There have been very many versions of laws similar to CISA that have been proposed, modified, and changed/passed/failed/delayed. When I try to understand exactly what this CISA version includes, most rhetoric I read is alarmist and not conducive to actually knowing what can and cannot be done under CISA. Is there a digestible explanation of what this CISA entails?
CISA defines "cybersecurity threats" and "threat indicators", which are now legalese versions of the stuff Intrusion Detection Systems track: exploit code, vulnerability information, and wire traces of attacks.
Everyone already collects this stuff; that's most of what network security teams are paid to do. The government has several huge network security teams (they operate the largest IT system in the world), and, of course, the whole Fortune 500 does as well. All these organizations are collecting information about attacks and siloing it.
CISA requires the government to establish a process to share indicators with private companies. So when analysts or IPS systems or anomaly detection schemes running inside FedGov networks generate a signature for an attack, there will now be federal rules requiring them to submit that data to a process that will disseminate it to the private sector.
CISA allows the private sector to do the same thing in reverse, sharing their data with the government, which will in turn share a facsimile of that data back out to the rest of the private sector. The bill requires companies to have a process to ensure they aren't knowingly sharing any personally identifying information, and they are only allowed to share information that pertains to the types of attacks defined as "cybersecurity threats". Those attacks specifically exclude terms of service violations.
Unlike CISPA, which was a more benign bill, CISA explicitly allows local, state, and federal law enforcement to use threat indicators to prosecute crimes. CISA has a very short list of crimes whose prosecution can be assisted with shared indicators --- identity theft, espionage, and trade secret theft. PCNA, the (now dead) House version of CISA, had a broader list.
Unlike the law of the land before CISPA/CISA/PCNA was proposed, there is now a path for private companies to share data with the USG regardless of the other regulatory regimes they're under. This is good if you think sharing attack information is very important and bad if you think companies that work with regulated information (driving records, credit scores, medical data, student records, &c) should operate under different, stricter rules than other companies. Much of the impetus for these bills was to overcome objections from legal at BigCos that would never allow any information sharing out of fear that such sharing could get them sued. They are now immunized from those suits, so long as they're in good faith sharing only information about actual cybersecurity threats.
That's pretty much it, at a high level. It's a very short bill, just 30 pages, and most of the interesting stuff is in the definitions at the top of the bill. It's worth skimming.