Recently, the Cybersecurity and Information Security Agency (CISA) released a Request for Information (RFI) to inform the agency's development of new critical infrastructure cyber incident reporting rules enacted by Congress earlier this year.
The Cyber Incident Reporting for Critical Infrastructure Act was approved by Congress in March. The law directs CISA to develop rules requiring covered critical infrastructure owners and operators to report to CISA within 72 hours of a reasonable belief that they have experienced a cyberattack, or within 24 hours of making a cyber ransom payment. Although water systems are not explicitly mentioned in the statute, they could be subject to the reporting requirements depending on how CISA decides to define covered entities.
Continue Reading
This archived story is available after you provide your email address and accept our Privacy Policy.








Leave a Reply