On the recordApril 23, 2015
I thank the gentleman for yielding. Mr. Chairman, I am very pleased to be back on the floor today to support the House's second major piece of cybersecurity legislation in less than 24 hours. As I said yesterday afternoon, it has been a long time coming, for sure. Cybersecurity has been a passion of mine for nearly a decade, and I am absolutely thrilled that, after years of hard work, the House, the Senate, and the President finally are beginning to see eye-to-eye. The National Cybersecurity Protection Advancement Act has at its core three basic authorizations. First, it authorizes private entities and the DHS's NCCIC to share, for cybersecurity purposes only, cyber threat indicators that have been stripped of personal information and details. Second, it allows businesses to monitor their networks in search of cybersecurity risks. And third, it authorizes companies to deploy limited defensive measures to protect their systems from malicious actors. Those three authorizations perfectly describe the information-sharing regime we so desperately need. Under the act, companies would collect information on threats, share it with their peers and with a civilian portal, and then use the indicators they have received to defend themselves. Data are scrubbed of personal identifiable information before they are shared and after they are received by the NCCIC. Companies are offered limited liability protections for sharing information they gather in accordance with this bill.…





