Cybersecurity Regulations: Industry Panelists Identify Duplication and Conflicts and Ways to Address Them
Imported from official source
What GAO Found GAO convened a panel discussion to gather industry perspectives on potential duplication or conflict among federal cybersecurity regulations affecting selected critical infrastructure sectors. The industry participants identified multiple federal cybersecurity regulations within their sectors as duplicative or conflicting with other regulations (see figure below). In such cases, participants said it could be difficult to fully satisfy all reporting requirements while remediating cyber threats. Number of Duplicative or Conflicting Federal Cybersecurity Regulations Identified by Selected Industry Sector Representatives For example, participants in all three sectors noted that the Department of Homeland Security’s proposed rule for cyber incident reporting or the Securities and Exchange Commission’s cybersecurity disclosure rules were duplicative and in conflict with their own sector’s regulations. Participants also identified duplication or conflict in sector-specific cybersecurity reporting requirements. While participants in all three sectors noted that progress in harmonizing federal cybersecurity regulations has been made over the past year—such as federal agenc...
This version
- Version
- 1 of 1
- Recorded
- October 03, 2026 20:42
- Change
- Initial
- Content hash
1a2092fcf9696b820fd7fd941469fef6- All versions
- Revision history