-
Notifications
You must be signed in to change notification settings - Fork 38
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
White House RFI : Office of the National Cyber Director Requests Public Comment on Harmonizing Cybersecurity Regulations #9
Comments
Count with me: |
Below is a rough outline of a FINOS response to the White House RFI that will form the basis of the upcoming kick off meeting on Thursday 28th September. Introduction (1-2 paragraphs)
Common Cloud Controls
Conclusion
|
The kick off call for the White House RFI has been scheduled for Thursday 28th Sept at 2pm BST / 9am EST. Join Zoom Meeting Meeting ID: 982 5461 7376 |
I think the response above is fine within the narrow context of our agenda with CCC. |
Sep 28, 2023 Meeting Notes
|
The FINOS response to the |
Description
FINOS requests that
Common Cloud Controls
leads the response to the White House RFI highlighted in this issue and in the attached PDF. Please feedback the project's appetite in the comments so the response can be planned.Office of the National Cyber Director Requests Public Comment on Harmonizing Cybersecurity Regulations
The White House Office of the National Cyber Director (ONCD) is announcing a request for information (RFI) on cybersecurity regulatory harmonization and regulatory reciprocity. The RFI builds on the commitment the Administration made in the National Cybersecurity Strategy to “harmonize not only regulations and rules, but also assessments and audits of regulated entities.” The RFI advances one of the 69 initiatives that were released last week as part of the National Cybersecurity Strategy Implementation Plan.
When cybersecurity regulations of the same underlying technology are inconsistent or contradictory – or where they are duplicative but enforced differently by different regulators – consumers pay more, and our national security suffers. Duplicative regulation leads to companies focusing more on compliance than on security, which results in their passing higher costs on to customers, working families, and state, local, Tribal, and territorial governments. Harmonizing baseline regulatory requirements can therefore produce better security outcomes at lower costs.
ONCD is seeking input from stakeholders to understand existing challenges with regulatory overlap and inconsistency in order to explore a framework for reciprocal recognition by regulators of compliance with common baseline cybersecurity requirements. Unlike many other fields, at a technical level, the cybersecurity of one sector is inherently similar to the cybersecurity of other sectors. While regulated sectors may engage in distinct activities, they often use the same software, hardware, and information and communications technology and services to enable interconnectivity or automation. The technological commonalities also mean that baseline risk mitigation measures are likely to be common among entities and sectors.
ONCD-Reg-Harm-RFI-Final-July-19.2023.pdf
GitHub Issues for Questions 3, 4 and 7 Response
Shared Google Doc for White House RFI Response
Please find the shared Google Doc for White House RFI response below ...
-https://docs.google.com/document/d/1qIgjIVQtQgNd-DdhzVia_VKhWa_gsV5maPDQG-KzyXI/edit?usp=sharing
The text was updated successfully, but these errors were encountered: