"
The House Homeland Security cyber subcommittee will hold a May 1 hearing on CISA’s notice of proposed rulemaking to establish a mandatory incident reporting regime, featuring private sector stakeholders. 'Just two years after CIRCIA was signed into law, the cyber threat landscape has become even more dynamic with ever-increasing risk to our critical infrastructure from cyber adversaries, such as China and Russia, and opportunistic cybercriminals. Addressing these complex threats to the homeland demands effective implementation of CIRCIA,' subcommittee Chairman Andrew Garbarino (R-NY) said in a statement to Inside Cybersecurity. Garbarino said, 'It is more important than ever to ensure there is a streamlined process for critical infrastructure entities to identify cross-sector vulnerabilities and mitigate risk.' CISA was directed under the 2022 Cyber Incident Reporting for Critical Infrastructure Act to establish a mandatory regime where critical infrastructure owners and operators would be required to report cyber incidents to the agency within 72 hours and 24 hours for ransom payments. The law gave CISA 24 months to issue the NPRM and an additional 18 months for the final rule. The agency published the 447-page NPRM on April 4. The expansive rulemaking provides definitions for key terms, how to determine applicability, a proposal for establishing agreements between CISA and other agencies who have reporting requirements, and what should be provided in reports to CISA.The NPRM also contains data records and preservation requirements and details on enforcement and protections. CISA interprets key terminology from the law in the NPRM to suit the agency’s reporting needs. The agency’s approach to defining what should be considered a “covered entity” has drawn concerns from stakeholders. Garbarino said, 'Successfully combating the cascading effects of cyber intrusions requires complete alignment with Congress' intent in CIRCIA, which will empower CISA to foster public-private partnerships and enhance interagency information sharing.'
54"
Read The Full Article Here.
|