MGMA, WEDI urge CISA to align its reporting timelines and requirements with other federal partners, including the HHS Office for Civil Rights, to decrease the administrative burden. Stakeholders in healthcare are proposing changes to the Cybersecurity and Infrastructure Security Agency’s proposed rule on cyber incident reporting requirements under the Cyber Incident Reporting for Critical InfrastructureContinue reading “Stakeholders Suggest Changes to CISA’s Cybersecurity Reporting Rule.”
Category Archives: CISA
How MFA Is Falling Short.
In baseball, it’s tempting to think that once you’re on a base, the hard part is over. But then, just when you think you’re safe (you are literally “safe”) the baseman hits you with the hidden ball trick. Your opponent appears to throw the ball away, but merely hides it and tags you in the moment you’re mostContinue reading “How MFA Is Falling Short.”
New DHS guidance for faith-based communities advises online protection for physical security
DHS Secretary Alejandro N. Mayorkas says the country is in a “heightened threat environment” and that the agency was acting accordingly to protect houses of worship. Many faith-based institutions across the country are preparing for a busy holiday season, and the Department of Homeland Security has issued guidance intended to help with security—and no, leavingContinue reading “New DHS guidance for faith-based communities advises online protection for physical security”
CIA urges ‘secure by design’ elimination of factory-default passwords.
The agency recommended physical access requirements for initial setup and time-limited credentials. CISA says default passwords like “1111” need at least a few more special characters. In an advisory issued December 15, the agency offered “secure by design” recommendations for tech manufacturers, especially those making programmable logic controllers (PLCs)—devices that cyber attackers have targeted to compromise wasteContinue reading “CIA urges ‘secure by design’ elimination of factory-default passwords.”
FBI Issues Guidance for Delaying SEC-Required Data Breach Disclosure.
The FBI has issued guidance for SEC data breach reporting requirements and how disclosures can be delayed. The FBI has issued guidance regarding the data breach reporting requirements of the Securities and Exchange Commission (SEC), providing useful information on how disclosures can be delayed. The SEC announced in late July that it had adopted new cybersecurityContinue reading “FBI Issues Guidance for Delaying SEC-Required Data Breach Disclosure.”

You must be logged in to post a comment.