But of course, CISPA does nothing of the sort. It is:
* An opt-in measure that can't be forced on a private company by the government
* Restricted to "cyber threat information", a term carefully (relative to any other online legislation) defined to apply only to attacks on the confidentiality/integrity/availability of systems and applications
* Specifically restricted from applying to Aaron Swartz-style ToS violations, or, for that matter, to intellectual property misappropriation
* Written to exclude "individuals" from "protected entities" to avoid any reading that would permit ISPs to use it to hand over records for individual targeted customers
And, while it exempts private companies from suits for good-faith attack data sharing (that is the point of the measure), it deliberately makes the government liable for any damages from misuse of shared information.
As Declan McCullagh pointed out in another thread here recently, private companies operate under a bewildering stack of regulations that make it legally dicey to share even innocuous data during attacks. In addition to ECPA and SCA, the two omnibus federal electronic privacy laws, there are a number of domain-specific laws ranging from HIPAA for medical privacy to DPPA for drivers records. Companies who handle protected data currently either don't share attack data, or incur legal risks when they do, or incur legal expenses when they have their sharing practices reviewed.
CISPA is a straightforward (and short) bill that attempts to remedy that problem. I don't support it (I don't think it will do much to help), but it's not evil, and organizations that try to fundraise off the idea that it is are playing games with your attention.