★ ANNUAL REVIEW 2027 SPONSORSHIPS NOW OPEN   Learn more →

Log In  |  Become a Member  |  Sponsor  |  ⌕ Search

News/Cyber & Privacy/The Cybersecurity Incident Reporting Requirements Fail in the Latest Version of the National Defense Authorization Act
Free SampleYou’re reading a free sample of the Cyber & Privacy Brief. Members get every case digest like this, six days a week.See Membership Options
Expert Opinion·Cyber & Privacy Brief

The Cybersecurity Incident Reporting Requirements Fail in the Latest Version of the National Defense Authorization Act

The House of Representatives passed the National Defense Authorization Act for Fiscal Year 2022, which notably excluded any cybersecurity incident reporting requirements. In September, the House approved a previous version of the bill that included a mandatory breach notification provision that would have required CISA to develop and establish standards, procedures and timelines for critical infrastructure owners and operators to report cybersecurity incidents, including a requirement to report such incident as early as 72 hours after confirming such cybersecurity incident. Such a requirement would have been a broad expansion of the government’s involvement in cybersecurity for the private sector.

Source:

Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.