Cybersecurity Regulations: Industry Panelists Identify Duplication and Conflicts and Ways to Address Them
28/09/2026 às 11:2010 بازدید

Tribunal de Contas dos EUA — Relatorios
What GAO Found
GAO convened a panel discussion to gather industry perspectives on potential duplication or conflict among federal cybersecurity regulations affecting selected critical infrastructure sectors. The industry participants identified multiple federal cybersecurity regulations within their sectors as duplicative or conflicting with other regulations (see figure below). In such cases, participants said it could be difficult to fully satisfy all reporting requirements while remediating cyber threats.
Number of Duplicative or Conflicting Federal Cybersecurity Regulations Identified by Selected Industry Sector Representatives
For example, participants in all three sectors noted that the Department of Homeland Security’s proposed rule for cyber incident reporting or the Securities and Exchange Commission’s cybersecurity disclosure rules were duplicative and in conflict with their own sector’s regulations. Participants also identified duplication or conflict in sector-specific cybersecurity reporting requirements.
While participants in all three sectors noted that progress in harmonizing federal cybersecurity regulations has been made over the past year—such as federal agencies providing increased regulatory guidance for financial institutions—half the participants agreed that this progress was limited.
Participants also identified several opportunities for harmonizing federal cybersecurity regulations, including those related to cybersecurity incident reporting. Participants stated that defining reporting timeframes and thresholds in consistent ways could streamline requirements and reduce duplication. Participants also stated that having a lead agency to coordinate and receive incident reports would increase collaboration between government agencies and industry.
Why GAO Did This Study
Nearly all the nation’s critical infrastructure is supported by computer-based information systems. Because this infrastructure is mostly owned by the private sector, having the public and private sectors work together to protect the information systems is vital. Cognizant federal agencies have issued numerous regulations to help protect health data and ensure smooth operation of financial systems, among other things. However, according to the Office of the National Cyber Director, when critical infrastructure sectors are subject to multiple cybersecurity regulations, it can lead to conflicting guidance, inconsistencies, increased compliance costs, and redundancies for regulated entities.
GAO was asked to gather perspectives of industry participants on the progress that federal agencies are making to harmonize cybersecurity regulations. This report summarizes industry views from selected sectors on duplication or conflicts among federal cybersecurity regulations that affect critical infrastructure sectors.
GAO convened a panel discussion on July 16, 2026. The panel included six representatives from different industry organizations within three critical infrastructure sectors that GAO’s prior work has identified as subject to a significant number of cybersecurity regulations: energy, financial services, and healthcare and public health. The representatives included chief and senior executives overseeing cybersecurity, medical, and industry operations, as well as regulatory affairs and legal specialists.
For more information, contact David B. Hinchman at HinchmanD@gao.gov.
این خبر مفید بود؟
بحثها 0
نخستین مشارکتکننده در بحث باشید.