Cybersecurity Regulations: Industry Panelists Identify Duplication and Conflicts and Ways to Address Them
What GAO Found GAO convened a panel discussion to gather industry perspectives on potential duplication or conflict among federal cybersecurity regulations affecting selected critical infrastructure sectors. The industry participants identified multiple federal cybersecurity regulations within their sectors as duplicative or conflicting with other regulations (see figure below). In such cases, participants said it could be difficult to fully satisfy all reporting requirements while remediating cyber threats. Number of Duplicative or Conflicting Federal Cybersecurity Regulations Identified by Selected Industry Sector Representatives For example, participants in all three sectors noted that the Department of Homeland Security’s proposed rule for cyber incident reporting or the Securities and Exchange Commission’s cybersecurity disclosure rules were duplicative and in conflict with their own sector’s regulations. Participants also identified duplication or conflict in sector-specific cybersecurity reporting requirements. While participants in all three sectors noted that progress in harmonizing federal cybersecurity regulations has been made over the past year—such as federal agenc...
Read the original at the source: https://www.gao.gov/products/gao-26-109197
Officially imported this from Government Accountability Office’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Government Accountability Office — imported from official source
- Official source
- https://www.gao.gov/rss/reports.xml RSS
- Imported
- October 03, 2026 20:42
- Versions
- 1 recorded
- Identity
-
/products/gao-26-109197