GAO: OMB’s 1 Hour PII breach reporting requirement is “infeasible” and provides “little value”

Editor’s Note: The following is an excerpt from the Conclusion to GAO’s report, INFORMATION SECURITY: Agency Responses to Breaches of Personally Identifiable Information Need to Be More Consistent. The complete report is available here.

From: GAO

While US-CERT plays an important role in responding to cyber incidents, including coordinating governmentwide responses and providing technical assistance to agencies, the utility of its role in responding to PII incidents is more limited, particularly when system or network issues are not involved. Given this limited role, the requirement to report all PII-related incidents within 1 hour provides little value. Likewise, immediate reporting of individual incidents involving the loss of hardware containing encrypted PII or paper-based PII to US-CERT adds little value beyond what could be achieved by periodic consolidated reporting. As a result, agencies may be making efforts to meet the reporting requirements that could be diverting attention and limited resources from other breach response activities.

 

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *