A Government Accountability Office report found that seven out of 10 federal cyber regulations requiring written reports to agencies are duplicated elsewhere, creating overlapping obligations for the private sector. Efforts by the Office of the National Cyber Director and the Department of Homeland Security to harmonize these rules have made limited progress, even as CIRCIA and other reporting requirements continue to add complexity. #GAO #CIRCIA #OfficeoftheNationalCyberDirector #DepartmentofHomelandSecurity
Keypoints
- GAO found 80 of 117 federal cyber rules contain duplicated reporting requirements.
- The study examined regulations across 37 federal agencies.
- Some critical infrastructure sectors face overlapping requirements from multiple agencies.
- CIRCIA would add new incident reporting duties for major attacks and ransomware payments.
- Harmonization efforts have seen delays and limited progress.
Read More: https://cyberscoop.com/gao-report-duplicate-cybersecurity-regulations-harmonization/