CIRCIA-2240 | Definitions: Covered Entity, Covered Cyber Incident, Ransom Payment | 1 |
CIRCIA-2241 | Cyber Incident Review and Threat Indicator Sharing | 1 |
CIRCIA-2242a1 | 72-Hour Covered Cyber Incident Report | 2 |
CIRCIA-2242a2 | 24-Hour Ransom Payment Report | 2 |
CIRCIA-2242a3 | Supplemental Reports | 2 |
CIRCIA-2242a4 | Preservation of Data Relevant to the Incident | 1 |
CIRCIA-2242a5 | Reporting Exceptions: Substantially Similar Reporting and DNS | 0 |
CIRCIA-2242c4 | Required Contents of a Covered Cyber Incident Report | 1 |
CIRCIA-2242c5 | Required Contents of a Ransom Payment Report | 1 |
CIRCIA-2242d | Third-Party Report Submission | 0 |
CIRCIA-2242e | Awareness of Reporting Obligations | 1 |
CIRCIA-2243 | Voluntary Reporting of Other Cyber Incidents | 0 |
CIRCIA-2244b | Response to a CISA Request for Information | 1 |
CIRCIA-2244c | Subpoena and Civil Enforcement for Noncompliance | 1 |
CIRCIA-2244d | Referral to the Attorney General | 0 |
CIRCIA-2244f | Exclusion of State, Local, Tribal and Territorial Governments | 0 |
CIRCIA-2245a | Authorized Use, Retention and Digital Security of Reports | 1 |
CIRCIA-2245a5 | Prohibition on Use of Reported Information in Regulatory Actions | 0 |
CIRCIA-2245b | Protections for Reporting Entities (FOIA, Privilege, Proprietary) | 0 |
CIRCIA-2245c | Liability Protections and Evidentiary Restrictions | 0 |
CIRCIA-2246 | Cyber Incident Reporting Council Harmonization | 0 |
CIRCIA-2247 | Federal Sharing of Incident Reports | 0 |