❌

Reading view

There are new articles available, click to refresh the page.

CISA to host industry feedback sessions on cyber incident reporting regulation

The Cybersecurity and Infrastructure Security Agency will hold sector-by-sector town halls in the coming weeks to get feedback on a stalled regulation requiring critical infrastructure owners and operators to report when they suffer major cyberattacks.

The meeting dates, set to be published in the Federal Register Friday, would β€œallow external stakeholders a limited additional opportunity to provide input on refining the scope and burden” of a proposed rule that CISA is advancing as part of the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) that Congress enacted in 2022.

That law requires critical infrastructure owners and operators to notify CISA within 72 hours when they are hit with a significant cyberattack and within 24 hours when they make a ransomware payment.

But defining what entitiesΒ  the law would specifically cover and how has been a point of contention. The Trump administration moved a deadline to complete the rule last year, saying it would delay finalizing the rule until May.

Among the specific topics CISA wants comment on during the virtual town halls are proposed sector-based criteria for whom the regulations apply to; how to handle small businesses; how to consider chemical plants in light of a chemical plant security law lapsing; the list of example incidents that would meet the law’s reporting requirements; and how to reduce conflicts with existing regulations.

After the sector-by-sector meetings, CISA would hold general sessions on March 31 and April 2.

One industry source, granted anonymity to speak candidly, said they weren’t aware the additional sessions were coming until Thursday’s Federal Register notice and it β€œwould have been nice” to know it was coming.

They also told CyberScoop they weren’t sure the town halls were what CIRCIA needed right now.

β€œIndustry has already been very vocal about what we think needs to be addressed in the final rule,” the source said. β€œWe want some back and forth, give and take to better understand what CISA may view as its limitations in implementing the rule.

β€œAnd to me, a town hall where you’re asking for more input isn’t what we need at this point. We want a dialogue,” they said.

Speaking to reporters at a conference last week about the timeline on CIRCIA releasing a final rule, CISA official Nick Andersen said that β€œI think that we’ll have some news on CIRCIA in pretty short order in the next couple of weeks, hopefully.” Andersen, executive assistant director for cybersecurity at the agency, said he couldn’t say more at the time on whether CISA would continue the existing rulemaking process or undertake a new one.

The post CISA to host industry feedback sessions on cyber incident reporting regulation appeared first on CyberScoop.

Small and Medium Business Security Strategies: Part 5

Jordan Drysdale// tl;dr Inventory management and personnel management are critical to making this work. Often, the difference between your company becoming a statistic and catching someone with a foothold in […]

The post Small and Medium Business Security Strategies: Part 5 appeared first on Black Hills Information Security, Inc..

Small and Medium Business Security Strategies: Part 4

Jordan Drysdale// tl;dr Vulnerability management is a part of doing business and operating on the public internet these days. Include training as part of this Critical Control. Users should be […]

The post Small and Medium Business Security Strategies: Part 4 appeared first on Black Hills Information Security, Inc..

Small and Medium Business Security Strategies: Part 3

Jordan Drysdale // Blurb: A few of us have discussed the stress that small and medium business proprietors and operators feel these days. We want to help stress you out […]

The post Small and Medium Business Security Strategies: Part 3 appeared first on Black Hills Information Security, Inc..

Small and Medium Business Security Strategies: Part 2

Jordan Drysdale // A few of us have discussed the stress that small and medium business proprietors and operators feel these days. We want to help stress you out even […]

The post Small and Medium Business Security Strategies: Part 2 appeared first on Black Hills Information Security, Inc..

Small and Medium Business Security Strategies: Part 1

Jordan Drysdale// Blurb: A few of us have discussed the stress that small and medium business proprietors and operators feel these days. We want to help stress you out even […]

The post Small and Medium Business Security Strategies: Part 1 appeared first on Black Hills Information Security, Inc..

❌