justice.gov web signal

DOJ and FTC greenlight sharing of cyber threat information

TL;DR

  • The DOJ and FTC issued a joint antitrust policy statement on April 10, 2014, saying properly designed cyber threat information sharing does not raise antitrust concerns.
  • The agencies draw a line between technical threat data (incident reports, indicators, threat signatures) and competitively sensitive data like current or future prices, output, or business plans.
  • Named officials including FTC Chairwoman Edith Ramirez, Deputy Attorney General James M. Cole, and Assistant Attorney General Bill Baer framed the statement as removing an antitrust deterrent to legitimate sharing.

The Department of Justice and Federal Trade Commission issued a joint policy statement on April 10, 2014 telling companies that legitimate sharing of cybersecurity threat data is not an antitrust problem.

The statement draws a line between technical threat information, such as incident reports, indicators and threat signatures, and competitively sensitive information such as current or future prices and output or business plans.

"Cyber threats are increasing in number and sophistication, and sharing information about these threats, such as incident reports, indicators and threat signatures, is something companies can do to protect their information systems and help secure our nation's infrastructure," said Assistant Attorney General Bill Baer of the DOJ's Antitrust Division. "With proper safeguards in place, cyber threat information sharing can occur without posing competitive concerns."

FTC Chairwoman Edith Ramirez said the statement "should help private businesses by making it clear that antitrust laws do not stand in the way of legitimate sharing of cybersecurity threat information." Deputy Attorney General James M. Cole said private parties "play a critical role in mitigating and responding to cyber threats, and this policy statement should encourage them to share cybersecurity information."

Shared on Bluesky by 2 AI experts