乐鱼(Leyu)体育官网

Industries

Helping clients meet their business challenges begins with an in-depth understanding of the industries in which they work. That鈥檚 why 乐鱼(Leyu)体育官网 LLP established its industry-driven structure. In fact, 乐鱼(Leyu)体育官网 LLP was the first of the Big Four firms to organize itself along the same industry lines as clients.

How We Work

We bring together passionate problem-solvers, innovative technologies, and full-service capabilities to create opportunity with every insight.

Learn more

Careers & Culture

What is culture? Culture is how we do things around here. It is the combination of a predominant mindset, actions (both big and small) that we all commit to every day, and the underlying processes, programs and systems supporting how work gets done.

Learn more

Cybersecurity Strategy: ONCD, GAO

Cross-sector harmony and reciprocity in cyber regulation

Columns

乐鱼(Leyu)体育官网 Regulatory Insights

  • Top Priority: Concurrent issuances/actions from ONCD and GAO reiterate cyber as a top regulatory priority.
  • Harmonizing Cyber Regulations: Recommendations and RFI related to potential for creating a 鈥榰nified cybersecurity framework鈥�, streamlining regulations, and establishing reciprocal recognition across critical infrastructure sectors while recognizing associated challenges.
  • Baseline Cyber Standards: Desire for 鈥渂aseline cybersecurity standards鈥� across critical infrastructure sectors, that aim to reduce compliance costs.

听冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲

June 2024

In furtherance of the National Cybersecurity Strategy announced by the White House in March 2023, the Office of the National Cyber Director (ONCD) and the General Accountability Office (GAO) each take steps to consider the challenges associated with establishing new and updated cybersecurity regulations and frameworks that are 鈥渢ailored for each sector鈥檚 risk profile,鈥� harmonized and streamlined to reduce duplication, and 鈥渃alibrated to meet the needs of national security and public safety.鈥� These actions include a:

  1. Summary Report of the ONCD Request for Information (RFI)
  2. GAO Report, entitled 鈥淐ybersecurity: Efforts Initiated to Harmonize Regulations but Significant Work Remains鈥�

Both the ONCD Summary Report and the GAO Report are covered in testimony before the United States Senate Committee on Homeland Security and Governmental Affairs at a recent on 鈥淪treamlining the Federal Cybersecurity Regulatory Process: The Path to Harmonization.鈥�

1. ONCD RFI Summary

The ONCD, a component of the Executive Office of the President established to advise the President on cybersecurity policy and strategy, releases a Summary Report on comments received in response to its August 2023 RFI on cyber regulatory harmonization. (See related White House release, here.)

The ONCD, in coordination with the Office of Management and Budget, is tasked with leading the Administration鈥檚 efforts on cybersecurity regulatory harmonization pursuant to the National Cybersecurity Strategy (see 乐鱼(Leyu)体育官网鈥檚 Regulatory Alert, here). Responses to the RFI are intended to help the ONCD 鈥渦nderstand existing challenges with regulatory overlap, and explore a framework for reciprocity鈥n regulator acceptance of other regulators' recognition of compliance with baseline requirements.鈥� The ONCD states that it is 鈥減articularly interested in regulatory harmonization as it may apply to critical infrastructure sectors and sub-sectors鈥nd providers of communications, IT, and cybersecurity services to owners and operators of critical infrastructure.鈥�

For these purposes:

  • 鈥淗armonization鈥� refers to a common set of updated baseline regulatory requirements that would apply across sectors.
  • 鈥淩eciprocity鈥� means mutual recognition of compliance findings across regulations and/or jurisdictions.
  • Baseline requirements would apply to all sectors and regulators; regulators could impose requirements beyond the baseline requirements to capture unique sector-specific risks.

Eleven of the sixteen critical infrastructure sectors were among the respondents to the RFI. As identified in the Summary Report, key findings include:

  • The lack of harmonization and reciprocity harms cybersecurity outcomes while increasing compliance costs through additional administrative burdens.
  • Challenges with cybersecurity regulatory harmonization and reciprocity extend to businesses of all sectors and sizes and cross jurisdictional boundaries.
  • The U.S. Government is positioned to act to address these challenges. Respondent recommendations include legislation to set national, high-level standards for cybersecurity, and ways to include independent regulators in future planning for regulatory harmonization.

Questions in the 2023 RFI focused on the following topics:

  • Conflicting, mutually exclusive, or inconsistent regulations.
  • Use of common guidelines (e.g., Federal Financial Institutions Examination Council (FFIEC)).
  • Use of existing standards or frameworks.
  • Third-party frameworks (e.g., NIST Cybersecurity Framework).
  • Tiered regulation (e.g., risk-based regulatory requirements for sectors).
  • Oversight by multiple regulators of the same entity.
  • Cloud and other service providers.
  • State, local, tribal, and territorial regulation.
  • International regulation.

2. GAO Report

The , 鈥淐ybersecurity: Efforts Initiated to Harmonize Regulations but Significant Work Remains,鈥� outlines the Administration鈥檚 recent work to harmonize cybersecurity regulations, including the ONCD RFI. The efforts (other than the ONCD RFI) include release of the:

  • National Cybersecurity Implementation Plan Version 2 (May 2024) containing initiatives to be completed by March 2025 or earlier, including:
    • Setting minimum cybersecurity requirements across critical infrastructure sectors.
    • Increasing agency use of frameworks and international standards to inform regulatory alignment. (Note: The National Institute of Standards and Technology (NIST) (February 2024) responds to this initiative.)
    • Exploring cybersecurity regulatory reciprocity pilot programs (Note: The National Cyber Director stated ONCD is working on a pilot program for regulatory reciprocity frameworks to be used in a critical infrastructure sub-sector and to provide insights into effective regulatory designs).
  • National Security Memorandum on Critical Infrastructure Security and Resilience (鈥淣ational Security Memorandum -22鈥�, April 2024), which calls for:
    • Federal department and agencies to use regulation to establish minimum requirements and accountability mechanisms for the security and resilience of critical infrastructure.
    • The Secretary of Homeland Security to prepare a report to the President by April 2025 and every two years thereafter on the National Infrastructure Risk Management Plan, which includes a plan for harmonizing minimum security and resilience requirements across all sectors.
  • Cybersecurity and Infrastructure Security Agency (CISA) on cyber incident and ransom payment reporting requirements for covered entities; CISA seeks comment on how to harmonize these requirements with other federal reporting regimes. (Comments due to CISA by July 3, 2024.)

The GAO Report also notes that challenges to harmonization across sectors include 鈥渄ifferences in the:

  • Definitions of reportable cyber incidents and thresholds for reporting.
  • Timelines and triggers for reporting.
  • Contents of incident reports.
  • Reporting mechanisms.
  • Procedural and resource burdens.
  • Legal barriers and limits on agency authorities.鈥�

Dive into our thinking:

Cybersecurity Strategy: ONCD, GAO

Cross-sector harmony and reciprocity in cyber regulation

Download PDF

Explore more

Get the latest from 乐鱼(Leyu)体育官网 Regulatory Insights

乐鱼(Leyu)体育官网 Regulatory Insights is the thought leader hub for timely insight on risk and regulatory developments.

Meet our team

Image of Amy S. Matsuo
Amy S. Matsuo
Principal, U.S. Regulatory Insights & Compliance Transformation Lead, 乐鱼(Leyu)体育官网 LLP, 乐鱼(Leyu)体育官网 LLP
Image of Matthew P. Miller
Matthew P. Miller
Principal, Advisory, Cyber Security Services, 乐鱼(Leyu)体育官网 US

Thank you

Thank you for signing up to receive Regulatory Insights thought leadership content. You will receive our next issue when we publish.

Get the latest from 乐鱼(Leyu)体育官网 Regulatory Insights

乐鱼(Leyu)体育官网 Regulatory Insights is the thought leader hub for timely insight on risk and regulatory developments. Get the latest perspectives on evolving supervisory, regulatory, and enforcement trends.聽

To receive ongoing 乐鱼(Leyu)体育官网 Regulatory Insights, please submit your information below:
(*required field)

By submitting, you agree that 乐鱼(Leyu)体育官网 LLP may process any personal information you provide pursuant to 乐鱼(Leyu)体育官网 LLP's .

An error occurred. Please contact customer support.

Thank you!

Thank you for contacting 乐鱼(Leyu)体育官网.聽We will respond to you as soon as possible.

Contact 乐鱼(Leyu)体育官网

Use this form to submit general inquiries to 乐鱼(Leyu)体育官网. We will respond to you as soon as possible.

By submitting, you agree that 乐鱼(Leyu)体育官网 LLP may process any personal information you provide pursuant to 乐鱼(Leyu)体育官网 LLP's .

An error occurred. Please contact customer support.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services 乐鱼(Leyu)体育官网 can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the 乐鱼(Leyu)体育官网 International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline