The document outlines the frequency, nature, and prosecution of violations under the Computer Fraud and Abuse Act (CFAA) as well as the Department of Justice's (DOJ) charging decisions and sentencing practices. It highlights that CFAA offenses are infrequently prosecuted, particularly instances involving legitimate computer security research, with average sentences often below recommended guidelines. The DOJ expresses openness to amending the CFAA to avoid penalizing trivial acts while emphasizing the importance of computer security research.