January 16, 2025
Daily News
Tech sector finds upcoming CISA incident reporting rule raises questions on addressing product security
The technology sector raises several questions in its submission to the Cybersecurity and Infrastructure Security Agency on what constitutes a need for incident reporting under the upcoming mandatory regime, including how to address product security and potential reporting on vulnerabilities.
CISA’s sector-specific definition of a covered entity for information technology “seems to state that IT Sector companies must report substantial cyber incidents experienced through ‘the products’ of the covered entity. This is confusing, as a substantial cyber incident is defined...