News

CISA seeks public input on new cybersecurity incident, ransomware reporting plans

As required by the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), the Cybersecurity and Infrastructure Security Agency (CISA) recently released a Notice of Proposed Rulemaking on new cybersecurity measures meant to bolster its real-time capabilities.

“Cyber incident reports submitted to us through CIRCIA will enable us to better protect our nation’s critical infrastructure,” Secretary of Homeland Security Alejandro Mayorkas said. “CIRCIA enhances our ability to spot trends, render assistance to victims of cyber incidents, and quickly share information with other potential victims, driving cyber risk reduction across all critical infrastructure sectors. The proposed rule is the result of collaboration with public and private stakeholders, and DHS welcomes feedback during the public comment period on the direction and substance of the final rule.”

CISA is a component of the Department of Homeland Security (DHS).

The proposed rule was published in the Federal Register. However, CISA has gathered input from public and private sector stakeholders on the rule since September 2022. Its umbrella includes proposed regulations for cyber incident and ransomware payment reporting, as CISA works to develop insights into cyber threats, reduce risks and offer early warning capabilities to potential targets.

“CIRCIA is a game changer for the whole cybersecurity community, including everyone invested in protecting our nation’s critical infrastructure,” CISA Director Jen Easterly said. “It will allow us to better understand the threats we face, spot adversary campaigns earlier, and take more coordinated action with our public and private sector partners in response to cyber threats. We look forward to additional feedback from the critical infrastructure community as we move towards developing the Final Rule.”

An important function of the proposed rule is that it would allow CISA to identify patterns in something closer to real-time, allowing it to more rapidly allocate resources and patch information holes in the face of potential and ongoing cyber attacks. Speed is of the essence in such cases, the agency noted, as it can keep other organizations from suffering similar attacks and allow the agency to better assist the compromised.

Once published, the public has 60 days to comment on the proposed rule.

Chris Galford

Recent Posts

Protect and Serve Act would elevate the harming or attempted harm of law enforcement to a federal crime

Following the deaths of four police officers while executing an arrest warrant in North Carolina…

22 hours ago

U.S. Reps. Steil, Dean introduce legislation to target human trafficking among other countries

As a way to crackdown on human trafficking, two U.S. representatives recently introduced the Exposing…

22 hours ago

DoD challenge brings opportunities for nine new ideas in talent management

A Department of Defense (DoD) 2040 Task Force (D2T) challenge on talent management innovation drew…

4 days ago

TSA publishes final rule on Flight Training Security Program improvements

For the first time since its creation in 2004, the Transportation Security Administration’s (TSA) Flight…

4 days ago

FEMA launches new hurricane season campaign with multicultural messaging on flood risks

The 2024 Hurricane Season Campaign began for the Federal Emergency Management Agency (FEMA) this week,…

5 days ago

SERVICE Act of 2024 seeks DOJ pilot program, grants for local veteran response teams

As a way to support veterans, U.S. Reps. Maria Elvira Salazar (R-FL), Dale Strong (R-AL),…

5 days ago

This website uses cookies.