The Cybersecurity and Infrastructure Security Agency will host seven town hall meetings to gather feedback from critical infrastructure sectors as it works to finalize the Cyber Incident Reporting for Critical Infrastructure Act, Cybersecurity Dive reports.The agency said the sessions will allow sector representatives to comment on key parts of the regulation required under the 2022 CIRCIA. It is seeking "specific, actionable improvements" that would make the requirements clearer or ease the burden on companies, while still ensuring officials receive useful information about cyber threats.CISA is seeking input on what details should be included in incident reports, whether company size should determine who must comply, and how it could use subpoenas to obtain information from firms that do not respond. It is also seeking views on whether cloud companies, managed service providers, or other operators should have to report incidents linked to open-source software they use. The proposal was released in April 2024 and would require organizations covered by the rule to notify the government within 72 hours of major cyber incidents.
Government Regulations
CISA to lead industry town halls on cyber incident reporting rule

(Adobe Stock)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds


