Evolving US Cybersecurity Laws: Key Takeaways and Updates
Recent amendments to US cybersecurity laws have strengthened regulations to protect sensitive information and prevent cyber threats. The Health Insurance Portability and Accountability Act (HIPAA), the Gramm-Leach-Bliley Act (GLBA), and the Payment Card Industry Data Security Standard (PCI DSS) are just a few of the laws that have been updated to enhance data protection. The New York Department of Financial Services (NYDFS) regulations now require more stringent notification procedures for ransomware deployments. The Executive Order on Improving the Nation's Cybersecurity aims to modernize cybersecurity by implementing protected networks for federal institutions and improving collaboration between the public and private sectors. The Securities and Exchange Commission (SEC) has also weighed in on cybersecurity regulations, passing legislation that governs cybersecurity management, incident reporting, governance, and strategy disclosures. The Department of Defense's spending bill includes $2.9 billion for the Cybersecurity and Infrastructure Security Agency (CISA) to bolster federal cybersecurity protection and improve threat hunting.
Key Takeaways:
- The Health Insurance Portability and Accountability Act (HIPAA) was recently amended on 21 February 2023 to strengthen patient health information protection.
- The Gramm-Leach-Bliley Act (GLBA) was adopted on 16 March 2022 to regulate the collection and handling of financial information, requiring organizations to comply with this law.
- The Payment Card Industry Data Security Standard (PCI DSS) last amended on 27 April 2022 sets rules for safeguarding consumer credit card data, and any MSP that processes payment card data must be compliant with this regulation.
- The New York Department of Financial Services (NYDFS) regulations now require more stringent notification procedures for ransomware deployments, affecting leadership responsibility, vulnerability assessments, and incident response and recovery.
- The Executive Order on Improving the Nation's Cybersecurity, signed in 2021, prioritizes modernizing cybersecurity and improving collaboration between the public and private sectors to better respond to cyber incidents.
- The Securities and Exchange Commission (SEC) has passed legislation that governs cybersecurity management, incident reporting, governance, and strategy disclosures for organizations operating within the industry.
- The Department of Defense's spending bill includes $2.9 billion for the Cybersecurity and Infrastructure Security Agency (CISA) to bolster overall federal cybersecurity protection, protect civilian networks, and improve threat hunting.
Statistics:
- $2.9 billion: The amount of funding pledged by the Department of Defense to the Cybersecurity and Infrastructure Security Agency (CISA) to enhance federal cybersecurity protection.
- $1.7 trillion: The total spending bill allocated by lawmakers in the Department of Defense.
- 5,000: The number of pages in the Department of Defense's spending bill.
- 27 April 2022: The date of the last amendment to the Payment Card Industry Data Security Standard (PCI DSS).
- 16 March 2022: The date of the adoption of the Gramm-Leach-Bliley Act (GLBA).
- 21 February 2023: The date of the amendment to the Health Insurance Portability and Accountability Act (HIPAA).
Sources:
- Amendment to the Health Insurance Portability and Accountability Act (HIPAA) on 21 February 2023.
- The Gramm-Leach-Bliley Act (GLBA) adopted on 16 March 2022.
- The Payment Card Industry Data Security Standard (PCI DSS) last amended on 27 April 2022.
- The New York Department of Financial Services (NYDFS) regulations.
- The Executive Order on Improving the Nation's Cybersecurity signed in 2021.
- The Securities and Exchange Commission (SEC) legislation passed recently.
- The Department of Defense's spending bill.