Cybersecurity Regulation: It’s Not ‘Performance-Based’ If Outcomes Can’t Be Measured

After Colonial Pipeline suffered a ransomware attack in May 2021 and took its 5,500-mile system offline for nearly a week, the Transportation Security Administration (TSA) issued a set of first-ever directives imposing mandatory cybersecurity requirements on pipeline operators. Industry balked, criticizing the rules for being too prescriptive. On Ju

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

This article has been indexed from Lawfare

Read the original article: