Cybersecurity Regulation

Introduction

Cybersecurity regulation in the United States is a complex patchwork of federal statutes, executive orders, agency regulations, and state laws. Unlike the European Union’s comprehensive General Data Protection Regulation, the United States has taken a sectoral approach, imposing cybersecurity requirements on specific industries while leaving others subject to general prohibitions on unfair or deceptive practices. The regulatory framework continues to evolve rapidly in response to the growing threat of cyber attacks.

FISMA and Federal Cybersecurity

The Federal Information Security Modernization Act (FISMA) of 2014 establishes the cybersecurity framework for federal agencies. FISMA requires agencies to develop information security programs, conduct risk assessments, implement security controls, and report security incidents. The statute directs the National Institute of Standards and Technology (NIST) to develop cybersecurity standards and guidelines for federal systems.

The Department of Homeland Security plays a central role in federal cybersecurity through the Cybersecurity and Infrastructure Security Agency (CISA). CISA operates the National Cybersecurity Protection System, facilitates information sharing between the government and private sector, and coordinates incident response. The Cybersecurity Maturity Model Certification (CMMC) program establishes cybersecurity requirements for defense contractors.

The NIST Cybersecurity Framework

The NIST Cybersecurity Framework, first issued in 2014 and updated in 2024, provides a voluntary framework for organizations to manage cybersecurity risk. The framework is organized around five core functions: Identify, Protect, Detect, Respond, and Recover. Each function includes categories and subcategories that describe specific cybersecurity outcomes.

The NIST framework has become the de facto standard for cybersecurity risk management in the United States. While voluntary for most private sector organizations, the framework has been adopted by many regulators and is referenced in contractual requirements. The framework’s adoption of risk-based, outcome-oriented language reflects a shift from prescriptive compliance to adaptive risk management.

State Breach Notification Laws

All fifty states, the District of Columbia, and Puerto Rico have enacted data breach notification laws. While the specifics vary, these laws generally require entities that maintain personal information to notify affected individuals when a security breach compromises their data. Notification typically must occur without unreasonable delay following discovery of the breach.

State breach notification laws vary in their definitions of personal information, breach triggers, notification methods, and exceptions. The California Consumer Privacy Act (CCPA) imposes particularly stringent requirements, including a private right of action for certain breaches. The variety of state laws creates compliance challenges for organizations operating in multiple states, and there have been calls for a uniform federal breach notification standard.

SEC Cybersecurity Rules

The Securities and Exchange Commission has adopted comprehensive cybersecurity disclosure requirements. The SEC’s 2023 rules require publicly traded companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality. The rules also require periodic disclosure of cybersecurity risk management, strategy, and governance.

The SEC rules represent the most significant federal cybersecurity regulation for public companies. The rules impose new obligations on corporate boards and management to oversee cybersecurity risks, require disclosure of the board’s expertise in cybersecurity, and mandate policies for reporting cybersecurity incidents. The rules have been challenged on procedural grounds, with petitioners arguing that the SEC exceeded its statutory authority.

Sectoral Cybersecurity Regulation

Several federal agencies impose cybersecurity requirements on regulated industries. The Health Insurance Portability and Accountability Act (HIPAA) Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards for protected health information. The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to develop information security programs.

The Federal Trade Commission has used its authority under Section 5 of the FTC Act to challenge unfair or deceptive cybersecurity practices. The FTC has brought numerous enforcement actions against companies that made misleading claims about their cybersecurity practices or failed to implement reasonable security measures. The FTC’s Cybersecurity Standards for Financial Institutions provide detailed requirements for entities subject to FTC jurisdiction.

Critical Infrastructure Protection

Executive Order 13636 (2013) and Presidential Policy Directive 21 established a framework for improving cybersecurity of critical infrastructure. The Department of Homeland Security has identified sixteen critical infrastructure sectors, including energy, financial services, healthcare, and transportation. The Transportation Security Administration has issued cybersecurity requirements for pipelines and other transportation infrastructure.

Conclusion

US cybersecurity regulation is a complex, multi-layered system combining federal statutory requirements, sector-specific regulations, state laws, and voluntary frameworks. The NIST Cybersecurity Framework provides a common language for cybersecurity risk management, while state breach notification laws impose disclosure obligations. The SEC’s cybersecurity rules represent a significant expansion of federal cybersecurity requirements for public companies.