CISPA is an amendment to the National Security Act of 1947, which does not currently contain provisions pertaining to cybercrime. It adds provisions to the Act describing cyber threat intelligence as "information in possession of an element of the intelligence community directly pertaining to a vulnerability of, or threat to, a system or network of a government or private entity, including information pertaining to the protection of a system or network from either "efforts to degrade, disrupt, or destroy such system or network".[16] In addition, CISPA requires the Director of National Intelligence to establish procedures to allow intelligence community elements to share cyber threat intelligence with private-sector entities and encourage the sharing of such intelligence.[17][18]
In an April 16, 2012, press release, the House of Representatives Permanent Select Committee on Intelligence announced the approval of several amendments to CISPA, including the addition of a new provision "to permit federal lawsuits against the government for any violation of restrictions placed on the government's use of voluntarily shared information, including the important privacy and civil liberties protections contained in the bill", the inclusion of an anti-tasking provision to "explicitly prohibits the government from conditioning its sharing of cyber threat intelligence on the sharing of private sector information with the government", and the prevention of the government from using the information for "any other lawful purpose unless the government already has a significant cybersecurity or national security purpose in using the information". Relevant provisions were also clarified to "focus on the fact that the bill is designed to protect against unauthorized access to networks or systems, including unauthorized access aimed at stealing private or government information".[19] In addition, already collected cyberthreat data can also be used to investigate "the imminent threat of bodily harm to an individual" or "the exploitation of a minor," bringing the bill into line with existing law codified by the Patriot Act and the PROTECT Our Children Act[20] in which these two conditions already allow for protected entities to share data voluntarily with the United States government, law enforcement agencies, and the National Center for Missing and Exploited Children.[21]
The Sunlight Foundation states, "The new cybersecurity bill, CISPA, or HR 3523, is terrible on transparency. The bill proposes broad new information collection and sharing powers (which many other organizations are covering at length). Even as the bill proposes those powers, it proposes to limit public oversight of this work."[52]
Cenk Uygur, from Current TV, opposed the bill highlighted one of Mike Rogers' speech about the bill to the business community. He also attempted to summarize the bill to his audience.[53]
Demand Progress opposes CISPA, stating "The Cyber Intelligence Sharing and Protection Act, or CISPA, would obliterate any semblance of online privacy in the United States."[54]
Reporters Without Borders states, "Reporters Without Borders is deeply concerned with the Cyber Intelligence Sharing and Protection Act of 2011 (CISPA), the cyber security bill now before the US Congress. In the name of the war on cyber crime, it would allow the government and private companies to deploy draconian measures to monitor, even censor, the Web. It might even be used to close down sites that publish classified files or information."[56]
testPAC opposes CISPA stating "CISPA would effectively take the door off the hinge of every household in America, but lacks the tools necessary to distinguish whether there is a criminal hiding in the attic. Why surrender the core of our privacy for the sake of corporate and governmental convenience?"
Mozilla, the makers of the Firefox Web-Browser, opposes CISPA stating, "While we wholeheartedly support a more secure Internet, CISPA has a broad and alarming reach that goes far beyond Internet security."[57]