Because CISPA promises (a) to allow Facebook to receive threat intelligence from the federal government, which collects massive amounts of it in ways that it is currently forbidden by statute to share, and (b) to allow Facebook to coordinate with Google and AT&T to track down attacks without worrying that someone's bogus interpretation of ECPA will land it in court for 5 years.
There are (faulty) readings of ECPA that would suggest that (say) Facebook providing NetFlow data to AT&T to help squelch a DDoS attack would constitute an unlawful sharing of private data.
Worth noting here that CISPA is entirely opt-in.