🌐 WorldLive
Accueil🇺🇸 États-UnisTechnologie

U.S. Chamber, McCrary Institute call for cyber incident reporting reform, with CISA in leading role

A report from the U.S. Chamber of Commerce and McCrary Institute calls for “harmonizing” cybersecurity incident reporting rules by establishing the Cybersecurity and Infrastructure Security Agency as the single intake point for reports that would satisfy multiple notification requirements across the federal government. The 31-page report , “From Fragmentation to Coordination,” was released Aug. 31 by the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University and the U.S. Chamber, under their joint “Common Sense Cybersecurity Regulation Task Force.” The report calls for: Establishing a single federal intake process for cyber incident reporting, led by the Cybersecurity and Infrastructure Security Agency (CISA), to the maximum extent permitted by law. Use CIRCIA’s existing “substantially similar” authority to allow a single report to satisfy multiple comparable federal reporting requirements where legally permissible. Standardize definitions, thresholds, data elements and reporting timelines across federal agencies where appropriate. Affirming the role of the Cyber Incident Reporting Council (CIRC) as the existing interagency mechanism for coordinating and harmonizing federal cyber incident reporting requirements. Having the Office of the National Cyber Director (ONCD) help drive alignment across the federal government and establish measures of success focused on speed, completeness and usability of information. Preserving sector-specific expertise and statutory requirements where they serve distinct national security and privacy purposes. McCrary director Frank Cilluffo said, “Companies didn’t go into businesses thinking they’d have to defend themselves against nation-states and ransomware gangs. Federal requirements that insist that entities report cyber incidents and encourage good cyber hygiene practices are all important, but these well-intentioned requirements from dozens of federal agencies have layered on top of each other and created a system where some organizations are spending more time proving they’ve complied with security requirements than on actually securing their systems.” “When the threat is accelerating every day,” Cilluffo said, “organizations should be able to count on the fact that when they share information with the federal government it’s shared appropriately and efficiently. As CISA finalizes the CIRCIA rule-making process, they have an opportunity to streamline the reporting mechanisms allowing our nation’s cyber defenders to allocate their resources adapting to fast-moving, increasingly AI-driven threats.” Christopher Roberti, the U.S. Chamber’s senior vice president for cyber, space and national security policy, as well as a McCrary Institute senior fellow, said, “When a company is responding to a critical cyber incident, every second counts. This report offers a practical path forward: leveraging relationships with government while reducing unnecessary duplication and complexity.” “By improving coordination across agencies and building on the work of the cyber community,” Roberti said, “we can ensure America’s cyber defenders stay focused on what matters most: defending their attack surfaces and stopping America’s adversaries.” The Government Accountability Office in July published a report identifying duplicative federal cyber regulations broken down by critical infrastructure sector, in response to a request from lawmakers who are exploring opportunities for harmonization. CISA is aiming to finalize in September its long-awaited rulemaking to establish a mandatory incident report regime for critical infrastructure, according to the federal government’s most recent regulatory agenda. “The report also notes that the federal government already has a significant foundation on which to build,” the Chamber and McCrary said in the release. “CISA is finalizing a rule established in the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). It established the Cyber Incident Reporting Council to coordinate, deconflict and harmonize federal incident reporting requirements across 33 federal departments and agencies.” “Using CIRCIA as a common mechanism to let organizations report once but have that information used many times,” they said, “is a natural path forward.” -- Charlie Mitchell (cmitchell@iwpnews.com) Article Type: Daily News Charlie Mitchell tags: info-sharing Weight: -20