity purposes under this subchapter.
Paragraph (1) shall apply only to information that is exchanged or assistance provided in order to assist with—
The sharing of a cyber threat indicator or defensive measure with a non-Federal entity under this subchapter shall not create a right or benefit to similar information by such non-Federal entity or any other non-Federal entity.
Legislative history
The public laws that enacted or amended this section. Tallies are for the whole bill as it passed each chamber — often an omnibus covering far more than this provision — not a vote on this section alone.
- Consolidated Appropriations Act, 2016