Duplicate reporting doesn’t improve cybersecurity 🤔 The government accountability office identified a whopping 117 existing cybersecurity regulations administered by 37 federal agencies across nine critical infrastructure sectors. Of those, it found that 80 regulations (about 70%) have affirmative reporting requirements, collectively imposing at least 125 separate reporting obligations on private sector entities. These obligations include cyber incident reporting, submission of cybersecurity plans and technical information, and reporting related to audits, reviews, and assessments.
The report found that many regulations require regulated entities to provide similar information to different federal agencies, such that companies may need to prepare multiple reports concerning the same cybersecurity event or compliance activity. GAO highlighted potential overlap across all three reporting categories, including 48 regulations requiring cyber incident reporting, 52 requiring cybersecurity plans or technical information, and 25 requiring audits, reviews, or assessments. (And this does not even touch on state obligations, which are proliferating. GAO highlighted the financial services sector, where entities are already subject to cybersecurity incident reporting obligations administered by the Securities and Exchange Commission, Federal Reserve, the Office of the Comptroller of the Currency, Federal Deposit Insurance Corporation, National Credit Union Administration, Department of the Treasury, Federal Trade Commission, and Commodity Futures Trading Commission. Once CIRCIA is finalized, many of those same organizations could also be required to report incidents to CISA. The report further notes that differences in definitions, reporting thresholds, triggers, timelines, and required content could require entities to prepare multiple reports about the same incident for different federal recipients. These concerns are not unique to the financial services sector. Several sectors, including communications and transportation, also have myriad overlapping obligations.
https://www.jdsupra.com/legalnews/gao-confirms-cyber-reporting-burdens-as-9175072/ #Infosec #Legal