Establishing and Using Cyber Requirements to Protect Critical Infrastructure
The NCS calls for the use of incentives and requirements to align the interests of individuals and
organizations with our collective goals of national security, public safety, and economic
prosperity. The Federal Government’s proactive approach to cybersecurity requirements
recognizes that every sector must be accounted for. Where cybersecurity requirements do not
exist or are poorly defined, we are pursuing new requirements that are agile enough to adapt as
adversaries increase their capabilities and change tactics. Where the regulatory landscape is
already mature, we are working to harmonize and align new and existing regulatory
requirements. We are also paying close attention to regulatory action in other countries where
such efforts can serve as a model, or where these actions may impact U.S. critical infrastructure
owners, operators, or third-party service providers.
In the past year, new or updated cybersecurity rules went into effect across several critical
infrastructure sectors. The Transportation Security Administration (TSA) issued updated
requirements for oil and natural gas pipelines, airport and aircraft operators, and rail carriers.
The Securities and Exchange Commission (SEC) adopted new rules requiring public companies
to disclose information related to material cybersecurity incidents and risk management
practices. In the healthcare and public health (HPH) sector, an amendment to the Federal Food,
Drug, and Cosmetic Act, one of the Food and Drug Administration’s (FDA) authorizing statutes,
now requires manufacturers of certain types of medical devices to design, develop, and maintain
cybersecure medical devices, including through the creation of comprehensive lists of software
components. FDA also finalized updated recommendations for medical device manufacturers to
comply with FDA rules related to medical device cybersecurity. For the Defense Industrial
Base (DIB), the Department of Defense (DoD) released revisions to its Cybersecurity Maturity
Model Certification program to establish new requirements for DIB contractors and subcontractors and expanded access to the voluntary DIB Cybersecurity (CS) Program. And, in the
maritime sector, the President signed EO 14116 on Amending Regulations Relating to the
Safeguarding of Vessels, Harbors, Ports, and Waterfront Facilities of the United States
alongside the U.S. Coast Guard issuing a Maritime Security Directive and Notice of Proposed
Rulemaking (NPRM) to bolster port and maritime cybersecurity.
Across all critical infrastructure sectors, implementation of CIRCIA will establish new
requirements for covered entities to report certain cybersecurity incidents to the Federal
Government. In March 2024, CISA published an NPRM setting out proposed regulations for
cyber incident and ransom payment reporting, as well as other aspects of the CIRCIA regulatory
program. The information contained in these reports will provide increased visibility into
malicious cyber activity, improve our understanding of cross-sector risks, and strengthen our
collective defense.
The Federal Government is prioritizing measures to harmonize baseline regulatory requirements
across sectors. Chaired by the Federal Communications Commission (FCC), the Cybersecurity
Forum for Independent and Executive Branch Regulators enables Federal agencies to coordinate
efforts to improve the effectiveness and consistency of regulatory activity. In September 2023,
the Cyber Incident Reporting Council delivered a report to Congress on streamlining and
harmonizing Federal cyber incident reporting requirements.
2024 REPORT
10
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE