# Cybersecurity and Information Sharing: Legal Challenges and Solutions

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/crs%3AR43941

## Record

- **Collection:** Congressional research report
- **Document type:** CRS Report
- **Published:** March 16, 2015
- **Citation:** R43941

## Text

Cybersecurity and Information Sharing:
Legal Challenges and Solutions
-name redactedLegislative Attorney
March 16, 2015

Congressional Research Service
7-....
www.crs.gov
R43941

Cybersecurity and Information Sharing: Legal Challenges and Solutions

Summary
Over the course of the last year, a host of cyberattacks has been perpetrated on a number of high
profile American companies. The high profile cyberattacks of 2014 and early 2015 appear to be
indicative of a broader trend: the frequency and ferocity of cyberattacks are increasing, posing
grave threats to the national interests of the United States. While considerable debate exists with
regard to the best strategies for protecting America’s various cyber-systems and promoting
cybersecurity, one point of general agreement amongst cyber-analysts is the perceived need for
enhanced and timely exchange of cyber-threat intelligence both within the private sector and
between the private sector and the government. Nonetheless, there are many reasons why entities
may opt to not participate in a cyber-information sharing scheme, including the potential liability
that could result from sharing internal cyber-threat information with other private companies or
the government. More broadly, the legal issues surrounding cybersecurity information sharing—
whether it be with regard to sharing between two private companies or the dissemination of
cyber-intelligence within the federal government—are complex and have few certain resolutions.
In this vein, this report examines the various legal issues that arise with respect to the sharing of
cybersecurity intelligence, with a special focus on two distinct concepts: (1) sharing of cyberinformation within the government’s possession and (2) sharing of cyber-information within the
possession of the private sector.
With regard to cyber-intelligence that is possessed by the federal government, the legal landscape
is relatively clear: ample legal authority exists for the Department of Homeland Security (DHS)
to serve as the central repository and distributor of cyber-intelligence for the federal government.
Nonetheless, the legal authorities that do exist often overlap, perhaps resulting in confusion as to
which of the multiple sub-agencies within DHS or even outside of DHS should be leading efforts
on the distribution of cyber-information within the government and with the public. Moreover,
while the government has wide authority to disclose cyber-intelligence within its possession, that
authority is not limitless and is necessarily tied to laws that restrict the government’s ability to
release sensitive information within its possession.
With regard to cyber-intelligence that is possessed by the private sector, legal issues are clouded
with uncertainty. A private entity that wishes to share cyber-intelligence with another company, an
information sharing organization like an Information Sharing and Analysis Organization (ISAO)
or an Information Sharing and Analysis Centers (ISAC), or the federal government may be
exposed to civil or even criminal liability from a variety of different federal and state laws.
Moreover, because of the uncertainty that pervades the interplay between laws of general
applicability—like federal antitrust or privacy law—and their specific application to cyberintelligence sharing, it may be very difficult for any private entity to accurately assess potential
liability that could arise by participating in a sharing scheme. In addition, concerns may arise with
regard to how the government collects and maintains privately held cyber-intelligence, including
fears that the information disclosed to the government could (1) be released through a public
records request; (2) result in the forfeit of certain intellectual property rights; (3) be used against a
private entity in a subsequent regulatory action; or (4) risk the privacy rights of individuals whose
information may be encompassed in disclosed cyber-intelligence.
The report concludes by examining the major legislative proposal—including the Cyber
Intelligence Sharing and Protection Act (CISPA), Cybersecurity Information Sharing Act (CISA),
and the Cyber Threat Sharing Act (CTSA)—and the potential legal issues that such laws could
prompt.

Congressional Research Service

Cybersecurity and Information Sharing: Legal Challenges and Solutions

Contents
Introduction...................................................................................................................................... 1
Conceptualizing the Legal Issues Regarding Cyber Information Sharing ....................................... 5
Sharing Cyber-Information in the Possession of the Government .................................................. 6
Sharing Cyber-Information in the Possession of Private Entities .................................................. 12
Sharing Cyber-Information with Another Private Entity......................................................... 13
Privacy Laws ..................................................................................................................... 13
Antitrust Laws ................................................................................................................... 26
Tort Law ............................................................................................................................ 29
Other Sources of Liability ................................................................................................. 32
Sharing Cyber -Information with the Government.................................................................. 33
Freedom of Information Act Disclosures .......................................................................... 34
Intellectual Property Concerns .......................................................................................... 36
Regulatory Enforcement Concerns ................................................................................... 37
Privacy Concerns............................................................................................................... 39
Legislative Options for Cyber-Information Sharing ...................................................................... 43
Creating a Broader Legal Framework for the Sharing of Cyber-Information ......................... 43
Clarifying Which Government Agency Leads the Efforts on Cyber-Information
Sharing ................................................................................................................................. 46
Increasing the Amount and Quality of Government Cyber-Information Disclosed to
the Private Sector.................................................................................................................. 47
Minimizing Liability Related to Distributing Privately Held Cyber-Intelligence ................... 48
“Tailored” Approach to Minimizing Liability ................................................................... 49
“Broad” Approach to Minimizing Liability ...................................................................... 50
Increasing the Participation of Private Sector Cyber-Information Sharing ............................. 52
Preventing Government Misuse of Acquired Cyber-Intelligence............................................ 55
Conclusion ..................................................................................................................................... 59

Contacts
Author Contact Information........................................................................................................... 59

Congressional Research Service

Cybersecurity and Information Sharing: Legal Challenges and Solutions

Introduction
Over the course of the last year, a host of cyberattacks1 have been perpetrated on a number of
high profile American companies. In January 2014, Target announced that hackers, using
malware,2 had digitally impersonated one of the retail giant’s contractors,3 stealing vast amounts
of data—including the names, mailing addresses, phone numbers or email addresses for up to 70
million individuals and the credit card information of 40 million shoppers.4 Cyberattacks in
February and March of 2014 potentially exposed contact and log-in information of eBay’s
customers, prompting the online retailer to ask its more than 200 million users to change their
passwords.5 In September, it was revealed that over the course of five months cyber-criminals
tried to steal the credit card information of more than fifty million shoppers of the world’s largest
home improvement retailer, Home Depot.6 One month later, J.P. Morgan Chase, the largest U.S.
bank by assets, disclosed that contact information for about 76 million households was captured
in a cyberattack earlier in the year.7 In perhaps the most infamous cyberattack of 2014, in late
November, Sony Pictures Entertainment suffered a “significant system disruption” as a result of a
“brazen cyber attack”8 that resulted in the leaking of the personal details of thousands of Sony
employees.9 And in February of 2015, the health care provider Anthem Blue Cross Blue Shield
1
For purposes of this report, the term “cyberattack” refers to a deliberate infiltration of a computer system or network
with the intent to either extract or destroy confidential information or to destroy the functioning of the system or
network. See Jay P. Kesan and Carol M. Hayes, Mitigative Counterstriking: Self-Defense and Deterrence in
Cyberspace, 25 HARV. J.L. & TECH. 429, 439-446 (2012). It should be noted however the exact contours of what the
term “cyberattack” entails is subject to much debate. See id. at 439 (“The modern lexicon considers all types of online
intrusions to be cyberattacks, even though many commentators would assert that such indiscriminate use of the term
‘cyberattack’ is incorrect.”); see also William A. Owens, Kenneth W. Dam, and Herbert S. Lin, et al., Overview,
Findings, and Recommendations, in TECHNOLOGY, POLICY, LAW, AND ETHICS REGARDING U.S. ACQUISITION AND USE
OF CYBERATTACK CAPABILITIES 10-11(2009) (distinguishing between the terms “cyberattack” and “cyber
exploitation”); Oona A. Hathaway et al., The Law of Cyber-Attack, 100 CALIF. L. REV. 817, 823 (2012). (“The absence
of a shared definition has made it difficult for analysts from different countries to develop coordinated policy
recommendations and for governments to engage in coordinated actions.”)
2
Malware is the diminutive for malicious software and can come in a wide variety of forms. See generally Rick
Lehtinen, Deborah Russell, and G.T. Gangemi Sr., COMPUTER SECURITY BASICS 80 (2d ed. 2006); see also Matthew J.
Skelrov, Solving the Dilemma of State Responses to Cyberattacks: A Justification for the Use of Active Defenses
Against States Who Neglect Their Duty to Prevent, 201 ML. L. REV. 1, 15 n.78. (2009).
3
See Dan Goodin, Epic Target hack reportedly began with malware-based phishing email, ARS TECHNICA, (February
12, 2014), http://arstechnica.com/security/2014/02/epic-target-hack-reportedly-began-with-malware-based-phishing-email/.
4
See Press Release, Target Provides Update on Data Breach and Financial Performance, (January 10, 2014),
available at http://pressroom.target.com/news/target-provides-update-on-data-breach-and-financial-performance.
5
See Press Release, eBay Inc. To Ask eBay Users To Change Passwords, (May 21, 2014), available at
http://www.ebayinc.com/in_the_news/story/ebay-inc-ask-ebay-users-change-passwords.
6
See Press Release, The Home Depot Completes Malware Elimination and Enhanced Encryption of Payment Data in
All U.S. Stores, (September 18, 2014), available at http://www.prnewswire.com/news-releases/the-home-depotcompletes-malware-elimination-and-enhanced-encryption-of-payment-data-in-all-us-stores-275649511.html.
7
See Emily Glazer and Daniel Yadron, J.P. Morgan Says About 76 Million Households Affected By Cyber Breach,
WALL STREET JOURNAL (October 2, 2014), available at http://www.wsj.com/articles/j-p-morgan-says-about-76-millionhouseholds-affected-by-cyber-breach-1412283372.
8
See Press Release, Message for current and former Sony Pictures employees and dependents, and for production
employees, (December 15, 2014), available at http://www.sonypictures.net/SPE_Cyber_Notification.pdf?.
9
See Amelia Smith, Sony Cyber Attack One of Worst in Corporate History, NEWSWEEK, (December 4, 2014), available
at http://www.newsweek.com/sony-cyber-attack-worst-corporate-history-thousands-files-are-leaked-289230.

Congressional Research Service

1

Cybersecurity and Information Sharing: Legal Challenges and Solutions

disclosed that a “very sophisticated attack” obtained personal information relating to the
company’s customers and employees.10
The high profile cyberattacks of 2014 and early 2015 appear to be indicative of a broader trend:
the frequency and ferocity of cyberattacks are increasing,11 posing grave threats to the national
interests of the United States. Indeed, the attacks on Target, eBay, Home Depot, J.P. MorganChase, Sony Pictures, and Anthem were only a few of the many publicly disclosed cyberattacks
perpetrated in 2014 and 2105.12 Experts suggest that hundreds of thousands of other entities may
have suffered similar incidents during the same period,13 with one survey indicating that 43% of
firms in the United States had experienced a data breach in the past year.14 Moreover, just as the
cyberattacks of 2013—which included incidents involving companies like the New York Times,
Facebook, Twitter, Apple, and Microsoft15—were eclipsed by those that occurred in 2014,16 the
consensus view is that 2015 and beyond will witness more frequent and more sophisticated cyber
incidents.17 To the extent that its expected rise outpaces any corresponding rise in the ability to
defend against such attacks, the result could be troubling news for countless businesses that rely
more and more on computers in all aspects of their operations, as the economic losses resulting
from a single cyberattack can be extremely costly.18 And the resulting effects of a cyberattack can
have effects beyond a single company’s bottom line. As “nations are becoming ever more
dependent on information and information technology,”19 the threat posed by any one cyberattack
10

See Press Release, Statement regarding cyberattack against Anthem, (February 11, 2015), available at
https://www.anthem.com/health-insurance/about-us/pressreleasedetails/WI/2015/1813/statement-regarding-cyberattack-against-anthem.
11
See generally Managing cyber risks in an interconnected world, PRICEWATERHOUSECOOPERS, 5, (September 30,
2014) available at http://www.pwc.com/gx/en/consulting-services/information-security-survey/index.jhtml (noting that
in a survey of 9,700 security, IT, and business executives in 154 countries, cybersecurity incidents have risen 66%
since 2009).
12
See 2014: A Year of Mega Breaches, PONEMON INSTITUTE, 1, (January 2015) available at http://www.ponemon.org/
local/upload/file/2014%20The%20Year%20of%20the%20Mega%20Breach%20FINAL3.pdf (hereinafter “Ponemon
Institute- 2014”) (noting breaches at CHS community Health Systems, Michaels Stores, Nieman Marcus, and Staples).
13
See PRICEWATERHOUSE COOPERS, supra note 11, at 7 (estimating that globally 117,339 attacks occur each day).
14
See Is Your Company Ready for a Big Data Breach?, PONEMON INSTITUTE, 1, (September 2014), available at
http://www.experian.com/assets/data-breach/brochures/2014-ponemon-2nd-annual-preparedness.pdf (hereinafter
“Ponemon Institute- Big Data Breach”). This study, of course, only accounts for cyberattacks are actually discovered
by a given business. One cybersecurity expert estimates that 85% of cyberattacks go unnoticed for two or more weeks.
See Joshua R. McCloud, Cisco’s Internal Approach to Cyber Security, (February 2013), available at
http://www.cisco.com/web/AP/asiapac/academy/Archive/News_Feb.shtml.
15
Chenda Ngak, Are Facebook, Twitter, Apple, New York Times, NBC hacks a sign of things to come?, CBS NEWS,
February 22, 2013, http://www.cbsnews.com/8301-205_162-57570805/are-facebook-twitter-apple-new-york-timesnbc-hacks-a-sign-of-things-to-come/.
16
See Sharone Tobias, 2014: The Year in Cyberattacks, NEWSWEEK (December 31, 2014), available at
http://www.newsweek.com/2014-year-cyber-attacks-295876.
17
See Lee Raine, Janna Anderson, and Jennifer Connolly, Cyber Attacks Likely to Increase, PEW RESEARCH CENTER, 67 (October 29, 2014), available at http://www.pewinternet.org/files/2014/10/
PI_FutureofCyberattacks_102914_pdf.pdf/ (reporting that from a canvass of “thousands of experts and Internet
builders,” 61% predicted that by 2025 “a major cyber attack [will] cause[] widespread harm to a nation’s security and
capacity to defend itself and its people”); see also Threats Report, MCAFEE LABS, 6-14, (November 2014), available at
http://www.mcafee.com/us/resources/reports/rp-quarterly-threat-q3-2014.pdf (concluding that cyber threats will
increase in the year 2015); see also Arjun Khrarpal, Think 2014 was bad for hacking? Worse is to come, CNBC
(January 15, 2015), available at http://www.cnbc.com/id/102362835# (quoting Cisco CEO John Chambers).
18
See PRICEWATERHOUSE COOPERS, supra note 11, at 10 (noting that the “annual estimated reported average financial
loss attributed to cybersecurity incidents was $2.7 million, a jump of 34% over 2013”).
19
See Owens, supra note 1, at 9.

Congressional Research Service

2

Cybersecurity and Information Sharing: Legal Challenges and Solutions

can have “devastating collateral and cascading effects across a wide range of physical, economic
and social systems.”20 With reports that foreign nations—such as Russia, China, Iran, and North
Korea –may be using cyberspace as a new front to wage war,21 fears abound that a cyberattack
could be used to shut down the nation’s electrical grid,22 hijack a commercial airliner,23 or even
launch a nuclear weapon with a single keystroke.24 In short, the potential exists that the United
States could suffer a “cyber Pearl Harbor,” an attack that would “cause physical destruction and
loss of life”25 and expose—in the words of one prominent cybersecurity expert–“vulnerabilities of
staggering proportions.”26
Given the growing and potentially grave threat posed by cyberattacks, one of the stated priorities
of the President and congressional leadership is to enact laws that ensure that both the public and
private sector are prepared to meet the cyber-challenges of the future.27 While considerable debate
exists with regard to the best strategies and methods for protecting America’s various cybersystems,28 one point of “general agreement” amongst cyber-analysts is the perceived need for
enhanced and timely exchange of cyber-threat intelligence29 both within the private sector and
20

See Securing America’s Future: The Cyber Security Act of 2012: Hearing on S. 2105 Before the S. Comm. on
Homeland Sec. and Gov’t Affairs, 112th Cong. (2012) (statement of Michael Chertoff, former Sec’y of the Dep’t of
Homeland Sec.), available at http://www.hsgac.senate.gov/download/cybersecurity-support-statement-former-dhssecretary-michael-chertoff.
21
See Joel Brenner, How Obama Fell Short on Cyber Security, POLITICO MAGAZINE (January 21, 2015), available at
http://www.politico.com/magazine/story/2015/01/state-of-the-union-cybersecurity-obama114411.html#.VMlUeXtq3VY (noting the sources for various cyberattacks).
22
See Michael Hayden, Curt Hebert, and Susan Tierney, Cybersecurity and the North American Electric Grid: New
Policy Approaches to Address an Evolving Threat, BIPARTISAN POLICY CENTER, (February 28, 2014), available at
http://bipartisanpolicy.org/library/cybersecurity-electric-grid/ (“Cyber threats to North America’s electric grid are
growing, making electric grid cybersecurity an increasingly important national and international issue.”).
23
See Pierluigi Paganini, Cyber Threats against the Aviation Industry, INFOSEC INSTITUTE, (April 8, 2014), available at
http://resources.infosecinstitute.com/cyber-threats-aviation-industry/. (“Security is fundamental for the aviation
industry. Considering the availability of numerous tools on the market that could be exploited in a hypothetical attack
against a plane, cyber security is becoming even more crucial.”)
24
See Jason Koebler, U.S Nukes Face Up to 10 Million Cyber Attacks Daily, U.S. NEWS & WORLD REPORT, (March 20,
2014) (“The computer systems of the agency in charge of America’s nuclear weapons stockpile are “under constant
attack” and face millions of hacking attempts daily”).
25
See Leon E. Panetta, Sec’y, U.S. Dep’t of Def., Remarks on Cybersecurity to the Business Executives for National
Security, (October 11, 2012), available at http://www.defense.gov/transcripts/transcript.aspx?transcriptid=5136.
26
See Joel Brenner, AMERICA THE VULNERABLE 24 (2011). While there appears to be general agreement about United
States’ vulnerabilities to a cyberattack, see Nathan Sales, Regulating Cyber-Security, 107 NW. U. L. REV. 1503, 1505
(2013) (“There are some naysayers but the consensus that we stand on the brink of cyber-calamity is both broad
deep.”), this viewpoint is not unanimous. See, e.g., Jerry Brito and Tate Watkins, Loving the Cyber Bomb? The
Dangers of Threat Inflation in Cybersecurity Policy¸ 3 HARV. NAT. SEC. J. 39 (2011); Vida M. Antolin-Jenkins,
Defining the Parameters of Cyberwar Operations: Looking for Law in All the Wrong Places?, 51 NAVAL L. REV. 132,
144-45 (2005).
27
See, e.g., Steven Dennis, Obama Pushes for Deals on Cybersecurity, Trade, Taxes, ROLL CALL (January 13, 2015),
available at http://blogs.rollcall.com/white-house/obama-meeting-with-top-congressional-leaders-without-harry-reid/?
pos=adpb (“Obama says he’s spoken to Speaker John A. Boehner, R-Ohio, and Senate Majority Leader Mitch
McConnell, R-Ky., on cybersecurity and ‘I think we agreed that this is an area where we can work hard together, get
some legislation done and make sure that we are much more effective in protecting the American people from these
kinds of cyberattacks’”).
28
See generally Henry Farrell, The political science of cybersecurity I—why people fight so hard over cybersecurity,
WASHINGTON POST (January 13, 2014), available at http://www.washingtonpost.com/blogs/monkey-cage/wp/2014/01/
23/the-political-science-of-cybersecurity-i-why-people-fight-so-hard-over-cybersecurity/.
29
Throughout this report, use of terms “cyber-intelligence,” “cyber-information,” “cyber-threat information,” and
“cybersecurity information” are used to holistically capture the entire range of possible information that could help
(continued...)

Congressional Research Service

3

Cybersecurity and Information Sharing: Legal Challenges and Solutions

between the private sector and the government.30 The argument for the real time sharing of cyberintelligence—which could include the sharing of vulnerability data (the vulnerabilities an intruder
might exploit to gain access to a computer system), threat data (the types of malware circulating
the Internet and the nature of the threats a given entity has faced), and countermeasure data (the
steps an entity has taken to prevent or mitigate the effects of a cyberattack)31—is grounded in the
idea that effective cybersecurity depends upon robust knowledge about potential threats and wide
dissemination of the best practices and strategies to combat such threats.32
Despite widespread agreement about the need for enhanced cyber-information sharing, there is
similar agreement among cyber-experts that current public and private sector information sharing
efforts are simply inadequate.33 While there may be many reasons why entities may opt to not

(...continued)
deter or mitigate a cyber-attack, including vulnerability, threat, and countermeasure data. See infra note 31 and
accompanying text.
30
See Bipartisan Policy Center, Cyber Security Task Force: Public-Private Information Sharing, July 2012, at p. 5,
available at http://bipartisanpolicy.org/wp-content/uploads/sites/default/files/PublicPrivate%20Information%20Sharing.pdf. This is not to say that there is agreement as to the particulars of how
information sharing should be facilitated, such as the need for privacy and civil liberty protections for information
shared amongst private and public entities. See, e.g., Erin Kelly, Obama, Congress may find cybersecurity consensus,
USA TODAY (January 25, 2015), available at http://www.usatoday.com/story/news/politics/2015/01/25/cybersecurityinformation-sharing-bill/22229049/ (“That doesn't mean that there are no conflicts between the White House and
Congress on the issue. House Republican leaders are still angry that the president threatened to veto an informationsharing bill they passed in the last Congress. Obama said the bill did not do enough to protect the privacy of
Americans’ personal data in the information-sharing process.”).
31
See Sales, supra note 26, at 1546. Threat data may consist of “signatures,” patterns of network traffic deployed to
detect and mitigate malicious cyber-activity, which in turn are comprised of cyber threat “indicators”—a combination
of data such as IP addresses, domain names, email headers, files, and internal strings that identify the malicious
activity. See Jeremy J. Broggi, Building on Executive Order 13,636 to Encourage Information Sharing for
Cybersecurity Purposes, 37 HARV. J.L. & PUB. POL’Y 653, 657 (2014); see generally Lehtinen, supra note 1, at 80.
32
See Sales, supra note 26, at 1546; see also Bipartisan Policy Center, supra note 30, at 7 (“With more robust
information sharing, there can be greater situational awareness about the health of the nation’s information technology
architecture. A real-time understanding of threats and vulnerabilities is necessary for government officials and industry
leaders to make decisions about tactical protective and response measures.”); Kimberly Peretti, Cyber Threat
Intelligence: To Share or Not to Share—What Are the Real Concerns?, 13 PVLR 1476 (2014) (“[T]he receipt of
critical threat data can and has been shown to prevent potential cyberattacks and mitigate ongoing attacks.”); Denise E.
Zheng and James A. Lewis, Cyber Threat Information Sharing: Recommendations for Congress and the
Administration, CTR. FOR STRATEGIC AND INT’L STUDIES 1 (March 2015), available online https://csis.org/files/
publication/150310_cyberthreatinfosharing.pdf (“Cyber threat information sharing.... is a critical step toward
improving cyber defenses.”). For arguments against the value of cyber-information sharing, see Paul Rosenzweig, The
Administration’s Cyber Proposals—Information Sharing, LAWFARE, (January 16, 2015), available at
http://www.lawfareblog.com/2015/01/the-administrations-cyber-proposals-information-sharing/ (“Given all the strum
and drang, the worst part about all of this is that it seems to me to be portending a big debate over something that won’t
matter that much. Most of the analysts I know are in pretty wide agreement that the most significant types of threats
come from sophisticated actors who are creating and deploying novel cyber threats. For those sorts of new threats, no
amount of information sharing is useful.”).
33
See Gregory T. Nojeim, Cybersecurity and Freedom on the Internet, 4 NAT’L SECURITY L. & POL’Y 119, 126 (2010)
(“Although laws authorize such sharing of information, actual practice has been inadequate.”) (hereinafter “NojeimCybersecurity”); see also Peretti, supra note 32, at 4 (“While an increasing number of companies are recognizing the
benefits of sharing information regarding cyber threats, many remain wary.... ”); Exchanging Cyber Threat
Intelligence: There Has to Be a Better Way, PONEMON INSTITUTE, (April 2014), available at
http://content.internetidentity.com/acton/attachment/8504/f-001b/1/-/-/-/-/Ponemon%20Study.pdf (hereinafter
“Ponemon Institute—Threat Intelligence”) (“71 percent of respondents say there has to be a better way to exchange
threat information than what exists today.”).

Congressional Research Service

4

Cybersecurity and Information Sharing: Legal Challenges and Solutions

participate in a cyber-information sharing scheme,34 a primary rationale for such a decision
concerns the potential liability that could result from sharing internal cyber-threat information
with other private companies or the government. Indeed, in a recent survey of over 700
information technology security practitioners, half of the respondents listed worries about
“potential liability [from] sharing” as the main reason for not participating in an initiative for
exchanging threat information.35 More broadly, the legal issues surrounding cybersecurity
information sharing—whether it be with regard to sharing between two private companies or the
dissemination of cyber-intelligence within the federal government—are complex and have few
certain resolutions. In this vein, this report analyzes the major legal issues regarding cyber-threat
information sharing by beginning with a discussion of the current legal authorities respecting the
exchange of cyber-intelligence. Included in this discussion will be an examination of the various
sources of liability that could result from information sharing. The report concludes by discussing
several of the major legislative proposals aimed at reforming federal cyber-information sharing
laws and potential legal issues that such laws could prompt.

Conceptualizing the Legal Issues Regarding Cyber
Information Sharing
While often the concept of “cyber-information sharing” is thought of as a monolith, the sharing of
cyber-intelligence touches on three related, but distinct concepts. First, cyber-information sharing
is often used in the context of describing efforts to promote the dissemination of cyberintelligence from the federal government to other government entities or the private sector. This
sort of cyber information sharing would occur, for example, when the Federal Bureau of
Investigation (FBI) provides the Department of Homeland Security (DHS) or privately owned
banks with the IP addresses of computers known to have launched distributed denial of service
(DDoS) attacks against other entities within the financial sector.36 Second, cyber-threat
information sharing also embraces the concept of private entities sharing cyber-intelligence with
each other, such as when several companies in a particular sector establish a formal exchange or
34

Among these concerns include worries about compromising proprietary information, a desire to not aid competitors,
losing customer goodwill, and reputational harms that may occur if an entity discloses details about a prior cyberattack.
See Sales, supra note 26, at 1549; see also Derek E. Bambauer, Ghost in the Network, 162 U. PA. L. REV. 1011, 1046
(2014) (“Firms have significant incentives not to disclose breaches or attacks. Revealing lapses could have reputationrelated market effects. Publicly traded companies ... suffer drops in share price immediately after revealing security
breaches. Disclosing vulnerability information risks further dissemination (even if inadvertent) that could lead to
additional attacks ... firms may not want to aid competitors either by reducing their information security costs or by
protecting them from the same attack.”).
35
See Ponemon Institute—Threat Intelligence, supra note 33, at 3.
36
See, e.g., Cybersecurity: Enhancing Coordination to Protect the Financial Sector, Hearing Before Senate Committee
on Banking, Housing, and Urban Affairs, 113th Cong. (2013) (statement of Joseph M. Demarest, Assistant Director,
Cyber Division, Federal Bureau of Investigation, available at http://www.fbi.gov/news/testimony/cyber-securityenhancing-coordination-to-protect-the-financial-sector (“The FBI worked closely with Department of Homeland
Security (DHS) to issue Joint Indicator Bulletins (JIBs) to the U.S. banks, which included thousands of IP addresses
that participated in the attacks. The U.S. banks used the IP addresses to better mitigate future incidents, thus helping to
ensure their business operations could proceed with less interruption of service to their customers.”); see generally
Sales, supra note 26, at 1547 (“[T]he government’s highly resourceful intelligence agencies are simply better than the
private sector at detecting intrusions by sophisticated adversaries like foreign militaries and developing
countermeasures. The government can provide these firms with the signatures of malware used in previous attacks, and
firms can use the signature files to detect future intrusions.”).

Congressional Research Service

5

Cybersecurity and Information Sharing: Legal Challenges and Solutions

formal agreements to share relevant cyber-information with each other.37 Finally, cyberinformation sharing also describes when private entities share cyber-threat information in their
possession with the government. Such information sharing could occur, for example, when
private security firms report to DHS details about potential cyber-vulnerabilities unearthed in
research.38 While collectively these three variants on the concept of cyber-information sharing
have some commonalities, each also raises separate legal challenges that may impede cyberintelligence dissemination more generally.

Sharing Cyber-Information in the Possession of the
Government
Perhaps the area in which there is the most legal clarity with respect to cyber-information sharing
pertains to the authority of the federal government –and its subcomponents—to disseminate cyber
threat information within the government and with the private sector. Two central components of
DHS lead efforts to distribute cyber-intelligence to others in the government39 and the private
sector.40
First, the Office of Intelligence and Analysis (I&A), an entity established under Section 201 of
the Homeland Security Act of 2002 (Homeland Security Act or the Act),41 is generally authorized
to “access and receive” information and intelligence from “agencies of the Federal Government,
State and local government agencies (including law enforcement agencies), and private sector
entities”42 in order to “identify and assess” “terrorist threats to the homeland” and “actual and
potential vulnerabilities to the homeland.”43 In addition, the I&A is responsible for “integrat[ing]
relevant information, analysis, and vulnerability assessments” and disseminating such
information in “both classified and unclassified formats, as appropriate” to “other agencies of the
37

See, e.g., About Us: Information Sharing and Analysis Centers (ISACs), NATIONAL COUNCIL OF ISACS, (no date
provided), available at http://www.isaccouncil.org/aboutus.html.
38
See, e.g., Rachael King, Cyber Attackers Target Building Management Systems, WALL STREET JOURNAL, (April 5,
2013), available at http://blogs.wsj.com/cio/2013/04/05/cyber-attackers-target-building-management-systems/.
39
The White House recently announced the creation of the Cyber Threat Intelligence Integration Center (CTIIC), an
agency housed within the Office of the Director of National Intelligence (DNI) and will be modelled off of the National
Counterterroism Center (NCTC) to share cyber-intelligence across various entities within the federal government. See
The White House, Presidential Memorandum—Establishment of the Cyber Threat Intelligence Integration Center,
(February 25, 2015), http://www.whitehouse.gov/the-press-office/2015/02/25/presidential-memorandumestablishment-cyber-threat-intelligence-integrat.
40
See Stakeholder Priorities for the Quadrennial Homeland Security Review Hearing Before the Subcomm. on
Oversight and Managment Efficiency of the H. Comm. on Homeland Security, 113th Cong. (2014) (statement of Frank
J. Cilluffo, Director Homeland Security Policy Institute and Cybersecurity Initiative The George Washington
University) (“Currently responsibility for cyber analysis is split between the DHS Office of Intelligence and Analysis
(I&A), and the National Protection and Programs Directorate.”).
41
See P.L. 107-296, Title II, Subtitle A, §201, codified at 6 U.S.C. §121(a). Under the Homeland Security Act of 2002,
the term “terrorism” encompasses an act that is (1) “dangerous to human life or potentially destructive of critical
infrastructure or key resources;” (2) a violation of federal or state or local criminal law; and (3) appears to be intended
to either (a) intimidate or coerce a civilian population, (b) influence the policy of a government by intimidation or
coercion, or (c) affect the conduct of a government by mass destruction, assassination, or kidnapping. See 6 U.S.C.
§101(16).
42
6 U.S.C. §121(d)(1).
43
Id. §121(d)(1)(A)-(C).

Congressional Research Service

6

Cybersecurity and Information Sharing: Legal Challenges and Solutions

Federal Government, State, and local government agencies and authorities, the private sector, and
other entities.”44 In turn, pursuant to 6 U.S.C. Section 143, DHS, through I&A, is required to
provide to state and localities “analysis and warnings related to threats to, and vulnerabilities of,”
“critical information systems,”45 a term of art presumably46 controlled by the Homeland Security
Act’s definition for the term “critical infrastructure”:
[S]ystems ... so vital to the United States that the incapacity or destruction of such systems ...
would have a debilitating impact on security, national economic security, national public
health or safety, or any combination of those matters.47

Moreover, DHS is authorized “upon request” to provide the same “analysis and warnings” to
“private entities that own or operate critical information systems.”48 In practice, the I&A has
primarily exercised its authority by focusing its efforts on analyses of cyber-threat information
and the distribution of those analyses to various public and private entities.49
In addition to the I&A, DHS’s National Protection and Programs Directorate (NPPD) and its
subcomponents play perhaps an even more important role with respect to the sharing of cyberthreat information with other government and private entities.50 Within the NPPD exists the
Office of Cybersecurity and Communications (CS&C), an office Congress created in 200651 that
is tasked with overseeing the “security, resiliency, and reliability of the nation’s cyber and
communications infrastructure.”52 To execute this mission, CS&C, supports “24x7 information
sharing, analysis, and incident response” through the National Cybersecurity and Communication
Integration Center (NCCIC or Center).53 Established in 2009, the NCCIC is a “24-hour, DHS-led
44

6 U.S.C. §121(d)(3), (8), (13), (21).
Id. §143(1)(A).
46
See Perales v. Sullivan, 948 F.2d 1348, 1355 (2d Cir. 1991) (“Similar language in two different sections of the same
law should be given a similar interpretation.”) (citing Northcross v. Board of Education, 412 U.S. 427, 428 (1973) (per
curiam))
47
See id. §101(4) (citing 42 U.S.C. §5195c(e)) (defining “critical infrastructure,” which includes both critical assets
and systems).
48
See id. §143(1)(A).
49
See Office of Intelligence and Analysis’ Vision and Goals, Hearing Before the H. Comm. on Homeland Security,
111th Cong. (2010) (statement of Under Secretary and Chief Intelligence Officer Caryn Wagner), available at
http://www.dhs.gov/news/2010/05/12/testimony-under-secretary-and-chief-intelligence-officer-caryn-wagner-andprincipal (“ I&A also possesses a cyber intelligence analytic program. This team provides a national intelligence
analytical framework in support of key cybersecurity customers, such as the DHS National Cybersecurity and
Communications Integration Center (NCCIC), the DHS United States Computer Emergency Readiness Team (USCERT), and the Industrial Control Systems CERT. We are working with partners in the community to collaborate on
strategic cyber analysis, and we continue to determine the amount of analytic support necessary to the Department’s
cybersecurity mission.”).
50
See About the National Protection and Programs Directorate, Dep’t of Homeland Security, (July 9, 2014), available
at http://www.dhs.gov/about-national-protection-and-programs-directorate.
51
See Dep’t of Homeland Sec. Appropriations Act, 2007, P.L. 109-295, Title VI, Subtitle A, §611(13), 120 Stat. 1409,
codified at 6 U.S.C. §321c.
52
See About the National Protection and Programs Directorate, Dep’t of Homeland Security, (July 9, 2014), available
at http://www.dhs.gov/about-national-protection-and-programs-directorate (describing the “mission” of CS&C).
53
See Facilitating Cyber Threat Information Sharing and Partnering with the Private Sector to Protect Critical
Infrastructure: An Assessment of DHS Capabilities, Hearing Before Subcomm. on Cybersecurity, Infrastructure
Protection and Security Technologies H. Comm. on Homeland Security, 113th Cong. (2013) (statement of NPPD Office
of CS&C Acting Assistant Secretary Roberta Stempfley and NCCIC Director Larry Zelvin) (hereinafter “Stempfley
and Zelvin”).
45

Congressional Research Service

7

Cybersecurity and Information Sharing: Legal Challenges and Solutions

coordinated watch and warning center” monitoring “threats and incidents affecting the nation’s
critical information technology and cyber infrastructure.”54 NCCIC, through the United States
Computer Emergency Readiness Team (US-CERT), helps operate “key aspects” of several
information sharing programs, including the Cyber Information Sharing and Collaboration
Program (CISCP) and Enhanced Cybersecurity Services (ECS).55 CISCP allows for often
unclassified56 “cyber threat, incident, and vulnerability information” to be disclosed “in near realtime” with private information sharing organizations and select owners and operators of so-called
critical infrastructure and key resources.57 ECS entails a “voluntary information sharing program”
that, in part, “shares sensitive and classified government ... cyber threat information” with certain
private actors.58
In late 2014, Congress enacted the National Cybersecurity Protection Act of 2014 (NCPA), which
formally codified NCCIC’s authority, allowing the “Center to carry out certain responsibilities of

54

See Press Release, Secretary Napolitano Opens New National Cybersecurity and Communications Integration
Center, (October 30, 2009), available at http://www.dhs.gov/news/2009/10/30/new-national-cybersecurity-centeropened.
55
See Stempfley and Zelvin, supra note 53.
56
See Jason Miller, DHS finds classified cyber sharing program slow to take off, FEDERAL NEWS RADIO, (June 13,
2013), available at http://www.federalnewsradio.com/473/3356694/DHS-finds-classified-cyber-sharing-program-slowto-take-off (distinguishing between ECS and CISCP based on the types of information shared with the private sector);
see also Robert Gyenes, A Voluntary Cybersecurity Framework Is Unworkable—Government Must Crack the Whip, 14
PGH. J. Tech. L. & Pol’y 293, 305-06 (2014) (noting that CISCP, because of its focus on sharing unclassified
information, has a higher participation rate than ECS). President Obama’s 2013 Executive Order on cybersecurity
expanded efforts to disclose unclassified cybersecurity information, requiring the “timely production of unclassified
reports of cyber threats to the U.S. homeland that identify a specific targeted entity.” See Improving Critical
Infrastructure Cybersecurity, Exec. Order No. 13,636, §4(a), 78 Federal Register 11,739, 11,740-41 (February 12,
2013).
57
See Dep’t of Homeland Sec., Critical Infrastructure and Key Resources Cyber Information Sharing and
Collaboration Program 1, (no date provided), available at https://www.us-cert.gov/sites/default/files/c3vp/
CISCP_20140523.pdf. According to DHS, to join CISCP and gain access to NCCIC’s cyber intelligence, a private
entity must sign a Cooperative Research and Development Agreement (CRADA) with the agency. Id. Pursuant to the
Stevenson-Wydler Technology Innovation Act of 1980, agencies are authorized to enter into CRDAs with private
parties “under which the Government ... provides personnel, services, facilities, equipment, intellectual property, or
other resources with or without reimbursement ... and the non-Federal parties provide funds, personnel, services,
facilities, equipment, intellectual property, or other resources toward the conduct of specified research or development
efforts which are consistent with the mission [of the agency].” See 15 U.S.C. §3710a(d)(1).
58
See Dep’t of Homeland Sec., Enhanced Cybersecurity Services 1, available at http://www.dhs.gov/sites/default/files/
publications/ECS-Fact-Sheet.pdf (emphasis added). The private entities that participate in ECS and receive government
furnished threat indicators are either Commercial Service Providers (CSP) or Operational Implementers (OIs) who have
been vetted by the government and entered into a Memorandum of Understanding with DHS. See id. at 2. CSPs, such
as AT&T, provide information services to private entities, while an OI is a private entity who provides information
services for its own network. See Defense Cyber Crime Center, DIB Enhanced Cybersecurity Services (DECS),
(February 26, 2013), available at http://www.dc3.mil/data/uploads/dcise-pdf-dib-enhanced-cybersecurity-servicesprocedures_updated-feb-26-2013.pdf (describing the Department of Defense’s precursor to ECS). Regardless, either a
OI or CSP must be capable of implementing government furnished information, comply with applicable security
requirements, and have appropriately cleared personnel and facilities in order to participate in ECS. Id. ECS was
expanded pursuant to President Obama’s 2013 Executive Order on cybersecurity. See Improving Critical Infrastructure
Cybersecurity, Exec. Order No. 13,636, §4(c), 78 Federal Register 11,739, 11,740-41 (February 12, 2013) (“To assist
the owners and operators of critical infrastructure in protecting their systems from unauthorized access, exploitation, or
harm, the Secretary ... in collaboration with the Secretary of Defense, shall, within 120 days of the date of this order,
establish procedures to expand the [ECS] program to all critical infrastructure sectors.”) For more on the origins of
ECS and the President’s Executive Order, see CRS Report R42984, The 2013 Cybersecurity Executive Order:
Overview and Considerations for Congress, by (name redacted) et al., at pp. 10-11.

Congressional Research Service

8

Cybersecurity and Information Sharing: Legal Challenges and Solutions

the Under Secretary” for the NPPD.59 Specifically, the NCPA confirmed that the NCCIC’s
functions include serving as an “interface” for the “real-time” “sharing of information related to
cybersecurity risks, incidents, analysis, and warnings between Federal and non-Federal
entities.”60 Furthermore, the NCPA directs the Center to provide a number of additional services,
such as technical assistance, risk management support, and incident response capabilities to both
public and private entities.61 The NCPA requires NCCIC to include representatives of federal
agencies, state and local governments, and private sector owners and operators of critical
information systems,62 while still providing the Under Secretary for the NPPD with discretion
with respect to the precise makeup of the Center.63 In February of 2015, in keeping with NCCIC’s
statutory role, President Obama, in an Executive Order, mandated that the Center “engage in
continuous, collaborative, and inclusive coordination with” Information Sharing and Analysis
Organizations (ISAOs),64 a formal or informal entity or collaboration created or employed by
public or private sector organizations that gather, analyze, and disseminate cyber-threat
information.65
The Homeland Security Act, as amended by the NCPA, provides significant authority for DHS to
disseminate a wide range of cyber-threat intelligence within the possession of the federal
government to other government agencies and to the private sector. Earlier iterations of the
Homeland Security Act seemingly cabined DHS’s authority to collect and share cyberintelligence only to the extent such information respected a “terrorist threat”66 or would pertain to
“critical information systems.”67 In contrast, the NCPA provides NCCIC the authority to share
cyber-information to the extent that such information relates to “cybersecurity risks,”68 a term of
art that encompasses any “threats” and “vulnerabilities” to information systems and “any related
consequences caused by or resulting” from a host of actions that could compromise an
information system or the information stored on an information system.69 In other words, given
59

P.L. 113-282, 128 Stat. 3066.
6 U.S.C. §148(c)(1). The Center is composed of various federal entities, such as sector-specific agencies, law
enforcement agencies, and members of the intelligence community, and non-federal entities, such as state and local
governments, information sharing and analysis organizations, and owners and operators of critical information systems.
Id. §148(d).
61
Id. §148(c).
62
Id. §148(d)(1)(A)-(B).
63
Id. §148(d)(1)(E).
64
See Executive Order, Promoting Private Sector Cybersecurity Information Sharing, THE WHITE HOUSE, (February
13, 2015), §2(c), available at http://www.whitehouse.gov/the-press-office/2015/02/13/executive-order-promotingprivate-sector-cybersecurity-information-shari.
65
6 U.S.C. §131(5).
66
See, e.g., P.L. 107-296, Title II, Subtitle A, §201(d)(1) (“[T]he responsibilities of the Under Secretary for
Information Analysis and Infrastructure Protection shall be ... to access, receive, and analyze law enforcement
information, intelligence information, and other information from agencies of the Federal Government, State and local
government agencies ... and private sector entities, and to integrate such information in order to ... identify and assess
the nature and scope of terrorist threats to the homeland ... ”).
67
Id. §223 (“In carrying out the responsibilities under section 201, the Under Secretary for Information Analysis and
Infrastructure Protection shall ... as appropriate, provide to State and local government entities, and upon request to
private entities that own or operate critical information systems ... analysis and warnings related to threats to, and
vulnerabilities of, critical information systems.”).
68
See 6 U.S.C. §148(c).
69
Id.§148(a)(1) (defining “cybersecurity risk” to mean “threats to and vulnerabilities of information or information
systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation,
disruption, modification, or destruction of information or information systems, including such related consequences
(continued...)
60

Congressional Research Service

9

Cybersecurity and Information Sharing: Legal Challenges and Solutions

DHS’s discretion in designating various entities to participate in the NCCIC,70 it appears DHS has
fairly broad authority to disseminate federal cyber threat information throughout the private
sector, regardless of whether the information pertains to an industry that is “so vital to the United
States that the incapacity or destruction” of that industry’s assets or information systems would be
“debilitating” to the country.71 In fact, one issue that has been raised by commentators is whether
the statutory authority allotted to the various entities within DHS—such as I&A and NPPD—to
engage in cyber-information sharing is so broad and ill-defined that confusion could result
internally within the Department as to who the central actor should be with respect to the sharing
of federal cyber-intelligence.72 The same argument could plausibly be made with respect to the
authority to disseminate cyber-intelligence amongst the various entities of the federal
government, as entities like the I&A73 and NPPD74 within DHS and new entities outside of DHS,
like the newly formed Cyber Threat Intelligence Integration Center (CTICC)75 appear to possess
overlapping legal authorities with respect to the internal sharing of cyber-information within the
federal government.76
(...continued)
caused by an act of terrorism”); see also id. §148(a)(4) (citing 44 U.S.C. §3502(8) (defining “information system” to
mean “a discrete set of information resources organized for the collection, processing, maintenance, use, sharing,
dissemination, or disposition of information”).
70
6 U.S.C. §148(d)(1)(E).
71
See 42 U.S.C. §5195c(e) (defining “critical infrastructure,” which includes both critical assets and systems).
72
See, e.g., Sean Lyngaas, Can DHS get it together?, FEDERAL COMPUTER WEEK, (October 31, 2014), available at
http://fcw.com/articles/2014/10/31/cybersecurity-can-dhs-get-it-together.aspx (noting difficulty integrating threat
analyses done by I&A with the work of NPPD); see generally, Paul Rosenzweig, Cyber Security: A Complex ‘Web’ of
Problems, HERITAGE Foundation, (August 26, 2010), available at http://www.heritage.org/research/reports/2010/08/
cyber-security-a-complex-web-of-problems#_ftnref2 (“Today, as it pertains to cyber security, America still needs
clearer lines of authority within the federal government and a more coherent structure of public–private interaction to
allow for effective action.”) (hereinafter “Rosenzweig-Heritage”); Robert Kenneth Palmer, Critical Infrastructure:
Legislative Factors for Preventing a “Cyber Pearl Harbor,” 18 VA. J.L. & TECH. 289, 329 (2014) (“There are too
many government agencies with different cyber-missions working independently, with project duplication to the point
that it is not uncommon for several different groups to be working on the same thing, unaware of each other’s
efforts.”); but see Cybersecurity, Terrorism, and Beyond: Addressing Evolving Threats to the Homeland, Hearing
Before S. Comm. on Homeland Security and Gov’t Affairs, 113th Cong (2014) (testimony of Under Secretary Francis
Taylor and NPPD Under Secretary Suzanne Spaulding), available at http://www.dhs.gov/news/2014/09/10/writtentestimony-ia-and-nppd-senate-committee-homeland-security-and-governmental (“I&A and NPPD work closely
together every day to recognize and reduce risks posed by cyber threats.”). In this vein, some have lamented the fact
that the disperse authorities respecting cyber-intelligence sharing have resulted in key entities, like US-CERT, lacking
any specific authority to request cooperation from other agencies within DHS or the rest of the government on cyberintelligence efforts. See Examining the Cyber Threat to Critical Infrastructure and the American Economy: Hearing
before the H. Comm. of Homeland Security, Subcomm. on Cybersecurity, Infrastructure Protection, and Security
Technologies, 112th Cong. 50 (2011) (testimony of Mischel Kwon, President, Mischel Kwon & Associates, LLC),
available at http://www.gpo.gov/fdsys/pkg/CHRG-112hhrg72221/pdf/CHRG-112hhrg72221.pdf (“US–CERT does not
have the authority to require the departments or agencies to share detailed information, or follow any specific
instructions”); see also Palmer, supra note 72, at 327 (“A significant part of the US-CERT’s mission is to ‘coordinate
and collaborate’ with critical infrastructure owners and operators, but this is rarely accomplished because the USCERT
is buried within the DHS and has no authority to compel sector-specific federal agencies or law enforcement to
coordinate and cooperate with the US-CERT’s activities.”).
73
See 6 U.S.C. §121(d)(3)-(4).
74
See id.§148(c)(2).
75
See supra note 39.
76
See, e.g., Richard Bejtlich, What are the prospects for the Cyber Threat Intelligence Integration Center?, BROOKINGS
INSTITUTION, (February 19, 2015), available at http://www.brookings.edu/blogs/techtank/posts/2015/02/19-cybersecurity-center-bejlich (“Some may view CTIIC as just the latest in a long line of cyber agencies created by the
government ... The concern with CTIIC, however, is the perception that it duplicates the mission of NCCIC and older
(continued...)

Congressional Research Service

10

Cybersecurity and Information Sharing: Legal Challenges and Solutions

Nonetheless, DHS’s ability to share federal cyber-intelligence is not limitless. First, cyber-threat
information the government provides to the private sector generally must occur on a voluntary
basis.77 The plain language of Section 223 of the Homeland Security Act limits DHS’s ability to
share cyber-intelligence with “private entities that own or operate critical information systems,”
such that information sharing can only occur “upon [those entities’] request.”78 And indeed, the
NCPA contains an even more explicit provision disclaiming the Act from being “construed to
require any private entity” to request any assistance from the Secretary of DHS.79 In other words,
under current law, DHS generally does not have the authority to “mandate private sector
participation” in federal cyber information sharing efforts,80 leading some to question the value of
the current voluntary information sharing scheme.81
Second, other laws outside of the context of cybersecurity may limit the ability of the government
to disseminate cyber-threat information. The Homeland Security Act itself requires DHS to
ensure that any intelligence in its possession “is protected from unauthorized disclosure and
handled and used only for the performance of official duties.”82 More specifically, the Act
mandates that DHS adhere to (1) the requirements of the National Security Act of 1947 to the
extent any information pertains to intelligence sources and methods and (2) any authorities of the
Attorney General “concerning sensitive law enforcement information.”83 In other words, to the
extent any federal cyber-intelligence contains sensitive information, such as the sources or
methods that are the heart of an ongoing cybercrime investigation,84 the government may be
limited in its ability to disclose such information.
Beyond laws aimed at limiting disclosures that may inhibit core governmental functions, laws
aimed at preserving privacy and civil liberties may also restrict DHS’s ability to share certain
cyber-information. The Homeland Security Act requires DHS to “ensure ... that any information
databases and analytical tools developed and utilized by the Department”—which would
presumably include programs like CISCP and ECS—“treat information in such databases in a
manner that complies with applicable Federal law on privacy.”85 Moreover, the NCPA requires
(...continued)
units.”).
77
The federal government is authorized to provide, without request, “analysis and warnings related to threats to, and
vulnerabilities of, critical information systems” to state and local government entities. See 6 U.S.C. §143(1). Moreover,
the Homeland Security Act authorizes DHS to make general recommendations and disseminate information analyzed
by the Department as “appropriate” or “necessary.” See id. §121(d)(6)-(8).
78
See id. §143(1).
79
See P.L. 113-282, §8, 128 Stat. 3072.
80
See Broggi, supra note 31, at 658 (“On the contrary, the phrase ‘upon request’ suggests any such mandate is
forbidden.”).
81
See Palmer, supra note 72, at 358 (“Even after two decades, voluntary information sharing has failed to create an
effective information sharing environment.... ”).
82
6 U.S.C. §121(d)(11)(A); see also 6 U.S.C. §141(2) (authorizing the Secretary of DHS to “establish procedures on
the use of information shared under this title that ... ensure the security and confidentiality of such information.... ”).
83
Id. §121(d)(11)(B). For more information on the laws governing the protection of classified information, see CRS
Report RS21900, The Protection of Classified Information: The Legal Framework, by (name redacted).
84
See Gus P. Coldebella and Brian M. White, Foundational Questions Regarding the Federal Role in Cybersecurity, 4
J. NAT’L SEC. L. & POL’Y 233, 240-41 (2010) (“While the government has information about malicious code and the
behavior of criminal networks gained through its intelligence and law enforcement functions, fears of botching
investigations or compromising sources and methods make sharing with the private sector (or even with other
government agencies) difficult.”).
85
See 6 U.S.C. §121(d)(14)(b); see also 6 U.S.C. §141(3) (authorizing the Secretary of DHS to “establish procedures
(continued...)

Congressional Research Service

11

Cybersecurity and Information Sharing: Legal Challenges and Solutions

that the NCCIC “comply with all policies, regulations, and laws that protect the privacy and civil
liberties of United States persons.”86 As such, if DHS’s cyber intelligence included, for example,
individually identifiable information—like a name or a social security number—laws like the
Privacy Act of 1974 may restrict the manner in which the government may disclose such
information in a cyber-information sharing program.87
Collectively, the legal effect of the various federal disclosure and privacy laws may limit the
efficacy of any cyber-information DHS provides private entities. As one commentator recently
noted, the resulting “sanitation” of cyber-intelligence has a dual effect.88 First, the host of federal
agencies that “own classified or law enforcement information germane to a particular warning”
“must be coordinated with as part of the review process,” resulting in significant delays before
DHS can release any information to a private entity, by which time the information may be
irrelevant.89 Second, even if DHS releases government cyber threat information in a timely
manner, the cyber intelligence resulting after agency review of the underlying material may omit
critical information that is “actually useful to industry.”90

Sharing Cyber-Information in the Possession of
Private Entities
Whereas the law governing the dissemination of cyber-threat information in the possession of the
federal government is relatively straightforward, the legal landscape surrounding the sharing of
cyber-intelligence that is in the possession of private parties stands in stark contrast. Indeed, there
is an array of legal concerns—some more theoretical than actual—that shroud the law governing
the sharing of privately-held cyber-threat information in a cloud of uncertainty and create
disincentives against the sharing of such information by private parties.91 The legal issues can be
(...continued)
on the use of information shared under this title that ... protect the constitutional and statutory rights of any individuals
who are subjects of such information.... ”).
86
See 6 U.S.C. §148(e)(3).
87
See 5 U.S.C. §552a(b) (generally prohibiting an agency from disclosing “any record which is contained in a system
of records by any means of communication to any person, or to another agency.... ”). Pursuant to the Privacy Act and
the Homeland Security Act, DHS has promulgated Fair Information Practice Principles (FIPPs), which generally
amount to framework for how the Department uses and disseminates information containing personal identifying
information. See Hugo Teufel III, DHS Privacy Policy Guidance, DEP’T OF HOMELAND SEC., (December 29, 2008),
available at http://www.dhs.gov/xlibrary/assets/privacy/privacy_policyguide_2008-01.pdf. However, it should be noted
that the Privacy Act does contains exemptions for some inter-agency data sharing for national security and law
enforcement purposes, as well as routine uses described by the agency in the Federal Register. See 5 U.S.C.
§§552a(a)(8)(B)(vi), (b)(3), (b)(7), (e)(4)(D), & (j). There are numerous other more narrowly applicable laws on
privacy and data protection that protect specific types of information in the possession of the government that could
implicate the sharing of federal cyber-intelligence. See, e.g., 42 U.S.C. §1320(d) & 45 C.F.R. §§160, 164 (Health
Insurance Portability and Accountability Act of 1996); 18 U.S.C. §1905 (Trade Secrets Act).
88
See Palmer, supra note 72, at 326.
89
Id.
90
Id. at 327.
91
See Peretti, supra note 32, at 4 (noting concerns with current legal incentives governing private cyber-information
sharing); see also Palmer, supra note 72, at 317-18 (“Although many of these limitations may be less limiting than they
are perceived to be, the result of these perceptions and, at the very least, the uncertainty about the state of the law as
they pertain to information sharing, have created collective inaction where individual companies often simply feel safer
(continued...)

Congressional Research Service

12

Cybersecurity and Information Sharing: Legal Challenges and Solutions

divided between those that arise when private companies share cyber-information with each other
and those that occur when private companies share cyber-intelligence with the government.

Sharing Cyber-Information with Another Private Entity
Information security professionals within the private sector have “long relied” on information
from other private entities to “gain insight into cybersecurity threats and vulnerabilities.”92 And
often the most valuable cyber-intelligence comes from peers in other companies, including direct
competitors that may be subject to similar cybercrimes.93 Private cyber-information sharing can
take many forms, from informal arrangements, such as peer discussions via phone, email, or in
person, to formal sharing arrangements, such as cyber-intelligence sharing through an
Information Sharing and Analysis Center (ISAC), a private sector nonprofit corporation formed to
facilitate the sharing of information on cyber-threats, incidents and vulnerabilities among
members within a particular sector.94 At times, the federal government has been quite supportive
of such private efforts to share cyber-intelligence. Indeed, the impetus for ISACs was Presidential
Decision Directive-63, issued by President Clinton in 1998, which initially called for the creation
of industry-specific ISACs.95 Nonetheless, there are several bodies of law whose basic norms run
counter to the concept of a private business sharing cyber-threat information with an industry
peer, raising potential liability issues for those in the private sector that wish to exchange cyberintelligence.96 Without any overarching federal law governing private exchanges of cyber-threat
information, the potential remains for various laws facially unrelated to cyber-information sharing
to discourage such activity within the private sector.

Privacy Laws
A variety of state and federal privacy laws govern the collection, storage, use, and dissemination
of electronic information, potentially leaving limited room for cyber-intelligence sharing amongst
private actors or between private actors and the government.
The most pertinent federal privacy law is the Electronic Communications Privacy Act of 1986
(ECPA), which contains three titles: (1) Title I, the Wiretap Act,97 which regulates the interception
of communications content in transit; (2) Title II, the Stored Wire and Electronic Communications
and Transactional Records Access Act98 (Stored Communications Act or SCA), which governs
electronic communications already transmitted and currently in storage; and (3) Title III, the Pen

(...continued)
by keeping threat information to themselves rather than sharing it for mutual benefit.”); CRS Report R43821,
Legislation to Facilitate Cybersecurity Information Sharing: Economic Analysis, by (name redacted).
92
See Peretti, supra note 32, at 2.
93
See Ponemon Institute—Threat Intelligence, supra note 33, at 5 (noting that 58% of a survey’s respondents rely on
“peers in other companies” as their main source of threat intelligence).
94
See Peretti, supra note 32, at 2.
95
See Memorandum from President William Clinton on Critical Infrastructure Protection (Presidential Decision
Directive/NSC-63) (May 22, 1998), available at http://www.fas.org/irp/offdocs/pdd/pdd-63.htm.
96
See Peretti, supra note 32, at 4.
97
18 U.S.C. §§2510-2522.
98
Id. §§2701-2711.

Congressional Research Service

13

Cybersecurity and Information Sharing: Legal Challenges and Solutions

Register and Trap and Traces Devices Act (Pen/Trap Act),99 which regulates the interception of
noncontent communications, such as phone numbers or IP addresses. Each section of ECPA is
potentially relevant to those private entities considering sharing cyber-intelligence information.

The Wiretap Act
The Wiretap Act generally provides for criminal100 and civil damages101 against anyone who
“intentionally intercepts, endeavors to intercept, or procures any other person to intercept or
endeavor to intercept” any covered communication,102 which includes electronic
communication.103 To “intercept” an electronic communication is to use “any electronic,
mechanical, or other device” to acquire the “contents” or the “substance, purport, or meaning” of
the communication,104 contemporaneously with the transmission.105 Relatedly, the statute also
generally prohibits a “person or entity providing electronic communication service to the public”
from intentionally divulging the contents of any electronic communication while in transmission
other than to the “addressee or intended recipient of such communication.”106 Perhaps most
relevant to cyber-information sharing, the Wiretap Act also prohibits the disclosure or use of the
contents of any electronic communication that was obtained in violation of the statute, such an
illegal interception of electronic communications.107
Putting to the side the several exceptions contained in the Wiretap Act, on its face, ECPA’s
general prohibition on the interception of electronic communications would appear to encompass
any strategy for detecting cyber-threats that involved scanning the contents of an electronic
communication while in transmission,108 and ECPA’s general prohibition on an electronic service
99

Id. §§3121-3127.
The Wiretap Act imposes significant criminal penalties on those who violate its terms, with a minimum of a ten
thousand dollar fine per violation and up to five years of imprisonment. See id. §§2511, 2520.
101
Id. §2520(a).
102
Id. §2511(1)(a). Put another way, to show a violation of Title I of ECPA, five elements must be shown: the person
or entity (1) intentionally (2) intercepted, endeavored to intercept or procured another person to intercept or endeavor to
intercept (3) the contents of (4) an electronic communication (5) using a device. See In re Phramatrak Privacy Litig.,
329 F.3d 9, 18 (1st Cir. 2003).
103
An electronic communication includes any “transfer of signs, signals, writing, images, sounds, data, or intelligence
of any nature transmitted in whole or in part by a wire, radio, electromagnetic, photoelectronic or photoptical system.”
See 18 U.S.C. §2510(12).
104
18 U.S.C. §2510(4) & (8). The statute also generally prohibits conduct related to or taken as a consequence of an
illegal interception of covered communication, such as the use of a device to intercept a covered communication, the
disclosure of illegally intercepted communications, or the use of illegally intercepted communications. See 18 U.S.C.
§2511 (b)-(e).
105
See Fraser v. Nationwide Mut. Ins. Co., 352 F.3d 107, 114 (3d Cir. 2003); Steve Jackson Games, Inc. v. U.S. Secret
Serv., 36 F.3d 457, 462 (5th Cir. 1994); Konop v. Hawaiian Airlines, Inc., 302 F.3d 868, 878 (9th Cir. 2002); United
States v. Steiger, 318 F.3d 1039, 1048-49 (11th Cir. 2003); but see United States v. Councilman 418 F.3d 67, 80 (1st
Cir. 2005) (en banc) (suggesting that ECPA may not require “contemporaneity or real-time” transmission of electronic
communications).
106
See 18 U.S.C. §2511(3)(a).
107
See id. §2511(1)(c)-(d).
108
See generally Noel v. Hall, 568 F.3d 743, 749 (9th Cir. 2009) (holding that an interception of a covered
communication “occurs ‘when the contents of a ... communication are captured or redirected in any way.’”) (quoting
United States v. Rodriguez, 968 F.2d 130, 136 (2d Cir. 1992)); see, e.g. Campbell v. Facebook, Inc.,—F.Supp.3d—-,
2014 WL 7336475, at *3 (N.D.Cal. December 23, 2014) (holding the use of a software application to scan the content
of private messages for marketing purposes amounts to “redirection” of the contents of the users’ messages); In re
(continued...)
100

Congressional Research Service

14

Cybersecurity and Information Sharing: Legal Challenges and Solutions

provider divulging the contents of any communication while in transmission may bar the real
time transmission of certain cyber-intelligence.109 While cyber-intelligence may often not include
the contents of an electronic communication and may merely contain, for example, the IP address
of the origin of malware, as one commentator has suggested, many common cyber-threat
detection methods require using the contents of electronic communications—such as text within
the body of an email—to determine whether a particular communication is malicious.110
Moreover, to be effective, cyber-information sharing often necessitates the use of real time
sharing of cyber-threat information.111 Nonetheless, the Wiretap Act contains two key exceptions
to its general prohibition that may limit the scope of the law as it pertains to cyber-information
collection and sharing.112
First, the Wiretap Act includes an exception to its general prohibitions when there is the presence
of consent to the otherwise illicit interception or disclosure (“consent exception”).113 A private
actor can only rely on the consent exception where one of the parties to the communication has
given prior consent to the interception or divulgence.114 Courts reviewing the question of whether
a party to the communication consented to an interception or disclosure will look into the
(...continued)
Yahoo Mail Litig., 7 F. Supp. 3d 1016, 1027 (N.D. Cal. 2014) (holding that accessing the content of emails in transit
constitutes an interception for purposes of ECPA).
109
See generally Shubert v. Metrophone, Inc., 898 F.2d 401, 405 (3d Cir. 1990) (holding that §2511(3)(a) “prohibits a
communication service provider from intentionally divulging the contents of a communication while in the
transmission of that service.”).
110
See Broggi, supra note 31, at 661-62 (“[S]ignatures are comprised of indicators, and ... indicators may include text
strings. If these strings are located in the body or subject line of an email, courts will consider them contents.”).
111
See, e.g., Palmer, supra note 72, at 368 (“The nation needs real-time situational awareness and innovative
cybersecurity standards to keep up with the technological curve of cyber-threats that confront critical infrastructure.”).
112
The Wiretap Act’s prohibition on the use of a “device” to intercept any oral communication, see 18 U.S.C.
§2511(b), contains another exception that may be relevant for those engaged in cyber-threat detection. Specifically,
ECPA’s definition of a “device” necessarily excludes “any device or apparatus” used by “any ... equipment or facility
... furnished to the subscriber or user ... in the ordinary course of business.” See id. §2510(5)(a). However, the “ordinary
course of business” exception may not apply to a private entity that is scanning electronic communication for potential
cyber-threats. Courts have generally interpreted the ordinary course of business exemption to apply to devices that
further an underlying communications system, such as routers or switchboards, which arguably is unrelated to
determining whether particular communications within such a system pose a cyber-threat. See In re Google Inc. Gmail
Litigation, No. 13–MD–02430, 2013 WL 5423918, at *8 (N.D. Cal. September 26, 2013) (holding the “ordinary course
of business exception” “offers protection from liability only where an electronic communication service provider’s
interception facilitates the transmission of the communication at issue or is incidental to the transmission of such
communication. Specifically, the exception would apply here only if the alleged interceptions were an instrumental part
of the transmission of email.”); see also Campbell, 2014 WL 7336475, at *7 (holding the ordinary course of business
exception requires some nexus between interception and the subscriber’s “ultimate business, that is, the ability to
provide the underlying service or good”); see generally Sanders v. Robert Bosch Corp., 38 F.3d 736, 740 (4th Cir.
1994) (refusing to apply the ordinary course of business exemption to a voice logger); Hall v. EarthLink Network, Inc.,
396 F.3d 500, 504-5 (2d Cir. 2005); Williams v. Poulos, 11 F.3d 271, 280 (1st Cir. 1993); Deal v. Spears, 980 F.2d
1153, 1158 (8th Cir. 1992); but see Kirch v. Embarq Mgmt. Co., 702 F.3d 1245, 1250 (10th Cir. 2012) (holding that an
Internet Service Provider was operating in the ordinary course of business by allowing an online advertising company
to conduct technology tests for directing online advertising on electronic communications that the provider ordinary
accessed). More broadly, courts have been reluctant to find that indiscriminate recording of communications is within
the ordinary course of most businesses. See, e.g., United States v. Murdock, 63 F.3d 1391, 1397 (6th Cir. 1995).
113
See 18 U.S.C. §2511(2)(d); id. §2511(3)(b)(ii).
114
See 18 U.S.C. §2511(2)(d); id. §2511(3)(b)(ii). In addition, under the consent exception to the Wiretap Act’ s
interception prohibition, the exception does not apply when the underlying communication is “intercepted for the
purposes of committing any criminal or tortious act in violation of the Constitution or laws of the United States or of
any State.” Id. §2511(2)(d).

Congressional Research Service

15

Cybersecurity and Information Sharing: Legal Challenges and Solutions

“dimensions of the consent” and then ascertain whether the act in question “exceeded those
boundaries.”115
With respect to a private entity’s efforts to collect content-based cyber-threat information and
disseminate such information, the Wiretap Act’s consent exception, while often a viable route to
avoid liability, raises several difficult legal questions. For example, determining who is a “party to
the communication” when someone is launching a cyberattack can be very difficult, as the
cybercriminal may be using multiple computers and the ultimate destination of the hacker’s
communication may be unclear.116 While an entity attempting to monitor its system for cyberintruders could argue that it is a party to the underlying electronic communication being
monitored because the data is flowing on its network and is being directed toward its computers
and employees,117 such an interpretation of what it means to be a party to a communication may
eliminate any privacy protections for the individuals who are directly participating in the
electronic communication.118 Instead, a court may likely interpret that a party to a communication
must be the individuals who actually take part in the electronic conversation.119
Moreover, assuming that the private entity acquiring cyber-threat information is not a party to the
communication, consent must be obtained from one of the individuals taking part in the
communication, which, in turn, depends on the dimensions of the consent and whether the
interception or divulgence of the contents of electronic communication exceeded the boundaries
of the consent.120 Such an inquiry can be quite context specific,121 inviting litigation and creating
legal uncertainty for entities wishing to engage in cyber-information sharing. For example, courts
have come to differing conclusions as to whether an electronic communications service
provider’s customer has consented to having the provider intercept certain communications,
largely because of the specific nature of the interception in question and the precise terms of
service to which the customer agreed.122 Importantly, consent cannot be “casually” inferred,123
115

See Gilday v. Dubois, 124 F.3d 277, 297 (1st Cir. 1997) (citing Griggs-Ryan v. Smith, 904 F.2d 112, 116 (1st Cir.
1990).
116
See Dep’t of Justice, Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal
Investigations, 172 (2009), available at http://www.justice.gov/criminal/cybercrime/docs/ssmanual2009.pdf.
117
See Pitts Sales, Inc. v. King World Prods., 383 F. Supp. 2d 1354, 1361 (S.D. Fla. 2005) (holding that a “party to the
communication” under §2511(2)(d) is a party “who is present when the ... communication is uttered and need not
directly participate in the conversation”); see also United States v. Mullins, 992 F.2d 1472, 1478 (9th Cir. 1993) (stating
that the consent exception of §2511(2)(d) authorizes monitoring of computer system misuse because the owner of the
computer system is a party to the communication).
118
See generally Brown v. Waddell, 50 F.3d 285, 289 (4th Cir. 1995); see also Orin Kerr, Internet Surveillance Law
After the USA PATRIOT Act: The Big Brother That Wasn’t, 97 NW. U. L. REV. 607, 620 (2003) 664-665 (“[L]abeling
the [provider] a party to the communication may sound logical ... but ultimately would eviscerate the privacy
protections of the Wiretap Act.”).
119
See Caro v. Weintraub, 618 F.3d 94, 97 (2d Cir. 2010) (holding that a “a party to the conversation is one who takes
part in the conversation.”).
120
See In re Pharmatrak Privacy Litig., 329 F.3d at 19 (citing Griggs-Ryan v. Smith, 904 F.2d 112, 119 (1st Cir.
1990)). Moreover, consent may be explicit or implied, but it must be actual consent rather than constructive consent. Id.
121
United States v. Footman, 215 F.3d 145, 155 (1st Cir. 2000) (“The question of consent, either express or implied,
may vary with the circumstances of the parties.”).
122
See, e.g., Backhuat v. Apple, Inc.,—F.Supp.3d—-, 2014 WL 6601776, at *8 (N.D. Cal. November 19, 2014) (“In
light of the specific language of the license agreement, the Court concludes that a reasonable iMessage user would not
be adequately notified that Apple would intercept his or her messages when doing so would not ‘facilitate delivery’ of
the messages.”); In re Yahoo Mail Litig., 7 F.Supp.3d at 1029 (“The Court concludes that the [Yahoo Global
Communications Additional Terms of Service for Yahoo Mail and Yahoo Messenger] establishes explicit consent by
Yahoo Mail users to Yahoo’s conduct.”); In re Google Inc. Gmail Litig., 2013 WL 5423918, at *11–14 (“[A]
(continued...)

Congressional Research Service

16

Cybersecurity and Information Sharing: Legal Challenges and Solutions

and absent actual notice of the nature of the interception or divulgence, consent can only be
implied if the “surrounding circumstances convincingly show that the party knew about and
consented to the interception.”124 Courts, interpreting the consent exception narrowly to ensure
the exemption does not swallow the rule, have held that merely providing a person notice that an
entity has the capability of intercepting communications cannot be considered implied consent.125
And deficient notice will “almost always defeat a claim of consent.”126 As a consequence, for a
private entity that wishes to employ and share the results of a cyber-threat detector, which often is
created with the goal of invisibly tracking communications without alerting either internal or
external users of its operation, notice to a party of an electronic communication that is sufficient
to create consent may, at times, defeat the entire purpose of monitoring and sharing the contents
of electronic communications.
Second, the Wiretap Act also includes a “provider exception” which allows the provider of
electronic communications to “intercept, disclose, or use” the contents of communications when
the activity is a “necessary incident to ... the protection of the rights or property of the provider of
that service.”127 On its face, the provider exception is limited to protecting the “rights or property
of the provider,” as opposed to any third party.128 While at least one court has read the provider
exception broadly to allow a service provider to intercept or disclose covered communications for
purposes of aiding third parties,129 several courts have cabined the provider exception in terms of
whether the interception was done for the purpose of protecting the provider’s own “equipment
and rights.”130 And the Department of Justice’s (DOJ’s) Office of Legal Counsel has likewise
concluded that the provider exception “must protect the provider’s own rights or property, and not
(...continued)
reasonable Gmail user who read the Privacy Policies would not have necessarily understood that her emails were being
intercepted to create user profiles or to provide targeted advertisements. Accordingly, the Court finds that it cannot
conclude at this phase that the new policies demonstrate that Gmail user Plaintiffs consented to the interceptions.”).
123
See Griggs-Ryan, 904 F.2d at 117-18.
124
See Berry v. Funk, 146 F.3d 1003, 1011 (D.C. Cir. 1998).
125
See Watkins v. L.M. Berry & Co., 704 F.2d 577, 581 (11th Cir. 1983).
126
See In re Pharmatrak Inc., 329 F.3d at 20.
127
See 18 U.S.C. §2511(2)(a)(i). The provider exception also contains a provision that allows the service provider to
intercept, disclose, or use cover communications when the activity is a necessary incident to the rendition of a service.
Id. This exception generally allows interception that is “unavoidable” and a part and parcel of modern
telecommunications. U.S. Dep’t of Justice, supra note 116, at 177 (citing United States v. New York Tel. Co., 434 U.S.
159, 168 n.13 (1977)).
128
See 18 U.S.C. §2511(2)(a)(i).
129
See, e.g., United States v. Pervaz, 118 F.3d 1, 5 (1st Cir. 1997) (holding that a company had the right to intercept
covered communications where there was evidence that its customers were being defrauded); see generally United
States v. Harvey, 540 F.2d 1345, 1352 (8th Cir. 1976) (“18 U.S.C. §2511(2)(a)(i) ... was designed to allow the
disclosure of justified wire monitoring” in order to provide evidence for “wire fraud prosecution”); New York Tel. Co.,
434 U.S. at 168 n.13 (stating in dicta that the provider exception “excludes all normal telephone company business
practices from the prohibitions of the [Wiretap] Act.”).
130
See United States v. Mullins, 992 F.2d 1472, 1478 (9th Cir. 1993) (holding that an employee of an electronic
communication service can act to “protect the rights and property of her employer by monitoring ... apparent misuse of
[the] electronic communication service.”); Campiti v. Walonis, 611 F.2d 387, 393 (1st Cir. 1979) (“The section is
obviously intended to allow the telephone company to intercept and disclose calls as a necessary protection of its
equipment and rights”) (emphasis added); United States v. Auler, 539 F.2d 642, 646 (7th Cir. 1976) (holding that
telephone companies which intercept calls pursuant to §2511(2)(a)(i) may forward to the police no more of the content
of those calls than “necessary to protect company rights and property.”); Hodge v. Mountain States Tel. & Tel. Co.,
555 F.2d 254, 260 (9th Cir. 1977) (“Congress enacted §2511(2)(a)(i) ‘to reflect existing law’ which allowed telephone
companies to intercept communications in order to protect the integrity of their property.”) (emphasis added).

Congressional Research Service

17

Cybersecurity and Information Sharing: Legal Challenges and Solutions

those of any third party.... ”131 As a consequence, there is a strong argument that while ECPA may
authorize private entities to monitor their own system and to share cyber-intelligence necessary to
protect their own system,132 the law likely does not authorize service providers to disclose or
divulge in real time to other private entities or the government133 the contents of electronic
communications for the purpose of protecting a third party’s property or rights.134 In other words,
a more narrow reading of the provider exception may cast doubt on the legality of certain cyberinformation sharing methods.

The Stored Communications Act
In contrast to the Wiretap Act, which focuses on the interception and disclosure of the contents of
communications in transmission, Title II of ECPA—the SCA—is centrally concerned with access
to and the disclosure of both content and non-content based electronic communications that are
kept in storage.135 In relevant part,136 the SCA in Section 2702 generally prohibits service
131

See Legal Issues Relating to the Testing, Use, & Deployment of an Intrusion-Detection Sys. (Einstein 2.0) to Protect
Unclassified Computer Networks in the Exec. Branch, 33 OP. O.L.C. 1 (2009).
132
See Broggi, supra note 31, at 669-70; see also Protecting America From Cyber Attacks: the Importance of
Information Sharing, Hearing Before the Senate Homeland Security and Gov’t Affairs Committee, (January 28, 2015),
statement of Gregory T. Nojeim, Senior Counsel and Director of the Freedom, Security and Technology Project, at pg.
5, available at https://d1ovv0c9tw0h0c.cloudfront.net/files/2015/01/HSGAC-Cybersec-tes-1-28-15-final-TEH.pdf
(hereinafter “Nojeim Testimony”).
133
The Wiretap Act does have other means for the government to intercept or receive electronic communications. See,
e.g., 18 U.S.C. §§2516-2518 (authorizing government access to covered communications pursuant to or in anticipation
of a court order); id. §2511(2)(i) (permitting “a person acting under color of law” to “intercept” the contents of “wire or
electronic communications of a computer trespasser transmitted to, through, or from [a] protected computer” under
limited circumstances).
134
See Aaron J. Burstein, Amending the ECPA to Enable a Culture of Cybersecurity Research, 22 HARV. J.L. & TECH.
167, 188 (2008) (“Even if a researcher intercepts electronic communications contents under the provider exception,
disclosing the contents to outside researchers might stretch the requirement of protecting the original service provider’s
rights or property.”) (emphasis added). Moreover, even if a provider, in collecting and sharing cyber-threat information,
is ostensibly acting out of self-interest, courts have been clear that ECPA, by permitting interceptions to “protect the
rights or property” of the provider, does not allow “unlimited” interceptions. See Auler, 539 F.2d at 646 (holding that
the authority of a service provider to intercept and disclose covered communications is “not unlimited”); Councilman,
418 F.3d at 82 (holding that it was “indisputable” that the “narrow[]” provider exception did not exempt a provider who
intercepted and copy all incoming communications to gain a commercial advantage). Instead, there must be a
“substantial nexus” between the monitoring and the threat to the provider’s rights or property. See United States v.
McLaren, 957 F. Supp. 215, 219 (M.D. Fla. 1997). The Department of Justice has interpreted the provider exception to
permit “providers and their agents to conduct reasonable monitoring that balances the providers’ needs to protect their
rights and property with their subscribers’ right to privacy.” See U.S. Dep’t of Justice, supra note 116, at 173. At least
one commentator has suggested that the substantial nexus test may limit the scope of what types of information can be
gathered to combat cyber-threats. See Burstein, supra note 134, at 187 (“Although cybersecurity researchers might ...
provide information that allows their employers to protect their networks, this connection is likely to be highly
attenuated ... since researchers usually develop methods of detecting malicious traffic, their results might not be
immediately applicable to that purpose.”).
135
See 18 U.S.C. §§2701-2702. What sorts of “storage” that the SCA regulates will depend several statutory terms that
will be explained in more detail infra.
136
The SCA also prohibits unauthorized access to an ECS facility and “thereby obtains, alters, or prevents authorized
access to [an] ... electronic communication while it is in electronic storage.... ” See 18 U.S.C. §2701(a). However,
Section 2701 exempts from that general prohibition “conduct authorized ... by the person or entity providing [an] ...
electronic communications service,” see id. §2701(c)(1), meaning that service providers that “obtain” electronic
communication while in storage for the purpose of determining cyber-threats are likely immune from liability under the
first prohibition in the SCA. See Fraser v. Nationwide Mut. Ins. Co., 352 F.3d 107, 115 (3d Cir. 2003) (“[W]e read
§2701(c) literally to except from Title II’s protection all searches by communications service providers ... because
Fraser’s email was stored on Nationwide’s system (which Nationwide administered), its search of that email falls
(continued...)

Congressional Research Service

18

Cybersecurity and Information Sharing: Legal Challenges and Solutions

providers engaged in either “electronic communications service” (ECS) or remote computing
service (RCS) to the public from divulging the contents137 of communications in their
possessions138 and subjects those that violate the SCA to civil liability.139 Notwithstanding that
general statement about Section 2702, the SCA is a notoriously complicated statute,140 and,
accordingly, Section 2702(a)’s central prohibition regarding the disclosure of the contents of
communications requires some clarification and several caveats.
First, to run afoul of Section 2702(a)(1)-(2)’s prohibition, the entity in question must provide
either ECS or RCS. ECS, as defined under the SCA, includes any service which provides users
the means to “send or receive ... electronic communication,”141 such as businesses that provide
text messaging142 or email143 services. An RCS, as defined by the SCA , entails “the provisions to
the public of computer storage or processing services by means of an electronic communications
system.”144 Courts have interpreted an RCS to refer to the long-term processing or storage of data
by an off-site third party.145 Second, not all disclosures by an ECS or RCS are prohibited by the
SCA; only disclosures of the contents of communications146—as opposed to address information,
like an email address147—would fall within the prohibition. Third, for an ECS provider, only
disclosures made while the underlying communication is in electronic storage amount to a
violation of the statute148—a status defined by the act as either (1) temporary, intermediate storage
of an electronic communication incidental to the transmission of that communication; or (2) any
storage of an electronic communication for backup protection.149 The definition of “electronic
storage” has been the source of considerable disagreement, with one prominent judicial opinion
(...continued)
within §2701(c)’s exception to Title II.”); see also In re Yahoo Mail Litig., 7 F. Supp. 3d at 1026-27 (“The SCA grants
immunity to 18 U.S.C. §2701(a) claims to [ECS providers] for accessing content on their own servers.”); Crowley v.
Cybersource Corp., 166 F. Supp. 2d 1263, 1272 (N.D. Cal. 2001) (holding that ECS “could not have limited access to
its own facilities.”); see generally Councilman, 418 F.3d at 82 (noting the “breadth” of §2701(c)(1)’s provider
exception).
137
18 U.S.C. §2702 prohibits what service providers can divulge with respect to non-content information only as it
relates to disclosures made to the government. See id. §2702(a)(3). For a discussion of §2702(a)(3), see infra “Privacy
Concerns.”
138
See 18 U.S.C. §2702(a)(1)-(2).
139
See 18 U.S.C. §2702(b)-(c) (including in the civil relief for a violation of the SCA (1) equitable relief; (2) actual
damages or at least $1,000; (3) punitive damages for willful or intentional conduct; (4) attorney fees).
140
United States v. Smith, 155 F.3d 1051, 1055 (9th Cir. 1998) (describing the SCA as a “complex, often convoluted,
area of the law.”).
141
18 U.S.C. §2510(15).
142
See, e.g., Quon v. Arch Wireless Operating Co., Inc., 529 F.3d 892, 902 (9th Cir. 2008), rev’d on other grounds by
City of Ontario v. Quon, 560 U.S. 746 (2010).
143
See, e.g., Theofel v. Farey-Jones, 359 F.3d 1066, 1075 (9th Cir. 2004).
144
Id. §2711(2). In turn, an electronic communication system is “any wire, radio, electromagnetic, photoptical or photo
electronic facilities for the transmission of wire or electronic communications, and any comput facilities or rleated
electronic equipment for the electronic storage of such communications.” Id. §2510(14).
145
See Quon, 529 F.3d at 901.
146
18 U.S.C. §2702(a)(1).
147
See, e.g., In re Zynga Privacy Litig., 750 F.3d 1098, 1108 (9th Cir. 2014) (noting that “email and IP addresses
‘constitute addressing information and do not necessarily reveal any more about the underlying contents of
communication than do phone numbers.’”) (internal citations omitted).
148
18 U.S.C. §2702(a)(1).
149
18 U.S.C. §2710(17)(A)-(B).

Congressional Research Service

19

Cybersecurity and Information Sharing: Legal Challenges and Solutions

interpreting “electronic storage” to encompass both electronic messages that have yet to be
delivered to their intended recipient, as well as electronic messages in backup storage by the
provider until “the underlying message has expired in the normal course,”150 while others have
criticized the notion of “electronic storage” encompassing opened emails serviced by an ECS.151
Fourth, for an RCS provider to violate 18 U.S.C. Section 2702(a)(2), the provider must disclose
the contents of communications that are (1) “on behalf of, and received by” a subscriber or
customer of the service; and (2) “solely for the purpose of providing storage or computer
processing services to ... [that] subscriber or customer.”152 The statutory prohibition necessarily
excludes providers of RCS to the public who are authorized to access the contents of
communication for purposes other than for storage and computer processing, such as for
advertising purposes.153
Putting to the side the exceptions to SCA’s prohibition found in 18 U.S.C. Section 2702(a)(1)-(2),
unlike the Wiretap Act, the SCA’s prohibition on disclosing communications in storage will be
unlikely to prohibit many forms of cyber-information sharing. After all, to violate the statute, a
company must not only disclose the contents of communications to another private entity, but the
company doing the disclosure must provide ECS or RCS to the public.154 In other words, if, for
example, an email provider to the public shares the IP address that was the source of a malicious
email to a ISAO, that email provider did not share content information and therefore likely did
not violate the SCA. Moreover, if a private entity provides email services to its employees and
shares the text of an email that is the source of a computer virus with another company, that
private entity likely did not violate the SCA because that entity does not provide ECS or RCS to
the public.
Nonetheless, many Internet Service Providers (ISPs) or email providers ostensibly provide ECS
or RCS to the public,155 and those companies may be interested in sharing the contents of
information with outsiders for cybersecurity purposes. If so, it is uncontroversial to say that
because of disputes over key terms like “electronic storage” and “RCS” and “ECS,” the SCA, as
currently written and interpreted, is hardly a model of clarity.156 The resulting ambiguity about the
legality of information sharing within the SCA’s general ambit may deter providers of ECS or
RCS to the public from sharing cyber-threat information with other private entities.157 After all,
150

See Theofel, 359 F.3d at 1076.
See Crispin v. Christian Audigier, Inc., 717 F. Supp. 2d 965, 987 (C.D. Cal. 2010); United States v. Weaver, 636 F.
Supp. 2d 769, 771-73 (C.D. Ill. 2009); see generally Orin S. Kerr, A User’s Guide to the Stored Communications Act,
and a Legislator’s Guide to Amending It, 72 GEO. WASH. L. REV. 1208, 1216-18 (2004) (explaining that emails that are
in transit or have been delivered but are unopened are in electronic storage by an ECS, while emails that have been
opened and saved exclusively on a server are stored in RCS) (hereinafter “Kerr-Guide”).
152
18 U.S.C. §2702(a)(2)(A)-(B).
153
Id. §2702(a)(2)(B); see also Viacom Int’l Inc. v. YouTube Inc., 253 F.R.D. 256, 264 n.8 (S.D.N.Y. 2008); Juror
Number One v. Superior Court, 206 Cal. App. 4th 854, 862 (“Thus, if the service is authorized to access the customer’s
information for other purposes, such as to provide targeted advertising, SCA protection may be lost.”).
154
18 U.S.C. §2702(a)(1)-(2).
155
See Kerr-Guide, supra note 151, at 1229-33; see also In re Application of the United States of America for a Search
Warrant for Contents of Electronic Mail and for an Order Directing a Provider of Electronic Communication Services
to not Disclose the Existence of the Search Warrant, 665 F. Supp. 2d 1210, 1214 (D. Or. 2009) (“Today, most ISPs
provide both ECS and RCS; thus, the distinction serves to define the service that is being provided at a particular time
(or as to a particular piece of electronic communication at a particular time), rather than to define the service provider
itself.”).
156
See Smith, 155 F.3d at 1055.
157
See Burstein, supra note 134, at 189; see also infra note 401 (discussing potential litigation costs).
151

Congressional Research Service

20

Cybersecurity and Information Sharing: Legal Challenges and Solutions

ambiguity in the law often breeds litigation, and the costs of litigation may be significant enough
to deter companies from engaging in cyber-information sharing.158
The hesitancy to participate in information sharing schemes may exist notwithstanding several
exceptions159 to the SCA’s general prohibition on the disclosure of certain types of electronic
communication held in storage.160 For example, while the SCA excludes from its prohibition on
the disclosure of communications disclosures made to a “person employed or authorized ... to
forward such communication to its destination,”161 that exception only eliminates liability for
those entities wishing to gather and share cyber-threat information within that organization162 and
does not sanction the sharing of the contents of a communication with an outsider. Moreover, the
SCA also contains a consent exception, allowing an ECS or RCS provider to divulge the contents
of a communication if the sender or recipient of that communication consents or, in the case of an
RCS, if the subscriber of the communication consents to the disclosure.163 Like the Wiretap Act’s
consent exception, the SCA’s consent exception is largely fact dependent, arguably providing
little assurance to a communications services provider that wishes to wholly eliminate litigation
risk.164 More specifically, the scope of the SCA’s consent exception is directly linked to a service
provider’s status as providing ECS or RCS, which may make the viability of the consent defense
contingent on the murky distinction between when a provider is acting in either role.165 Finally,
similar to the Wiretap Act, the SCA also contains a provider exception, and, much like its
counterpart in the Wiretap Act, the SCA’s provider exception is limited to allowing disclosures
that are necessary for the “protection of the rights or property of the provider”166 and arguably
does not extend to the protection of third parties that the provider may wish to share cyberintelligence.167

158

Id.
Besides the other exceptions mentioned in this paragraph, under the SCA’s exceptions to the prohibition in 18
U.S.C. §2702(a)(1)-(2), providers may divulge the contents of a communication to another private party to the extent
the disclosure is made: (1) to the addressee or intended recipient of such communication, id §2702(b)(1), or (2) to the
National Center for Missing and Exploited Children as required by federal statutes intended to prevent sexual
exploitation or trafficking of children or criminalize the possession, creation, or transportation of child pornography, id.
§§2702(b)(6), 2252A.
160
See 18 U.S.C. §2702(b).
161
Id. §2702(b)(4)
162
See Burstein, supra note 134, at 189.
163
See 18 U.S.C. §2702(b)(3) (“A provider ... may divulge the contents of a communication ... with the lawful consent
of the originator or an address or intended recipient of such communication, or the subscriber in the case of [RCS].”)
164
Compare Bower v. Mirvat El-Nady Bower, 808 F. Supp. 2d 348, 351 (D. Mass. 2011) (finding no consent); with
Flagg v. City of Detroit, 252 F.R.D. 346, 364 ( E.D. Mich. 2008) (finding consent).
165
See Theofel, 359 F.3d at 1076; Quon, 529 F.3d at 901-02; see generally Kerr-Guide, supra note 151, at 1215-16
(“The classifications of ECS and RCS are context sensitive: the key is the provider’s role with respect to a particular
copy of a particular communication, rather than the provider’s status in the abstract. A provider can act as an RCS with
respect to some communications, an ECS with respect to other communications, and neither an RCS nor an ECS with
respect to other communications.”).
166
See 18 U.S.C. §2702(b)(5) (“A provider ... may divulge the contents of a communication ... as may be necessarily
incident to the rendition of the service or to the protection of the rights or property of the provider of that service.”)
(emphasis added).
167
See Burstein, supra note 134, at 190; see also supra note 133 (discussing the “substantial nexus” test).
159

Congressional Research Service

21

Cybersecurity and Information Sharing: Legal Challenges and Solutions

The Pen/Trap Act
The final major federal privacy law potentially relevant to cyber-information sharing amongst
private parties is found in Title III of ECPA, Pen/Trap Act.168 The Pen/Trap Act has been referred
to as the “non-content counterpart” to the Wiretap Act, in that the Pen/Trap Act is concerned with
the real time capturing of non-content information,169 such as IP addresses and the “to” and
“from” fields in an email.170 Specifically, in 18 U.S.C. Section 3121, the Pen/Trap Act generally
prohibits any person from installing or using a “pen register or a trap and trace device,” devices
used outside of the ordinary course of business that capture either incoming or outgoing noncontent electronic information about the source of a communication, without first receiving
permission from a court.171 Violations of the Pen/Trap Act can result in criminal penalties,
including not more than one year in prison.172 Like its counterpart the Wiretap Act, the Pen/Trap
Act, also contains several exceptions to its general prohibition, including a (1) “provider
exception,” which permits service providers to use pen/trap devices for the “operation,
maintenance, and testing of [an] ... electronic communication service” or to protect the “rights
and property” of the provider or the “users of that service from abuse of service or unlawful use
of service,”173 (2) “consent exception,” which allows the use of pen/trap devices where the user of
the service has provided consent.174 Nonetheless, in sharp contrast to the Wiretap Act and the
SCA, the Pen/Trap Act contains no provisions barring the disclosure or divulgence of non-content
information derived from a pen/trap device.175
For a private entity wishing to share non-content cyber-threat information with a third party, the
Pen/Trap Act likely does not raise serious legal concerns. First, the Pen/Trap statute’s provider
exception likely eliminates any potential criminal liability that could arise from a company
168

18 U.S.C. §§3121-3127.
See Burstein, supra note 134, at 191.
170
See Daniel J. Solove, Reconstructing Electronic Surveillance Law, 72 GEO. WASH. L. REV. 1264, 1287 (2004)
(contending that “e-mail headers (the addressing information on e-mail messages), IP addresses, and Uniform Resource
Locators ... fall under [the] definition [of information captured by a pen/trap device].”); see also Dep’t of Justice, supra
note 116, at 154 (“Because Internet headers contain both ‘to’ and ‘from’ information, a device that reads the entire
header ... is both a pen register and trap and trace device.... ”).
171
18 U.S.C. §3121(a). Specifically, in relevant part, the Pen/Trap statute defines a “pen register” as a device that
records or captures information that is “reasonably likely to identify the source of [an] ... electronic communication,”
see id. §3127(3), whereas a “trap and trace device” is defined as one that captures incoming electronic or other
impulses that “identify the originating number or other dialing, routing, addressing, and signaling information
reasonably likely to identify the source of [an] ... electronic communication,” id. §3127(4). Both definitions exclude
devices that capture content information, id.§3127(3)-(4), and the definition for a pen register excludes “any device ...
used by a provider or customer of [an] ... electronic communication service for billing, or recording as an incident to
billing ... or any device ... used ... for cost accounting or other like purposes in the ordinary course of business,”
id.§3127(4).
172
See id.§3121(d).
173
18 U.S.C. §3121(b)(1).
174
Id. §3121(b)(3). The government can obtain authority to install a pen/trap device by certifying to a court “that the
information likely to be obtained [from a pen register] is relevant to an ongoing criminal investigation” being
conducted by a law enforcement agency. See 18 U.S.C. §3122(b).
175
Cf. United States v. Reed, 575 F.3d 900, 914 (9th Cir. 2009) (concluding that the Pen/Trap Act contains no
requirement that non-content information form a pen/trap device be sealed from public disclosure); see Burstein, supra
note 134, at 192 (“The Pen/Trap statute’s exception, however, si concerned only with the condition for allowing a
service provider to install a pen register; the statute lacks a corresponding disclosure provision.”); see also Broggi,
supra note 31, at 672 (“Unlike the Wiretap Act however, the statute is silent regarding voluntary disclosure of
information obtained under these exceptions.”).
169

Congressional Research Service

22

Cybersecurity and Information Sharing: Legal Challenges and Solutions

monitoring and capturing non-content information for cybersecurity purposes. After all, the
Pen/Trap Act’s provider exception sweeps more broadly than the provider exceptions in the
Wiretap Act or the SCA, in that Title III of ECPA allows providers to use a pen/trap device
“relating to the operation, maintenance, and testing of [an] ... electronic communication system....
”176 Given that nearly any electronic communication system, such as email or Internet
communication, necessarily depends on routing information from one source to another,177 it is
arguable that most private entities with genuine cybersecurity concerns may likely be capturing
non-content information as a natural product of the operating of an electronic communication
system anyway.178
Moreover, even if an entity’s decision to capture non-content address information is not related to
the “operation, maintenance, and testing of [an] ... electronic communication system,” the second
clause of the Pen/Trap Act’s provider exception allows the use of a pen/trap device to protect the
rights or property of the provider or the users of the service from “abuse of service or unlawful
use of service,”179 which would appear to encompass the circumstance where a private entity
collects non-content information to identify the source of a potential cyber-threat.180 In addition,
even if the provider exception does not allow the use of a pen/trap device, the consent exception
would allow a provider to capture non-content cyber-threat information with the agreement of the
provider’s user.181 Importantly, because the Pen/Trap Act only criminalizes the illegal use of
pen/trap devices and does not regulate the disclosures of non-content information culled from a
pen/trap device, once a provider has legally used a pen/trap device, there appears to be no reason
why a private entity should fear liability under the Pen/Trap Act if a company were, for example,
to share the IP address that was the source of malware with another private company.182

Other Federal and State Privacy Laws
While ECPA is the most prominently mentioned federal privacy law that could implicate cyberthreat information sharing efforts, other federal privacy laws could also plausibly deter the
exchange of cyber-intelligence amongst private entities. As noted above, ECPA’s privacy
protections are tied to (1) the age of the underlying communication, with communications in
storage generally getting less protection than communications that are being transferred in real
time, and (2) whether the underlying communication reveals substantive content, with noncontent information, such as IP addresses and email addresses, receiving fewer protections under
the statute.183 In contrast to ECPA, a host of various federal privacy laws target specific industries
176

18 U.S.C. §3121(b)(1).
See David D. Clark and Susan Landau, Untangling Attribution, 2 HARV. NAT’L SEC. J. 531, 534-35 (2011)
(describing all “data transport service of the Internet” as being based on packets, “small units of data prefixed with
delivery instructions.”).
178
See Columbia Pictures Industries v. Bunnell, No. 06-1093FMCJCX, 2007 WL 2080419, at *11 (C.D. Cal. May, 29,
2007 (holding that the capturing of an IP address necessary to “operate [a] website” falls within the Pen/Trap Act’s
provider exception).
179
18 U.S.C. §3121(b)(1).
180
See Broggi, supra note 31, at 672 (“The purpose of using signatures to scan network traffic is to protect the network
and its users from malicious activity.”).
181
18 U.S.C. §3121(b)(3).
182
There could be an argument that sharing non-content information with the government raises liability issues under
the SCA. See infra “Privacy Concerns.” Nonetheless, neither the SCA nor the Pen/Trap Act provide for criminal or
civil liability when a private entity discloses non-content information to another private entity.
183
See generally Omer Tenne, Quantifying Harm Structure: A New Harm Matrix for Cybersecurity Surveillance, 12 J.
(continued...)
177

Congressional Research Service

23

Cybersecurity and Information Sharing: Legal Challenges and Solutions

that tend to control personally identifying information (PII), such as names, addresses, phone
numbers, or Social Security numbers. For example, the Cable Communications Policy Act of
1984 (CCPA) generally prohibits “cable operators”184 from collecting and disclosing PII,185
subjecting entities that violate the CCPA’s privacy protections to civil liability.186 Some courts,
interpreting the CCPA, have concluded that cable providers when providing Internet services can
be subject to the Act’s privacy provisions,187 raising the specter of civil liability if a cable ISP
were to disclose PII—like a name or an email address—while sharing cyber-threat information
with another private entity.
Much as the CCPA could raise liability concerns for cable ISPs wishing to share cyberinformation with other private entities, so too could a variety of federal privacy laws raise legal
questions for the entities that are regulated by such laws. Indeed, several discrete federal privacy
laws regulate how PII is collected and disseminated. These laws target a variety of distinct
entities, including
•

consumer reporting agencies188

(...continued)
ON TELECOMM. & HIGH TECH. L. 391, 393-95 (2014) (discussing the key “legal distinctions that serve as proxies for the
measurement of privacy and civil liberties harms.”).
184
The CCPA defines cable operators as:
any person or group of persons (A) who provides cable service over a cable system and directly or
through one or more affiliates owns a significant interest in such cable system, or (B) who
otherwise controls or is responsible for, through any arrangement, the management and operation
of such a cable system.
47 U.S.C. §522(5).
185
47 U.S.C. §551(b)(1) & (c)(1). The statute does not define the term of art “personally identifiable information,” but
does exclude from the term “any record of aggregate data which does not identify particular persons.” Id.
§551(a)(2)(A). Nonetheless, courts have recognized the term to include “specific information about the subscriber, or a
list of names and addresses on which the subscriber is included.... ” See Scofield v. Telecable of Overland Park, Inc.,
973 F.2d 874, 876 n. 2 (10th Cir.1992). Another court has held that a person’s name, address, and telephone are
included in term “personal identifiable information.” See Warner v. Am. Cablevision of Kansas City, Inc. ., 699
F.Supp. 851, 855 (D.Kan.1988); see also Pruitt v. Comcast Cable Holdings, LLC, 100 Fed. App’x. 713, 716 (10th
Cir.2004) (holding that a cable box did not contain PII where, inter alia, it did not contain the name, address, or “any
other information regarding the customer.”). There are several exceptions to the CCPA’s general prohibition on
collecting or disclosing PII, including a consent exception, see 47 U.S.C. §551(b)(1) & (c)(1), an exception based on
the need to conduct a “legitimate business activity,” id. §551(b)(2) & (c)(2), and an exception for disclosure to the
government based on a court order, id.§551(c)(2)(B).
186
Id. §551(f) (allowing for liquidated damages calculated at a rate $100 for each day of a violation and punitive
damages).
187
See Digital Sin, Inc. v. Does 1-176, 279 F.R.D. 239, 241 (S.D.N.Y. 2012) (finding that “many ... ISPs ... qualify as
‘cable operators’ under the CPPA and subject to the restrictions found in 47 U.S.C. §551); see also Warner Bros.
Record Inc. v. Doe, 555 F. Supp. 2d 1, 2 (D.D.C. 2008) (ordering a subpoena to be issued upon a cable ISP under 47
U.S.C. §551(c)(2)); TCYK, Inc. v. Does 1-20, No. 3:13–cv–3927–L, 2013 WL 6475040, at *2 (N.D. Tex. December
10, 2014) (“The Cable Privacy Act prohibits cable operators, which includes the ISPs identified here, from disclosing
subscribers’ personal information without their consent or a court order.”); AF Holdings LLC v. Doe, No. 12cv1519–
BTM, 2012 WL 3238023, at *1-3 (S.D. Cal. January 29, 2013) (issuing an order under the CCPA for Cox
Communications to produce “produce documents and information sufficient to identify the user of the specified IP
address.”); see generally United States v. Kennedy, 81 F. Supp. 2d 1103, 1111 (D. Kan. 2000) (assuming without
holding that the CCPA applies to a “provider of high speed Internet services over cable wires”); but see Klimas v.
Comcast Cable Communs., Inc., 465 F.3d 271, 273 (6th Cir. 2006) (holding that the CCPA’s prohibition on the
collection and dissemination of PII did not extend cable providers that also functioned as ISPs).
188
See 15 U.S.C. §§1681, et seq. (Fair Credit Reporting Act).

Congressional Research Service

24

Cybersecurity and Information Sharing: Legal Challenges and Solutions

•

operators of websites or online services directed to children189

•

financial institutions190

•

videotape service providers191

•

educational agencies or institutions192

•

health plans, health care clearinghouses, and health care providers193

•

telecommunications carriers194

To the extent any one of these entities wishes to share cyber-intelligence within its possession
with others in the private sector, legal questions may abound if any of the information to be
shared contains material that is potentially protected under federal privacy law. None of the
aforementioned federal privacy laws specifically contemplate any exceptions for the sharing of
cyber-information for cybersecurity purposes. And, there is very little, if any, case law examining
how a given law applies to the specific context of the collection and dissemination of information
for cybersecurity purposes, leaving a legal lacuna for those regulated entities that may wish to
engage in cyber-information sharing.
Beyond federal privacy laws, states and localities have enacted countless laws that may prevent
or deter private entities from sharing cyber-intelligence with others. All but one of the fifty states
has an eav

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/crs%3AR43941. Public record. Not legal advice.
