乐鱼(Leyu)体育官网 Regulatory Insights
- Top Priority: Concurrent issuances/actions from ONCD and GAO reiterate cyber as a top regulatory priority.
- Harmonizing Cyber Regulations: Recommendations and RFI related to potential for creating a 鈥榰nified cybersecurity framework鈥�, streamlining regulations, and establishing reciprocal recognition across critical infrastructure sectors while recognizing associated challenges.
- Baseline Cyber Standards: Desire for 鈥渂aseline cybersecurity standards鈥� across critical infrastructure sectors, that aim to reduce compliance costs.
听冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲冲
June 2024
In furtherance of the National Cybersecurity Strategy announced by the White House in March 2023, the Office of the National Cyber Director (ONCD) and the General Accountability Office (GAO) each take steps to consider the challenges associated with establishing new and updated cybersecurity regulations and frameworks that are 鈥渢ailored for each sector鈥檚 risk profile,鈥� harmonized and streamlined to reduce duplication, and 鈥渃alibrated to meet the needs of national security and public safety.鈥� These actions include a:
- Summary Report of the ONCD Request for Information (RFI)
- GAO Report, entitled 鈥淐ybersecurity: Efforts Initiated to Harmonize Regulations but Significant Work Remains鈥�
Both the ONCD Summary Report and the GAO Report are covered in testimony before the United States Senate Committee on Homeland Security and Governmental Affairs at a recent on 鈥淪treamlining the Federal Cybersecurity Regulatory Process: The Path to Harmonization.鈥�
1. ONCD RFI Summary
The ONCD, a component of the Executive Office of the President established to advise the President on cybersecurity policy and strategy, releases a Summary Report on comments received in response to its August 2023 RFI on cyber regulatory harmonization. (See related White House release, here.)
The ONCD, in coordination with the Office of Management and Budget, is tasked with leading the Administration鈥檚 efforts on cybersecurity regulatory harmonization pursuant to the National Cybersecurity Strategy (see 乐鱼(Leyu)体育官网鈥檚 Regulatory Alert, here). Responses to the RFI are intended to help the ONCD 鈥渦nderstand existing challenges with regulatory overlap, and explore a framework for reciprocity鈥n regulator acceptance of other regulators' recognition of compliance with baseline requirements.鈥� The ONCD states that it is 鈥減articularly interested in regulatory harmonization as it may apply to critical infrastructure sectors and sub-sectors鈥nd providers of communications, IT, and cybersecurity services to owners and operators of critical infrastructure.鈥�
For these purposes:
- 鈥淗armonization鈥� refers to a common set of updated baseline regulatory requirements that would apply across sectors.
- 鈥淩eciprocity鈥� means mutual recognition of compliance findings across regulations and/or jurisdictions.
- Baseline requirements would apply to all sectors and regulators; regulators could impose requirements beyond the baseline requirements to capture unique sector-specific risks.
Eleven of the sixteen critical infrastructure sectors were among the respondents to the RFI. As identified in the Summary Report, key findings include:
- The lack of harmonization and reciprocity harms cybersecurity outcomes while increasing compliance costs through additional administrative burdens.
- Challenges with cybersecurity regulatory harmonization and reciprocity extend to businesses of all sectors and sizes and cross jurisdictional boundaries.
- The U.S. Government is positioned to act to address these challenges. Respondent recommendations include legislation to set national, high-level standards for cybersecurity, and ways to include independent regulators in future planning for regulatory harmonization.
Questions in the 2023 RFI focused on the following topics:
- Conflicting, mutually exclusive, or inconsistent regulations.
- Use of common guidelines (e.g., Federal Financial Institutions Examination Council (FFIEC)).
- Use of existing standards or frameworks.
- Third-party frameworks (e.g., NIST Cybersecurity Framework).
- Tiered regulation (e.g., risk-based regulatory requirements for sectors).
- Oversight by multiple regulators of the same entity.
- Cloud and other service providers.
- State, local, tribal, and territorial regulation.
- International regulation.
2. GAO Report
The , 鈥淐ybersecurity: Efforts Initiated to Harmonize Regulations but Significant Work Remains,鈥� outlines the Administration鈥檚 recent work to harmonize cybersecurity regulations, including the ONCD RFI. The efforts (other than the ONCD RFI) include release of the:
- National Cybersecurity Implementation Plan Version 2 (May 2024) containing initiatives to be completed by March 2025 or earlier, including:
- Setting minimum cybersecurity requirements across critical infrastructure sectors.
- Increasing agency use of frameworks and international standards to inform regulatory alignment. (Note: The National Institute of Standards and Technology (NIST) (February 2024) responds to this initiative.)
- Exploring cybersecurity regulatory reciprocity pilot programs (Note: The National Cyber Director stated ONCD is working on a pilot program for regulatory reciprocity frameworks to be used in a critical infrastructure sub-sector and to provide insights into effective regulatory designs).
- National Security Memorandum on Critical Infrastructure Security and Resilience (鈥淣ational Security Memorandum -22鈥�, April 2024), which calls for:
- Federal department and agencies to use regulation to establish minimum requirements and accountability mechanisms for the security and resilience of critical infrastructure.
- The Secretary of Homeland Security to prepare a report to the President by April 2025 and every two years thereafter on the National Infrastructure Risk Management Plan, which includes a plan for harmonizing minimum security and resilience requirements across all sectors.
- Cybersecurity and Infrastructure Security Agency (CISA) on cyber incident and ransom payment reporting requirements for covered entities; CISA seeks comment on how to harmonize these requirements with other federal reporting regimes. (Comments due to CISA by July 3, 2024.)
The GAO Report also notes that challenges to harmonization across sectors include 鈥渄ifferences in the:
- Definitions of reportable cyber incidents and thresholds for reporting.
- Timelines and triggers for reporting.
- Contents of incident reports.
- Reporting mechanisms.
- Procedural and resource burdens.
- Legal barriers and limits on agency authorities.鈥�