HomeMalware & ThreatsCISA Submits Final CIRCIA Rule to White House for Review

CISA Submits Final CIRCIA Rule to White House for Review

Published on

spot_img

Regulation,
Standards, Regulations & Compliance

Final Rule Goes to OMB as Defense Contractors Face Second Reporting Regime

CISA Submits Final CIRCIA Rule to White House for Review

Recent developments indicate the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has progressed towards implementing a long-awaited regulation, critical for enhancing national cybersecurity protocols. This rule mandates that operators of critical infrastructures report cyberattacks to the federal government. The submission of the final rule to the White House for review marks a significant milestone in its rollout, which has been delayed for some time.

The official submission came under the Cyber Incident Reporting for Critical Infrastructure Act and was made to the Office of Management and Budget (OMB) on a Thursday, according to federal regulatory review records. This delay in finalizing the rule comes after CISA missed a target set in its online regulatory agenda for September. This submission was closely timed with remarks from the White House’s senior cyber official, who emphasized that one of the main goals of the final rule is to reduce any overlap with existing reporting requirements.

Legal experts and industry observers are interpreting this movement positively. Eric Crusius, the chair of the government contracts group at the law firm Hunton Andrews Kurth, remarked that the submission of the final rule indicates that it is likely to be presented before the end of the calendar year. Crusius elaborated that the delays experienced in the rule’s progress were to be expected, particularly given the extensive due diligence required due to its impact across various sectors.

The requirement for this rule was first established by Congress in 2022. CISA’s proposed guidelines for 2024 suggest that organizations in 16 critical infrastructure sectors will be required to report “substantial” cyber incidents within 72 hours, while ransom payments must be reported within 24 hours. However, CISA had previously delayed its target date in response to feedback from the business community and lawmakers, indicating that the original scope may have been too broad. The agency noted that this initiative is expected to affect nearly 300,000 organizations across the United States.

Additional factors contributing to the delay included a lapse in funding for the Department of Homeland Security, which postponed necessary stakeholder town hall meetings until June of the same year. Acting Director Nick Andersen highlighted that the agency is committed to minimizing the unnecessary burden of implementing this rule while considering stakeholder feedback in the process. In a prior discussion on the rule’s development, CISA emphasized the importance of efficiently engaging stakeholders.

A report from the Government Accountability Office published earlier in the year found that approximately 70% of the federal cybersecurity regulations contained similar reporting requirements and that efforts to harmonize these regulations had yielded limited success. This indicates a systemic issue within the framework of federal regulations, where redundancy might hinder effective cybersecurity practices.

Current regulatory expectations require defense contractors to report cyber incidents to the Pentagon within a 72-hour window. Industry consensus seems to lean towards CISA accepting these existing reports, as highlighted by Jacob Horne, the chief cybersecurity evangelist at Summit 7, a compliance firm serving over 1,400 defense contractors. Horne expressed skepticism about the additional burden this new reporting requirement would impose, questioning whether CISA has adequately justified the necessity of creating a secondary reporting system for defense contractors.

Moreover, CISA’s proposed 2024 guidelines suggest that organizations could fulfill CIRCIA requirements through similar reports submitted to another federal agency, provided that there is a formal agreement between CISA and that agency. However, industry experts, including Horne, have indicated that there is currently no indication that such agreements will be reached, particularly with the Pentagon. Horne articulated that a single-report resolution is unlikely because current Department of Defense requirements are narrowly focused on incidents involving controlled unclassified information.

The Congressional Research Service has echoed these concerns, raising doubts about whether other regulatory bodies would abandon their specific requirements, as these rules have distinct objectives. Horne has suggested that for regulatory harmonization to work, CISA would need to accept less data than what CIRCIA currently seeks to collect, which is a substantial challenge given the differing compliance landscapes across agencies.

CIRCIA sets forth additional requirements, including follow-up reports as new incident details emerge and mandates for data retention of two years, compared to the current 90-day requirement under the Department of Defense rules. Many contractors remain unprepared to meet these heightened expectations as they have not yet achieved compliance with existing defense cybersecurity protocols. The Pentagon’s suspension of the second phase of its Cybersecurity Maturity Model Certification program, which was implemented in July to alleviate pressure on smaller suppliers, further complicates this landscape.

In addressing these regulatory changes, National Cyber Director Sean Cairncross highlighted during a recent cybersecurity summit that the White House is committed to fostering a strong partnership with DHS and CISA in creating a framework that brings clarity and direction to the industry. This collaboration is seen as vital in strengthening the cybersecurity measures across critical infrastructure sectors, ensuring that all stakeholders are equipped to navigate the evolving landscape of cyber threats.

Source link

Latest articles

America First, AI Safety Second?

Washington’s New Frontier in AI: A Voluntary Accord with Uncertain Outcomes In an unprecedented move...

Safari History Database Tags Reveal Users’ Browsing Themes in Forensic Investigations

Safari's History Database: A Crucial Tool for Digital Forensics The Safari web browser, widely utilized...

Cybersecurity Awareness Month: AI Agents as Users Demanding Governance

Cybersecurity Awareness Month Broadens Focus to Include AI Agents For over twenty years, Cybersecurity Awareness...

More like this

America First, AI Safety Second?

Washington’s New Frontier in AI: A Voluntary Accord with Uncertain Outcomes In an unprecedented move...

Safari History Database Tags Reveal Users’ Browsing Themes in Forensic Investigations

Safari's History Database: A Crucial Tool for Digital Forensics The Safari web browser, widely utilized...

Cybersecurity Awareness Month: AI Agents as Users Demanding Governance

Cybersecurity Awareness Month Broadens Focus to Include AI Agents For over twenty years, Cybersecurity Awareness...