Jacob Horne’s Post

View profile for Jacob Horne, graphic

CMMC Town Crier | Ask me about NIST cybersecurity controls | Smashing compliance frameworks for fun and profit | Cyber policy wonk |

The CIRCIA proposed rule will impact defense contractors and subs with additional cyber incident reporting requirements beyond DFARS 7012. Did anybody else notice that the DIB makes up by far the most number of entities affected and represents the largest amount of costs incurred? 𝟮𝟯% 𝗼𝗳 𝗮𝗹𝗹 𝗮𝗳𝗳𝗲𝗰𝘁𝗲𝗱 𝗲𝗻𝘁𝗶𝘁𝗶𝗲𝘀 𝟭𝟲% 𝗼𝗳 𝘁𝗼𝘁𝗮𝗹 𝗽𝗿𝗼𝗴𝗿𝗮𝗺 𝗰𝗼𝘀𝘁𝘀 On top of that, 𝟵𝟴% 𝗼𝗳 𝗮𝗹𝗹 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 𝗲𝗻𝘁𝗶𝘁𝗶𝗲𝘀 𝗮𝗿𝗲 𝘀𝗺𝗮𝗹𝗹 𝗯𝘂𝘀𝗶𝗻𝗲𝘀𝘀𝗲𝘀 At what point is the CIRCIA rule really just a Department of Defense small business cyber rule? According to the rule CISA is gonna try super duper hard to cooperate with the DoD in order to establish a "CIRCIA Agreement" to reduce duplicative reporting requirements. I don't know if you're holding your breath but I'm not. Luckily the rule has this tidbit: 𝗔𝘀𝘀𝗶𝘀𝘁𝗮𝗻𝗰𝗲 𝗳𝗼𝗿 𝗦𝗺𝗮𝗹𝗹 𝗘𝗻𝘁𝗶𝘁𝗶𝗲𝘀 "CISA wants to assist small entities in understanding this proposed rule so that they can better evaluate its effects on them and participate in the rulemaking. If this proposed rule would affect your small business, organization, or governmental jurisdiction and you have questions concerning its provisions or options for compliance," please contact: Todd Klessman, CIRCIA Rulemaking Team Lead, CISA circia@cisa[.]dhs[.]gov 202-964-6869 What's the over/under on the number of voicemails left by DoD so far?

Jacob Horne

CMMC Town Crier | Ask me about NIST cybersecurity controls | Smashing compliance frameworks for fun and profit | Cyber policy wonk |

3mo
Jacob Horne

CMMC Town Crier | Ask me about NIST cybersecurity controls | Smashing compliance frameworks for fun and profit | Cyber policy wonk |

3mo
Jacob Horne

CMMC Town Crier | Ask me about NIST cybersecurity controls | Smashing compliance frameworks for fun and profit | Cyber policy wonk |

3mo

Would you rather report to two different agencies or just have reporting requirements expand dramatically for one? https://www.linkedin.com/posts/jacob-evan-horne_defense-contractors-been-required-to-report-activity-7189712683871428608-NvhP

Jacob Horne

CMMC Town Crier | Ask me about NIST cybersecurity controls | Smashing compliance frameworks for fun and profit | Cyber policy wonk |

3mo
Like
Reply
Terry Kalka

Director, DC3/DCISE

3mo

I cannot overstate the importance of industry input during the public comment period.

James Gillooley, CC, CSM

Information Technology Management Specialists and overall GRC nerd to the DoD CIO. My views are my own and not of my employer.

3mo

I would love to see an agreement put in place to reduce duplicative DoD reporting burdens. At the DIB CS Summit Terry Kalka and DoD Cyber Crime Center (DC3) said it was something they are actively pursuing.

Linda Rust

Strategic advisor | Translating cybersecurity to business | Engaging Fortune 100 C-suite and Board, private equity (PE), and company owners | vCISO | Step Zero™ rapid cybersecurity estimates for M&A and compliance gaps

3mo

Really good points across the board, Jacob Horne.

John Allison

Building compliant systems and processes | Serving the public good | Enabling innovation

3mo

Jacob Horne What does this do for COTS used by DIB companies to do their mission critical stuff? So, if I build software, are all my COTS tools used in by CI/CD now having to report, even if they don't touch production? Oh, this is going to get ugly.

Christopher Holloway

Architect at Microsoft Federal | Chief Cloud Complianceologist | Earth Bound Misfit | Fun Organizer @ Aithics

3mo

Yes CISA please use Nessus on our environment…yes I’m being sarcastic…lol waiting on the DIB NCDOC so I can just ship logs for reporting instead of shipping them via CONMON plans

See more comments

To view or add a comment, sign in

Explore topics