In an influential 2014 article, CRE explained that OIRA needed to coordinate federal cybersecurity regulation across the Executive Branch because, with no agency in charge of cybersecurity, a regulatory “free for all” was going on “with agencies staking out turf and claims of authority.” Federal regulation of private sector cybersecurity was continues to proceed rapidly but
on an ad hoc basis, often using litigation, the crudest and most inefficient of regulatory mechanisms.
The result is uncertainty, more uncertainty and a salivating plaintiff’s bar.
The upshot is that cybersecurity regulation “needs to be developed with transparent coordination and clear division of responsibilities across agencies. Moreover, the regulatory coordinating process should also involve state regulators and our major trading partners. In short, there is a need for the White House’s Office of Information and Regulatory Affairs (OIRA) to coordinate federal cybersecurity regulations.”
Earlier this year, a Harvard Law Review article Presidential Intelligence, cited CRE in stating, “in an age of mounting threats in cyberspace, regulators from the “ordinary” administrative state— not to mention private actors —can and must learn from, and interact with, intelligence and national security agencies.”
The Financial Services Sector Coordinating Council is to be applauded for bringing their powerful voice to the call for coordination and harmonization of cybersecurity efforts across the government. As the FSSCC explained to NIST,
In the two and one half years since the creation of the NIST Cybersecurity Framework, financial services agencies and self-regulatory organizations at the federal and state level have issued or proposed over thirty different frameworks, questionnaires, rules, and requirements related to cybersecurity. Although some of these cyber initiatives have incorporated the NIST Cybersecurity Framework’s structure and terminology, others have not done so, opting for differing framework approaches and language. With these disparate approaches in structure and language, the ability of firms to contextualize key issues and appropriately evaluate the effectiveness of internal and external cybersecurity efforts have been negatively impacted. The lack of harmonization and alignment are causing firms to expend substantial resources reconciling unique, and often competing, examination questionnaires, frameworks, and tools. Indeed, as an example, one multinational financial services firm reported that approximately 40% of its cybersecurity efforts are expended on reconciliation and compliance, not on actual cybersecurity activity. More specifically, the resources spent to parse, identify, draft and compile equivalent data from similar systems multiple times for different regulators distracts limited personnel from actual security.This overlap has directed limited resources to creating single-use, compliance data sets, rather than expanding active security and mitigation.
Leave a Reply