GAO Report Highlights Duplicative Federal Cybersecurity Regulations Impacting Agencies
A recent report by the Government Accountability Office (GAO) has revealed that 70% of federal cybersecurity regulations requiring written reports are duplicated across various agencies. The study, requested by key lawmakers, examined 117 rules at 37 agencies and found that 80 of these rules had overlapping reporting requirements. This issue has persisted despite efforts to harmonize these regulations, which began under the Biden administration and continued into the second Trump administration. The GAO's findings indicate that sectors such as financial services may be subject to multiple cybersecurity reporting rules, including those from the Cybersecurity and Infrastructure Security Agency (CISA) and the pending Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). Efforts to streamline these regulations have faced delays, particularly after an executive order from President Trump paused some harmonization initiatives.