11.2 FISA 702, PATRIOT, USA Freedom, and CISA
Key Takeaways
- FISA Section 702 (50 U.S.C. § 1881a, added 2008) authorizes targeting of non-United States persons reasonably believed to be located outside the United States to acquire foreign intelligence; it is not an individualized warrant program for U.S. persons
- U.S.-person communications are collected incidentally when a U.S. person communicates with a 702 target; minimization procedures, not a targeting ban, govern that incidental take
- USA PATRIOT Act § 215 was the historical authority for bulk telephony-metadata collection; the USA FREEDOM Act of 2015 ended bulk collection under § 215, FISA pen/trap, and national security letters and required a specific selection term
- A national security letter is an FBI administrative demand for specified non-content records (classically 18 U.S.C. § 2709 subscriber and toll records), often with a nondisclosure order, not a content warrant
- The Cybersecurity Information Sharing Act of 2015 is a voluntary cyber-threat-indicator sharing authorization with liability, antitrust, and disclosure protections and a personal-information scrub; it is not a surveillance statute like Section 702
11.2 FISA 702, PATRIOT, USA Freedom, and CISA
Competency III.B is national-security and cyber-sharing access. Four labels dominate the items: the Foreign Intelligence Surveillance Act of 1978 (FISA) and its Section 702; USA PATRIOT Act § 215; the USA FREEDOM Act of 2015; and the Cybersecurity Information Sharing Act of 2015 (CISA). The exam’s recurring mistake is to treat every national-security acronym as a wiretap. Only some of them are collection authorities. CISA is not.
FISA 1978 and Section 702 (2008)
FISA, 50 U.S.C. Chapter 36, is Congress’s response to the Church Committee findings of warrantless domestic intelligence collection. Traditional FISA (Titles I and III of the 1978 Act) requires an individualized order from the Foreign Intelligence Surveillance Court (FISC) to conduct electronic surveillance or a physical search in the United States of a foreign power or its agent. That individualized-order regime is not Section 702.
Section 702 was added by the FISA Amendments Act of 2008, Pub. L. 110-261, and is codified at 50 U.S.C. § 1881a. The statutory targeting rule is the sentence to memorize: the Attorney General and the Director of National Intelligence may jointly authorize, for up to one year, the targeting of persons reasonably believed to be located outside the United States to acquire foreign intelligence information, and the title of the section is “certain persons outside the United States other than United States persons.” The government may not intentionally target a United States person, or any person known to be located in the United States. If a non-U.S. person target later enters the United States, targeting under 702 must stop. There is no probable-cause warrant for each selector. The FISC reviews targeting procedures, minimization procedures, and a certification — not a name-by-name probable-cause affidavit for every email address.
Two collection methods are how the Privacy and Civil Liberties Oversight Board and the intelligence community have long described the program. Downstream collection (historically called PRISM) sends selectors — email addresses, telephone numbers, similar identifiers — to U.S. electronic-communications service providers, which must produce communications to or from those selectors. Upstream collection compels providers that operate internet backbone circuits inside the United States to assist in acquiring communications that transit those circuits. Upstream historically included “about” collection (communications that mentioned a selector but were not to or from it); the National Security Agency ended upstream “about” collection in 2017. Teach the architecture as commonly described. Do not invent a later statute that merged PRISM and upstream into a single new title.
Incidental collection is the U.S.-person issue the exam actually tests. When a U.S. person emails or calls a 702 target, that U.S. person’s side of the communication is acquired even though the U.S. person was not the target. That take is lawful under 702 if the targeting rules were followed. What happens next is minimization: procedures, also FISC-reviewed, that limit how U.S.-person information may be used, retained, and disseminated. Querying already-collected 702 data for a U.S.-person identifier (the so-called “backdoor search”) is a policy and reauthorization fight, not a second targeting decision. RISAA, the Reforming Intelligence and Securing America Act of April 20, 2024, was the last comprehensive congressional reauthorization and attached a two-year sunset. Section 702 is a sunsetted authority Congress reauthorizes periodically; FISC annual certifications can keep existing directives running until those certifications expire even if the statute lapses. As of mid-August 2026, teach the § 1881a design — non-U.S. person, reasonably believed abroad, incidental U.S.-person collection, minimization. Do not invent a post-RISAA rewrite of those targeting rules.
USA PATRIOT § 215, bulk metadata, and USA FREEDOM
Section 215 of the USA PATRIOT Act of 2001 amended FISA’s business-records provision (then 50 U.S.C. § 1861) so the government could obtain any tangible thing from a third party if it was relevant to an authorized foreign-intelligence investigation. After 2013 disclosures, it became public that the FISC had interpreted “relevance” to authorize the National Security Agency’s bulk telephony-metadata program: collection of large volumes of call-detail records, including records of U.S. persons, with querying done later inside the government’s store.
The USA FREEDOM Act of 2015, Pub. L. 114-23, is the statute that ended that bulk program. Congress prohibited bulk collection under § 215, under FISA pen-register authority, and under the national security letter (NSL) statutes. In place of bulk § 215 collection it created a targeted call-detail-records mechanism: the government had to use a specific selection term that identifies a person, account, address, or personal device and limits the request to the greatest extent reasonably practicable, and the records stayed with the providers until a FISC order required production. After a 180-day transition, bulk § 215 telephony-metadata collection ended on November 28–29, 2015 (ODNI/DOJ fact sheet). The later targeted call-detail-records program was itself suspended by the NSA in 2019, and the underlying § 215/USA FREEDOM business-records authority sunset in March 2020 when Congress did not complete a reauthorization. Teach § 215 bulk collection as historical. Do not describe a live NSA bulk-metadata dragnet under current § 215.
National security letters remain. An NSL is an FBI administrative demand issued without prior judicial approval. The ECPA NSL, 18 U.S.C. § 2709, is the classic CIPP/US specimen: subscriber name, address, length of service, and local and long-distance toll billing records relevant to an authorized investigation to protect against international terrorism or clandestine intelligence activities. It is not a content warrant and not a 702 directive. Companion NSL statutes reach certain financial records (including an RFPA NSL at 12 U.S.C. § 3414) and credit reports. NSLs often arrive with a nondisclosure (gag) order. The USA PATRIOT Improvement and Reauthorization Act added judicial review; the USA FREEDOM Act adjusted gag-order review (18 U.S.C. § 3511), required the government to initiate court review when the recipient challenges the gag, banned bulk use of NSLs, and allowed banded transparency reporting. Recipients can produce non-content records and still owe their users a privacy analysis; they cannot treat an NSL as authorization to hand over email bodies.
Cybersecurity Information Sharing Act — sharing, not surveillance
CISA 2015 is Title I of the Cybersecurity Act of 2015, 6 U.S.C. §§ 1501–1510. CRS In Focus IF12959 (updated May 8, 2026) is the official short description. Private entities may share cyber-threat indicators and defensive measures with other private entities and with the federal government, typically through the Department of Homeland Security (DHS) process (the Automated Indicator Sharing (AIS) program is the technical implementation). Sharing is voluntary. In exchange, the statute provides:
- Liability protection for monitoring information systems, operating defensive measures, and sharing in accordance with the Act (6 U.S.C. § 1505).
- Antitrust protection for sharing conducted as authorized.
- Exemption from federal and state disclosure statutes (including the Freedom of Information Act) for information shared under the Act.
- A privacy scrub: the sharer must remove personal information not directly related to a cybersecurity threat before sharing, and DHS and the Department of Justice must publish civil-liberties guidelines.
CISA is not a collection order. It does not authorize the government to compel a company’s mailboxes, to query 702 repositories, or to bypass ECPA. A company that shares an indicator (a malicious IP, a malware hash, a command-and-control domain) after stripping customer names is using CISA. A company that receives a 702 directive to produce a named non-U.S. person’s account is in a different statute.
Sunset status (teach what CRS states, not a rumor). Congress originally authorized CISA for ten years, through September 30, 2025. CRS reported that the provisions were extended to September 30, 2026 in the FY2026 Consolidated Appropriations Act. As of 14 August 2026 the sharing authorization and its liability and scrub conditions remain the law the exam tests. Do not treat CISA as a permanent surveillance title, and do not confuse the statute named CISA with the Cybersecurity and Infrastructure Security Agency (also abbreviated CISA) that operates AIS.
Scenario. A U.S. software firm’s security team wants to send DHS a packet capture of a ransomware intrusion that still contains employee email addresses and a customer list sitting in the same log line as the attacker’s IP. Counsel’s CISA checklist is: this is voluntary sharing, not a 702 or NSL response; strip the employee and customer identifiers that are not needed to describe the threat; send the indicator through the DHS process if the firm wants the Act’s liability and FOIA protections; and keep a record of the scrub. If, the same week, the firm receives an FBI NSL for a subscriber’s billing records and a FISC 702 directive for a foreign target’s account, those papers are compelled process under different titles. CISA’s liability shield does not authorize, and does not excuse, over-production on the NSL or the 702 directive.
Exam traps
- Section 702 targets non-U.S. persons reasonably believed abroad. It is not a domestic Title III wiretap of a U.S. person, and incidental U.S.-person collection is handled by minimization, not by pretending it does not occur.
- USA PATRIOT § 215 bulk telephony metadata is the historical program. USA FREEDOM ended bulk collection and required a specific selection term; the later targeted call-detail program was suspended and the authority sunset in 2020.
- An NSL is administrative non-content process plus a possible gag. It is not a super-warrant and not a 702 selector.
- CISA authorizes voluntary, scrubbed sharing and gives liability protection. It is not “702 for malware” and does not compel disclosure.
Under FISA Section 702, which targeting statement is accurate?
What did the USA FREEDOM Act of 2015 do to the USA PATRIOT Act § 215 bulk telephony-metadata program?
A retailer wants to send the Department of Homeland Security a malware hash and the attacker’s command-and-control domain from last night’s intrusion, after deleting customer names that appeared in the same log. Which statute is the sharing authorization, and what is it not?