Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements; Correction
Primary source
Metadata and text below are from the Federal Register, a public-domain U.S. government work. Always verify the official published version before relying on it for any legal matter.
Issuing agencies
Abstract
On April 4, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) published, in the Federal Register, the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements notice of proposed rulemaking (NPRM). The NPRM proposes regulations to implement CIRCIA's covered cyber incident and ransom payment reporting requirements for covered entities. In the section describing covered entities, the NPRM included information and references in the applicability criteria for transportation system entities that were based on a proposed rule that has not yet been published by the Transportation Security Administration (TSA). This document clarifies and corrects the proposed applicability criteria for pipeline facilities and systems in the sector-based criteria discussion for transportation systems sector entities.
This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.