New cyber incident reporting rules released

Recently, the Cybersecurity and Information Security Agency (CISA) released a Request for Information (RFI) to inform the agency's development of new critical infrastructure cyber incident reporting rules enacted by Congress earlier this year.

The Cyber Incident Reporting for Critical Infrastructure Act was approved by Congress in March. The law directs CISA to develop rules requiring covered critical infrastructure owners and operators to report to CISA within 72 hours of a reasonable belief that they have experienced a cyberattack, or within 24 hours of making a cyber ransom payment. Although water systems are not explicitly mentioned in the statute, they could be subject to the reporting requirements depending on how CISA decides to define covered entities.

Continue Reading

This archived story is available after you provide your email address and accept our Privacy Policy.

This field is for validation purposes and should be left unchanged.
Benjamin Media uses the information you provide to us to contact you about our relevant content, products, and services. Benjamin Media will share the information you provide to us with sponsor(s) of requested content. You can unsubscribe from communications from Benjamin Media at any time. For more information, check out Benjamin Media's Privacy Policy.*

Benjamin Media uses the information you provide to us to contact you about our relevant content, products, and services. Benjamin Media will share the information you provide to us with sponsor(s) of requested content. You can unsubscribe from communications from Benjamin Media at any time. For more information, check out Benjamin Media's Privacy Policy.

Leave a Reply

Your email address will not be published. Required fields are marked *