{"id":3511,"date":"2024-05-09T19:08:48","date_gmt":"2024-05-10T00:08:48","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules"},"modified":"2024-05-09T19:08:48","modified_gmt":"2024-05-10T00:08:48","slug":"cisa-courts-private-sector-to-get-behind-circia-reporting-rules","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/09\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules\/","title":{"rendered":"CISA Courts Private Sector to Get Behind CIRCIA Reporting Rules"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt96cc86e0a6b6a306\/663d653dd760b34902da4175\/CISA_logo_GK_Images_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">RSA CONFERENCE 2024 \u2013 San Francisco \u2013<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> The Cybersecurity and Infrastructure Security Administration (CISA) has tagged an additional 30 days onto the window for the private sector to provide feedback on proposed Cyber Incident Reporting for Critical Infrastructure (CIRCIA) incident reporting rules. The agency has to maintain an open and collegial relationship with the private sector because it simply doesn&#8217;t have the resources necessary to do the job in-house.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But the reality of imposing another set of disclosure deadlines, on top of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/sec-adopts-new-rule-on-cybersecurity-incident-disclosure-requirements\" rel=\"noopener\">Security and Exchange Commission regulations<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/sec-charges-against-solarwinds-ciso-send-shockwaves-through-security-ranks\" rel=\"noopener\">enforcement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">) and state and local requirements, brings concerns about potentially piling more red tape onto victims of a cybercrime, and ultimately slowing down incident response.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/dhs-releases-unpublished-circia-document-proposing-new-rule\" rel=\"noopener\">CIRCIA was signed into law in 2022<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, requiring reporting an attack within 72 hours and any ransom payments within 24 hours, and has now moved to the end stages of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/topics\/cyber-threats-and-advisories\/information-sharing\/cyber-incident-reporting-critical-infrastructure-act-2022-circia\" rel=\"noopener\">rulemaking at CISA<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Lawmakers placed the responsibility of collecting the information on CISA because of the agency&#8217;s existing ability to act as a &#8220;convening authority&#8221; for the cybersecurity sector at large, according to Moira Bergin, who served as a subcommittee director under the House Committee on Homeland Security and helped to establish the legislation. However, after saddling CISA with the responsibility of collecting CIRCIA reporting, Congress denied any additional funding to help them resource up for the job.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We need to hold Congress accountable; CISA has not gotten the resources they&#8217;ve requested,&#8221; Bergin said during a panel discussion at RSAC 2024.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Now CISA is stuck \u2014 and asking for help from the same group it&#8217;s required to regulate.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Streamlined Reporting, Coordinated Cyber Defense\">Streamlined Reporting, Coordinated Cyber Defense<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISA executive director Brandon Wales tried to downplay enforcement and instead implored the cyber community to view sharing their incident data with the federal government as a gesture of goodwill to shore up the entire country&#8217;s cyber defenses. Bergin, however, reminded the audience that failure to comply with the regulation could result in organizations being banned from doing any business with the federal government.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Individual enterprise victims won&#8217;t likely see a direct benefit from sharing their intelligence with CISA, Wales explained, but will see improvements in the long run as the agency is able to do a better job at defending because it is aided by data from across the US infrastructure ecosystem.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Wales added that CISA is trying to become the singular repository for incident reporting, meaning organizations that have overlapping oversight from federal and state agencies could see a simpler process following the implementation of CIRCIA reporting rules.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Large cyber organizations like CrowdStrike have been working with CISA through the Joint Cyber Defense Collaborative (JCDC), while also acting as a vendor to the agency. Drew Bagley, CrowdStrike&#8217;s VP of council privacy and cyber privacy, said the company is prepared to continue its dual role of contributing to what he calls the &#8220;whole-of-community response&#8221; through the JCDC, CIRCIA reporting, and more, in tandem with the company&#8217;s work as a threat intelligence vendor for CISA.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As the clock counts down to the final implementation of CIRCIA reporting requirements, Bagley recommends the private sector continue to push for clear definitions of what is covered under the rules.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The private sector should pay attention to how a covered entity is defined and what a covered incident is,&#8221; Bagley added.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISA will accept recommendations on CIRCIA rules via the Federal Register through July 3.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>RSA CONFERENCE 2024 \u2013 San Francisco \u2013 The Cybersecurity and<\/p>\n","protected":false},"author":12,"featured_media":3512,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3511","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisa-courts-private-sector-to-get-behind-circia-reporting-rules.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3511","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3511"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3511\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3512"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3511"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3511"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3511"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}