What Happened?
Companies that run power grids, hospitals, and financial systems could find it difficult to meet overlapping federal cybersecurity rules at the same time they are remediating threats. The U.S. Government Accountability Office (GAO) published a report on possible duplication or conflict among federal cybersecurity requirements, based on input from industry panelists.
GAO convened a panel of industry representatives from energy, financial services, and healthcare that it identified as subject to a large number of federal cybersecurity rules. Panelists said that where federal critical infrastructure cybersecurity rules are duplicative or conflicting, it can be difficult to satisfy all reporting requirements while also responding to an active threat.
Why Does it Matter to Me?
For the operators involved, panelists' concern is that conflicting reporting duties could make it harder to respond to cyber threats in sectors that people depend on.
Both Sides, Now
The Office of the National Cyber Director (ONCD) has noted that overlapping rules can bring conflicting guidance, higher compliance costs and redundancies. Panelists proposed two fixes: consistent reporting timeframes and thresholds across agencies, and a single lead agency to coordinate and receive incident reports.
Half of the participants considered progress toward harmonizing the rules over the prior year to be limited, even as some improvements, including increased regulatory guidance for financial institutions, had been made. GAO's High Risk list calls for a national cybersecurity strategy.
What Happens Next?
The Department of Homeland Security and the Securities and Exchange Commission are the agencies most directly named in connection with the duplicative rules, and both would likely figure in any harmonization effort.
Will Congress or the administration move to designate a single lead agency to coordinate and receive incident reports?
---
AllCiv makes it easy to stay politically informed and involved.
---
Spot something wrong? Report an issue with this article