ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

6 U.S.C. § 673Protection of voluntarily shared critical infrastructure information

submitted 24 years ago by Pub. L. 107-296 to r/title-6-DOMESTIC-SECURITY · 1,143 words · no verdicts yet

in plain englishAI-generated · not legal advice

This section protects qualifying voluntarily submitted critical-infrastructure information from disclosure and specified uses. It sets handling procedures, criminal penalties for unauthorized disclosure, and authority to issue warnings.

(a) Protection. (1) General rule. Critical-infrastructure information, including who submitted it, that a person or entity voluntarily gives to a covered federal agency for security, protected-systems, analysis, warning, interdependency study, recovery, reconstitution, or another information purpose is protected when accompanied by the statement in paragraph (2). It (A) is exempt from disclosure under section 552 of title 5 (the Freedom of Information Act); (B) is not subject to agency rules or court doctrines about ex parte communications with a decision-maker; (C) may not, without the submitter’s written consent, be used directly by that agency, another federal, State, or local authority, or a third party in a civil case under federal or State law if submitted in good faith; (D) may not, without written consent, be used or disclosed by a United States officer or employee for a purpose outside this part, except (i) to investigate or prosecute a crime, or (ii) to either House of Congress, its committees or subcommittees, or a joint committee or subcommittee on matters within its jurisdiction, or to the Comptroller General or an authorized representative while performing Government Accountability Office duties; (E) when given to a State or local government or agency, (i) may not be made available under a State or local disclosure law, (ii) may not otherwise be disclosed or distributed without the submitter’s written consent, and (iii) may be used only to protect critical infrastructure or protected systems or investigate or prosecute a crime; and (F) does not waive a privilege or protection under law, including trade-secret protection. (2) Express statement. For written information or records, this means a written marking substantially saying: “This information is voluntarily submitted to the Federal Government in expectation of protection from disclosure as provided by the provisions of the Critical Infrastructure Information Act of 2002.” For oral information, it means a similar written statement submitted within a reasonable time after the oral communication. (b) Limit. Communicating critical-infrastructure information to a covered federal agency under this part is not an action subject to title 5, chapter 10. (c) Independently obtained information. This section does not limit a federal, State, or local government entity, agency, authority, or third party from obtaining information under applicable law in a way not covered by (a), including information lawfully and properly disclosed generally or broadly to the public, or from using it in any way the law allows. A permitted use includes disclosure under section 2302(b)(8) of title 5. (d) Voluntary submission does not satisfy another duty. Voluntarily giving the Government information protected by this part does not count as complying with a separate law requiring that information to be submitted to a federal agency. (e) Procedures. (1) The Secretary of Homeland Security, consulting appropriate National Security Council and Office of Science and Technology Policy representatives, must establish uniform procedures for federal agencies to receive, care for, and store voluntarily submitted critical-infrastructure information. The procedures had to be established within 90 days after November 25, 2002. (2) They must include mechanisms for (A) acknowledging receipt; (B) keeping the information identified as voluntarily submitted and subject to this part; (C) caring for and storing it; and (D) protecting and maintaining its confidentiality while allowing sharing within the federal government and with State and local governments and issuing infrastructure warnings, in a way that protects from public disclosure the submitter’s identity and information that is proprietary, business-sensitive, specifically related to the submitter, or otherwise not properly public. (f) Penalties. A United States officer or employee who knowingly publishes, divulges, discloses, or otherwise makes known, beyond what law allows, protected critical-infrastructure information received through employment, official duties, an examination or investigation, or a return, report, or record filed with the officer, employee, department, or agency, may be fined under title 18, imprisoned for up to one year, or both, and must be removed from office or employment. (g) Warnings. The federal government may issue advisories, alerts, and warnings about possible critical-infrastructure threats to relevant companies, targeted sectors, other governments, or the public. It must take appropriate steps to protect from disclosure (1) the source of voluntarily submitted information supporting the warning and (2) proprietary, business-sensitive, submitter-specific, or otherwise nonpublic information. (h) Delegation. The President may delegate to a critical-infrastructure-protection program designated under section 672 authority to enter a voluntary agreement promoting infrastructure security, including an agreement with an Information Sharing and Analysis Organization, or a plan of action as defined in section 4558 of title 50.
the actual law source: uscode.house.gov ↗public domain
(a) Protection
(1) In general

Notwithstanding any other provision of law, critical infrastructure information (including the identity of the submitting person or entity) that is voluntarily submitted to a covered Federal agency for use by that agency regarding the security of critical infrastructure and protected systems, analysis, warning, interdependency study, recovery, reconstitution, or other informational purpose, when accompanied by an express statement specified in paragraph (2)—

(A)

shall be exempt from disclosure under section 552 of title 5 (commonly referred to as the Freedom of Information Act);

(B)

shall not be subject to any agency rules or judicial doctrine regarding ex parte communications with a decision making official;

(C)

shall not, without the written consent of the person or entity submitting such information, be used directly by such agency, any other Federal, State, or local authority, or any third party, in any civil action arising under Federal or State law if such information is submitted in good faith;

(D)

shall not, without the written consent of the person or entity submitting such information, be used or disclosed by any officer or employee of the United States for purposes other than the purposes of this part, except—

(i)

in furtherance of an investigation or the prosecution of a criminal act; or

(ii)

when disclosure of the information would be—

(I)

to either House of Congress, or to the extent of matter within its jurisdiction, any committee or subcommittee thereof, any joint committee thereof or subcommittee of any such joint committee; or

(II)

to the Comptroller General, or any authorized representative of the Comptroller General, in the course of the performance of the duties of the Government Accountability Office.1

(E)

shall not, if provided to a State or local government or government agency—

(i)

be made available pursuant to any State or local law requiring disclosure of information or records;

(ii)

otherwise be disclosed or distributed to any party by said State or local government or government agency without the written consent of the person or entity submitting such information; or

(iii)

be used other than for the purpose of protecting critical infrastructure or protected systems, or in furtherance of an investigation or the prosecution of a criminal act; and

(F)

does not constitute a waiver of any applicable privilege or protection provided under law, such as trade secret protection.

(2) Express statement

For purposes of paragraph (1), the term “express statement”, with respect to information or records, means—

(A)

in the case of written information or records, a written marking on the information or records substantially similar to the following: “This information is voluntarily submitted to the Federal Government in expectation of protection from disclosure as provided by the provisions of the Critical Infrastructure Information Act of 2002.”; or

(B)

in the case of oral information, a similar written statement submitted within a reasonable period following the oral communication.

(b) Limitation

No communication of critical infrastructure information to a covered Federal agency made pursuant to this part shall be considered to be an action subject to the requirements of chapter 10 of title 5.

(c) Independently obtained information

Nothing in this section shall be construed to limit or otherwise affect the ability of a State, local, or Federal Government entity, agency, or authority, or any third party, under applicable law, to obtain critical infrastructure information in a manner not covered by subsection (a), including any information lawfully and properly disclosed generally or broadly to the public and to use such information in any manner permitted by law. For purposes of this section a permissible use of independently obtained information includes the disclosure of such information under section 2302(b)(8) of title 5.

(d) Treatment of voluntary submittal of information

The voluntary submittal to the Government of information or records that are protected from disclosure by this part shall not be construed to constitute compliance with any requirement to submit such information to a Federal agency under any other provision of law.

(e) Procedures
(1) In general

The Secretary of the Department of Homeland Security shall, in consultation with appropriate representatives of the National Security Council and the Office of Science and Technology Policy, establish uniform procedures for the receipt, care, and storage by Federal agencies of critical infrastructure information that is voluntarily submitted to the Government. The procedures shall be established not later than 90 days after November 25, 2002.

(2) Elements

The procedures established under paragraph (1) shall include mechanisms regarding—

(A)

the acknowledgement of receipt by Federal agencies of critical infrastructure information that is voluntarily submitted to the Government;

(B)

the maintenance of the identification of such information as voluntarily submitted to the Government for purposes of and subject to the provisions of this part;

(C)

the care and storage of such information; and

(D)

the protection and maintenance of the confidentiality of such information so as to permit the sharing of such information within the Federal Government and with State and local governments, and the issuance of notices and warnings related to the protection of critical infrastructure and protected systems, in such manner as to protect from public disclosure the identity of the submitting person or entity, or information that is proprietary, business sensitive, relates specifically to the submitting person or entity, and is otherwise not appropriately in the public domain.

(f) Penalties

Whoever, being an officer or employee of the United States or of any department or agency thereof, knowingly publishes, divulges, discloses, or makes known in any manner or to any extent not authorized by law, any critical infrastructure information protected from disclosure by this part coming to him in the course of this employment or official duties or by reason of any examination or investigation made by, or return, report, or record made to or filed with, such department or agency or officer or employee thereof, shall be fined under title 18, imprisoned not more than 1 year, or both, and shall be removed from office or employment.

(g) Authority to issue warnings

The Federal Government may provide advisories, alerts, and warnings to relevant companies, targeted sectors, other governmental entities, or the general public regarding potential threats to critical infrastructure as appropriate. In issuing a warning, the Federal Government shall take appropriate actions to protect from disclosure—

(1)

the source of any voluntarily submitted critical infrastructure information that forms the basis for the warning; or

(2)

information that is proprietary, business sensitive, relates specifically to the submitting person or entity, or is otherwise not appropriately in the public domain.

(h) Authority to delegate

The President may delegate authority to a critical infrastructure protection program, designated under section 672 of this title, to enter into a voluntary agreement to promote critical infrastructure security, including with any Information Sharing and Analysis Organization, or a plan of action as otherwise defined in section 4558 of title 50.

Source credit: (Pub. L. 107–296, title XXII, § 2224, formerly title II, § 214, Nov. 25, 2002, 116 Stat. 2152; Pub. L. 108–271, § 8(b), July 7, 2004, 118 Stat. 814; Pub. L. 112–199, title I, § 111, Nov. 27, 2012, 126 Stat. 1472; renumbered title XXII, § 2224, and amended Pub. L. 115–278, § 2(g)(2)(H), (9)(B)(ii), Nov. 16, 2018, 132 Stat. 4178, 4181; Pub. L. 117–286, § 4(a)(18), Dec. 27, 2022, 136 Stat. 4307.)

history & why it existsrecord from the source credit
  • 2002Enacted · Pub. L. 107-296 · 116 Stat. 2152
  • 2004Amended · Pub. L. 108-271 · 118 Stat. 814
  • 2012Amended · Pub. L. 112-199 · 126 Stat. 1472
  • 2018Amended · Pub. L. 115-278 · 132 Stat. 4178, 4181
  • 2022Amended · Pub. L. 117-286 · 136 Stat. 4307

A history note hasn’t been published yet. The record shows enactment by Pub. L. 107-296 on 2002-11-25.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case