Why It Matters
A key cybersecurity law that enables federal agencies and private companies to share threat information is set to expire on December 11, forcing Congress to decide whether to renew, modify, or let the Cybersecurity Information Sharing Act of 2015 (CISA) lapse entirely.
The expiration would strip away explicit protections that shield private entities from antitrust liability, shield them from legal liability for monitoring and sharing cyber threat information, and exempt shared data from public disclosure requirements.
The Big Picture
The Cybersecurity Information Sharing Act of 2015 was originally authorized for ten years and passed as Title I of the Cybersecurity Act of 2015, creating a legal framework for federal agencies and private companies to voluntarily exchange cyber threat indicators and defensive measures.
The law requires federal agencies to establish procedures for sharing classified and unclassified cyber threat information with federal and nonfederal entities, while mandating that personally identifiable information be stripped from all shared data and that the Departments of Homeland Security and Justice issue guidance on protecting civil liberties.
The primary implementation mechanism is the Automated Indicator Sharing Program, a voluntary initiative that enables real-time, machine-to-machine sharing of technical artifacts and observables suggesting cyberattacks or compromises, drawing indicators from both government agencies and the private sector.
Broader Context
Recent Inspector General reviews have found no violations of the law's privacy protections, though the statute now faces pressure from emerging technologies and threat vectors not contemplated when it was drafted. Operational technology systems and edge devices, which connect physical infrastructure like industrial control systems to networks, are not explicitly addressed in the law's definitions, yet nation-state actors and cybercriminals have increasingly targeted both categories of equipment.
Artificial intelligence is similarly not specifically addressed in the statute, leaving Congress to consider whether to update the law's language to encompass novel attack vectors and new defensive methods or adopt more flexible wording that anticipates future technological shifts.
Several industry groups have advocated for long-term renewal of the law, and Congress also enacted the Cyber Incident Reporting for Critical Infrastructure Act of 2022 to complement it, with the two statutes working in tandem rather than as substitutes for each other, one providing ongoing threat intelligence and the other capturing incident data after attacks occur.
The Bottom Line
Congress faces a choice between extending the law as written, modifying it to address gaps in coverage for emerging technologies, or letting core protections lapse and leaving companies and agencies to rely on alternative authorities that may lack the same legal safeguards.
Lawmakers could also consider whether to require certain entities, such as critical infrastructure operators or cyber threat information aggregators, to participate in sharing rather than keeping it voluntary, fundamentally reshaping how the government receives warning of threats.
Access the Legis1 platform for comprehensive political news, data, and insights.
Spot something wrong? Report an issue with this article