July 12, 2024 NASS Public Comment in Response to the Cybersecurity and Infrastructure Security Agency’s Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) Notice of Proposed Rulemaking (NPRM) The following public comment is submitted on behalf of the Executive Board of the National Association of Secretaries of State (NASS): NASS and its members appreciate the Cybersecurity. [...] • Through the Multi-State Information Sharing and Analysis Center (MS-ISAC) and the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC), of which all states are members, NASS members have efficient means of reporting cyber threat information and potential cyber incidents to CISA. [...] NASS Public Comment Regarding CIRCIA NPRM o We suggest SLTT government entities should be able to report cyber incidents to the MS/EI-ISAC and opt-in to having the report shared with CISA. [...] • As currently proposed, the required elements of a cyber incident report are overly broad and would strain the resources of SLTT government entities during a critical time for cyber incident response. [...] As currently proposed, we can imagine scenarios in which entities will need to spend a significant amount of time determining whether a cyber incident qualifies as “substantial.” o The Cyber Incident Reporting for Critical Infrastructure Act of 2022 and proposed rule require reporting within 72 hours after the covered entity reasonably believes that the covered cyber incident has occurred.
Authors
- Pages
- 3
- Published in
- United States of America