article thumbnail

CISA: “We don’t stab the wounded.”

Data Matters

Cybersecurity and Infrastructure Security Agency (“CISA”), repeatedly emphasizes CISA’s cooperative approach with the U.S. During her interview with Sidley’s Alan Raul on April 13, 2022, Easterly emphasized that CISA’s role was not to “name, blame, shame, or stab the wounded” victims of cybersecurity incidents. private sector.

FOIA 97
article thumbnail

U.S. Congress Releases Compromise Bill on Cybersecurity Information Sharing

Hunton Privacy

trillion omnibus spending bill that contained cybersecurity information sharing language that is based on a compromise between the Cybersecurity Information Sharing Act, which passed in the Senate in October, and two cybersecurity information sharing bills that passed in the House earlier this year.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

DHS and DOJ Issue Final Guidance on the Cybersecurity Information Sharing Act of 2015

Hunton Privacy

Department of Justice (“DOJ”) jointly issued final guidance on the Cybersecurity Information Sharing Act of 2015 (“CISA”). Enacted in December 2015, CISA includes a variety of measures designed to strengthen private and public sector cybersecurity. This document was developed by DHS and DOJ pursuant Section 105(b) of CISA.

article thumbnail

Michigan Adopts National Association of Insurance Commissioners’ (NAIC) Insurance Data Security Model Law

Data Matters

By doing so, Michigan joins Ohio and South Carolina as the third state to adopt the Model Law and the fifth state – along with Connecticut and New York – to have enacted cybersecurity regulations focused on insurance companies. FOIA Protections. Exclusive State Cybersecurity Standards. MCL § 500.550. MCL § 500.550.

article thumbnail

New law imposes disclosure requirements on software licensors

Data Protection Report

Moreover, if the person is a US person or affiliate, the person must disclose whether he or she has ever sought or currently holds a license under the Export Administration Regulations (EARs) or International Traffic in Arms Regulations (ITARs), as such disclosures are exempt from FOIA or corresponding state access to information laws.

FOIA 40
article thumbnail

Georgia’s HB 156, requiring state notice for utility cybersecurity incidents, is now in effect

DLA Piper Privacy Matters

Georgia’s governor has signed into law House Bill 156, creating specific notice requirements for state agencies and utilities that experience cybersecurity attacks, data breaches or malware and requiring notice to the state director of emergency management in Georgia within two hours of notifying the federal emergency management agencies.

article thumbnail

Congress Agrees – 72 Hour Cyber Incident Reporting Requirement to Take Effect

Data Protection Report

The Act will require a “covered entity” to report any “substantial cyber incident” to the Cybersecurity and Infrastructure Security Agency (“CISA”) within 72 hours after the covered entity reasonably believes the incident has occurred. Reporting Requirements. CISA will then coordinate further sharing of the report. Work to be Done .