<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Office of the National Cyber Director - Harmonization Request for Information in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Office-of-the-National-Cyber-Director-Harmonization-Request-for/m-p/63743#M6417</link>
    <description>Dear Federal Govt…&lt;BR /&gt;&lt;BR /&gt;Please pass sensible well thought out laws that preempt patchwork state laws, regulations etc on cybersecurity, data protection, AI Governance etc. It’s too important to leave to chance where there isn’t legislation covering it and the US should harmonies its own laws and regulations in the way that the EU has for things like GDPR and DORA.&lt;BR /&gt;&lt;BR /&gt;It’ll be tough to get there, there will be much gnashing of teeth and wailing but it will be worth it. You might as well work things out with Canada and Mexico at the same time so NAFTA gets the benifit.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;A Friend…</description>
    <pubDate>Thu, 19 Oct 2023 15:59:20 GMT</pubDate>
    <dc:creator>Early_Adopter</dc:creator>
    <dc:date>2023-10-19T15:59:20Z</dc:date>
    <item>
      <title>Office of the National Cyber Director - Harmonization Request for Information</title>
      <link>https://community.isc2.org/t5/Industry-News/Office-of-the-National-Cyber-Director-Harmonization-Request-for/m-p/63740#M6416</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;ONCD Harmonization RFI&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Harmonization has been an increasingly important topic of conversation when it comes to cybersecurity legislation and regulations. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;As regulation increases so does the opportunity for regulatory overlap and requirements that are inconsistent. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;This has affected some industries more than others. Have you been affected? Would you be willing to share for our ISC2 RFI? Please use these questions as prompts and reply to this thread. If you prefer, you can directly email your responses (or discuss challenges overlapping and conflicting regulations further) at&amp;nbsp;&lt;A href="mailto:crains@isc2.org" target="_blank"&gt;crains@isc2.org&lt;/A&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;Have you noticed an increase in inconsistent and conflicting cybersecurity regulations and standards in your industry as a cybersecurity professional?&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;How do regulated entities comply with these conflicting mutually exclusive, or inconsistent requirements? &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;What are some of the potential consequences cybersecurity teams face as a result of having to comply with a multitude of regulations that may be inconsistent or overlapping?&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;Your responses could be included in our ONCD RFI.&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;Please respond by Oct. 27 in order to to have your responses included.&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;More information:&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;I&gt; &lt;/I&gt;&lt;A href="https://www.whitehouse.gov/wp-content/uploads/2023/07/ONCD-Reg-Harm-RFI-Final-July-19.2023.pdf" target="_blank"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;https://www.whitehouse.gov/wp-content/uploads/2023/07/ONCD-Reg-Harm-RFI-Final-July-19.2023.pdf&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 15:02:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Office-of-the-National-Cyber-Director-Harmonization-Request-for/m-p/63740#M6416</guid>
      <dc:creator>AndreaMoore</dc:creator>
      <dc:date>2023-10-19T15:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Office of the National Cyber Director - Harmonization Request for Information</title>
      <link>https://community.isc2.org/t5/Industry-News/Office-of-the-National-Cyber-Director-Harmonization-Request-for/m-p/63743#M6417</link>
      <description>Dear Federal Govt…&lt;BR /&gt;&lt;BR /&gt;Please pass sensible well thought out laws that preempt patchwork state laws, regulations etc on cybersecurity, data protection, AI Governance etc. It’s too important to leave to chance where there isn’t legislation covering it and the US should harmonies its own laws and regulations in the way that the EU has for things like GDPR and DORA.&lt;BR /&gt;&lt;BR /&gt;It’ll be tough to get there, there will be much gnashing of teeth and wailing but it will be worth it. You might as well work things out with Canada and Mexico at the same time so NAFTA gets the benifit.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;A Friend…</description>
      <pubDate>Thu, 19 Oct 2023 15:59:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Office-of-the-National-Cyber-Director-Harmonization-Request-for/m-p/63743#M6417</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2023-10-19T15:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Office of the National Cyber Director - Harmonization Request for Information</title>
      <link>https://community.isc2.org/t5/Industry-News/Office-of-the-National-Cyber-Director-Harmonization-Request-for/m-p/63760#M6418</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1086253963"&gt;@AndreaMoore&lt;/a&gt;&amp;nbsp;wrote:&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Have you noticed an increase in inconsistent and conflicting cybersecurity regulations and standards in your industry as a cybersecurity professional?&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;What Congress and the courts need to do is sort out authority. Every state has its own set regulations under its authority to regulate business and corporations. However, the federal government always gets pulled in under the umbrella of interstate commerce. If it is a public corporation, you now have the SEC to think about. And when I say "state," it's really all 50 that you have to look at since you can have employees or customers in each of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To me the problem isn't that we haven't kept with this "new" technology. Lawmakers have allowed the bells and whistles to distract them from recognizing and applying core legal concepts. If Congress is aghast at Social Media, all it needs to do is eliminate the clause in the Communications Decency Act that exempts online providers from libel and other liability associated with what gets posted on their platforms. These platforms reach more people than any daily newspaper. Yet that newspaper is considered a publisher (subject to libel, invasion of privacy, etc.) and that platform, whose billions in advertising revenue is putting that newspaper out of business, acts with impunity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could take the same approach for personal information - essentially it is an issue of copyright. Again companies make billions trading, selling info that is not directly related to the conduct of their primary business. They're making money off my information. If they're going to be allowed to do that, I should be compensated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the end, the real problem, especially at the state level is that government exempts itself from regulation. Given that government is one of the biggest custodians of data such exemption misses the mark&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 12:20:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Office-of-the-National-Cyber-Director-Harmonization-Request-for/m-p/63760#M6418</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2023-10-20T12:20:56Z</dc:date>
    </item>
  </channel>
</rss>

