House Homeland Security Committee Hearing on Cyber Regulation Harmonization
Forbes Breaking NewsApril 7, 20251h 34min870 views
39 connections·40 entities in this video→Improving Federal Cyber Regulation
- 🎯 The hearing's purpose was to evaluate the effectiveness of the federal cyber regulatory regime and identify opportunities to harmonize cyber regulations across government agencies.
- 💡 The focus is on challenges faced by private sector owners and operators of critical infrastructure when navigating complex cyber regulatory landscapes.
Challenges with Current Cyber Regulations
- ⚠️ Over 50 federal regulations create a cumbersome and duplicative cyber regulatory regime, leading to significant compliance costs and time investment for organizations.
- ⚙️ More regulation is not the answer; instead, there's a need to streamline requirements to promote useful, actionable, and reasonable information sharing.
- ⏳ Organizations should be able to focus on securing networks during vulnerable moments, rather than spending hours on duplicative compliance tasks.
Cyber Incident Reporting for Critical Infrastructure Act (CERSIA)
- 📜 CERSIA, passed in 2022, aims to streamline cyber incident reporting by directing CISA to develop regulations for a standardized reporting system across 16 critical infrastructure sectors.
- 📈 Concerns were raised that the proposed CERSIA rule scope exceeded congressional intent, potentially burdening entities and overwhelming CISA with data.
- 🤝 Meaningful incorporation of industry feedback is crucial for a final rule that is not duplicative and ensures government is resourced to protect sensitive information.
Harmonization and Collaboration
- 🌐 Regulatory harmonization is a bipartisan priority, requiring collaboration between the public and private sectors to avoid being hindered by paperwork.
- 🔗 The SEC's rules on cybersecurity risk management, governance, and incident disclosure were cited as an example of rulemaking done without buy-in from stakeholders.
- 🤝 Reauthorization of the Cyber Security Information Sharing Act of 2015 is essential for continued collaboration and information sharing between government and the private sector.
Witness Perspectives and Recommendations
- 💡 Witnesses emphasized the need for CISA to meaningfully engage with industry, potentially through an ex parte process, to refine the CERSIA rule.
- 📉 The SEC's cyber disclosure rule was criticized for potentially undermining CERSIA, complicating incident response, and creating national security risks by disclosing vulnerabilities.
- 🏛️ There's a call for a unified approach, possibly led by the Office of the National Cyber Director or the Office of Management and Budget, to rationalize and harmonize cyber security regulations across agencies.
Knowledge graph40 entities · 39 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover · drag to explore
40 entities
Chapters20 moments
Key Moments
Transcript352 segments
Full Transcript
Topics14 themes
What’s Discussed
Cyber RegulationHomeland SecurityCyber Incident ReportingCERSIACISARegulatory HarmonizationCritical InfrastructureCyber Security Information Sharing ActSEC Cybersecurity RulePublic-Private PartnershipCybersecurity CoalitionEdison Electric InstituteBank Policy InstituteUS Telecom Association
Smart Objects40 · 39 links
Companies· 19
Product· 1
Person· 1
Medias· 6
Concepts· 11
Event· 1
Location· 1