CISA Is Now Law—What It Means for Your Organization

Patterson Belknap Webb & Tyler LLP
Contact

After several fits and starts, Congress finally passed the Cyber Information Sharing Act of 2015 (CISA) as part of the omnibus budget bill.  President Obama signed the bill into law on December 18, 2015.

CISA allows—but does not require—companies to share certain cybersecurity information with the NSA and other federal agencies, where that information is necessary to identify malicious intrusions, security vulnerabilities, or other enumerated “cyber threat indicators.”  Supporters of the legislation argue that this type of information-sharing is critical to protecting American citizens and businesses from potentially disastrous cyber attacks.

The law also includes a controversial provision that limits civil liability for companies who participate in CISA’s information-sharing framework.  Many privacy advocates objected to this provision on the grounds that it seems to exempt these companies from complying with other privacy laws.  More generally, critics—including many in the tech industry, such as Apple and Twitter—have expressed concern that CISA tips the scales too much toward security at the expense of users’ privacy.

The law will not go into effect immediately because the relevant federal agencies have 60 days to announce procedures and policies for implementing CISA’s information-sharing goals.  Nevertheless, it is not too soon for any organizations considering whether to submit information to the portal to begin to develop internal procedures for identifying and reporting that information.  Crucial to those procedures is the need for a system in place for scrubbing the data of personally identifiable information—otherwise, the statutory safe harbor will not apply and your organization may expose itself to civil liability.

We will continue to report on ongoing developments related to CISA’s implementation.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Patterson Belknap Webb & Tyler LLP

Written by:

Patterson Belknap Webb & Tyler LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Patterson Belknap Webb & Tyler LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide