Duplicate Cybersecurity Regulations Found in Government Report
A recent report from the Government Accountability Office (GAO) has found that seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicative, with 80 out of 117 rules containing the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.
The GAO examined federal cyber regulations at 37 agencies at the request of House Homeland Security Chairman Andrew Garbarino, R-N.Y., and Senator Gary Peters, D-Mich., the top Democrat on the Senate counterpart to Garbarino's panel. The report found that efforts to de-conflict these duplicative regulations have not been successful so far.
Harmonization Efforts
The desire to harmonize conflicting cybersecurity regulations has been ongoing, with the Biden administration undertaking a more aggressive push to regulate cybersecurity than prior administrations. However, the GAO noted that many past federal efforts have experienced delays and made limited progress.
A 2024 national security memorandum tasked the Office of the National Cyber Director and the Department of Homeland Security to harmonize conflicting regulations, and both agencies made some progress on those goals. However, the executive branch paused some of those efforts after Trump issued an executive order in March of last year, and a study of the 2024 memo was still underway as of last month, according to the GAO.
Impact on Critical Infrastructure
The GAO report found that a single critical infrastructure sector could have duplication with several agencies. For example, the Cybersecurity and Infrastructure Security Agency has been working on a regulation stemming from the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which would require critical infrastructure owners and operators to report when they are the victims of major attacks or make ransomware payments.
Elements of the financial services sector might fall under one of 15 preexisting cybersecurity reporting rules, depending on the agency that has oversight, but they may also be subject to the pending CIRCIA rules, the GAO noted.
Congressional Efforts
Congress has also looked at ways to streamline cybersecurity regulations. The GAO's study was focused only on federal rules, but BreachRx, a cyber incident response firm, published its own report looking at major cyber incidents and how overlapping regulatory reporting obligations came into play, folding in regulations from states and other sources.
The GAO's report highlights the need for harmonization of cybersecurity regulations to reduce duplication and improve the effectiveness of cybersecurity incident reporting. As the cybersecurity landscape continues to evolve, it is essential that regulatory efforts keep pace to ensure the protection of critical infrastructure and the private sector.
- The GAO report found that 80 out of 117 federal cyber regulations contain duplicative reporting requirements.
- The report noted that many past federal efforts to harmonize conflicting regulations have experienced delays and made limited progress.
- The Cybersecurity and Infrastructure Security Agency is working on a regulation stemming from the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA).
The GAO's report provides a comprehensive analysis of the current state of federal cybersecurity regulations and highlights the need for continued efforts to harmonize and streamline these regulations.
Source: CyberScoop