After a number of delays, amendment shuffles and even a little floor debate, the Cybersecurity Information Sharing Act (CISA) is now on track for a Senate vote as early as Oct. 27.
Through Information Sharing and Analysis Organizations (ISAOs), government and private industry would share data on known threat vectors in real-time — or near-real-time, depending on who you ask — in order to keep up with hackers and other bad actors.
The sharing and dissemination of that information would be coordinated by the Department of Homeland Security, which has already begun developing standards and reorganizing for the task.
The bill would codify the provisions of an executive order issued earlier this year to facilitate information sharing between the private sector and government on known cybersecurity threats.
FREE WEBCAST: Learn how military planners are strengthening networks with NETCOM’s COL David Isaacson on Oct. 29
“There is no easy solution but there are things Congress can do to improve cybersecurity that might make cyberattacks more difficult,” Sen. Ron Johnson, R-Wisc., said Oct. 22Thursday.
Referencing hearings held by the Senate Committee on Homeland Security and Governmental Affairs, which he chairs, Johnson pointed to recent high-profile breaches of government networks that might have been prevented, in part, by information sharing.
“Our committee’s oversight hearings on the IRS and OPM data breaches revealed that basic cybersecurity hygiene and best practices would have stopped attackers in their tracks had they been in place at these agencies,” Johnson said.
Opponents of the bill are generally in favor of information sharing, however they say it doesn’t include enough protections for users, whose personal information might be given to the government and subsequently shared without the individual’s permission.
Some of the amendments scheduled for debate on Tuesday before the vote — including those submitted by Sens. Ron Wyden, D-Ore., Dean Heller, R-Nev., Patrick Leahy, D-Vt., and Chris Coons, D-Del. — include language that would prevent the collection of personally identifiable information or at least limit its dissemination.
Other amendments still under consideration include a six-year sunset clause offered by Sen. Jeff Flake, R-Ariz., and would better define “cybersecurity threat” and “cyber threat indicators,” as offered by Sen. Al Franken, D-Minn.
After debate on several outstanding amendments on Tuesday, the Senate will consider a motion to invoke cloture (giving the body 30 hours to hold a vote) or might just take up a vote that evening.
If CISA passes, the bill would have to be merged with two House bills that passed earlier this year before undergoing a conference vote.




