USA Law and Practice Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields
cal infrastructure sectors, as identified by the DHS. These sectors include industries vital to public safety, economic stability and national security, such as the chemical, critical manufacturing, defence industrial base (DIB), energy, financial services, healthcare and IT industries. Sector-Specific Regulations • Energy – the Federal Energy Regulatory Commis - sion (FERC) enforces the North American Electric Reliability Corporation (NERC) Critical Infrastruc - ture Protection (CIP) Standards, requiring electric utilities to secure cyber-assets, manage supply chain risks and report incidents under Section 215 of the Federal Power Act (FPA). • Transportation – the Transportation Security Administration (TSA) mandates cybersecurity for pipeline, rail and aviation operators through direc - tives requiring incident reporting, risk mitigation and security plans. • Water and wastewater systems – the Environmen - tal Protection Agency (EPA) enforces cybersecurity requirements under America’s Water Infrastructure Act (AWIA), requiring utilities serving more than 3,300 people to assess risks and enhance cyberse - curity protections. • Nuclear – the National Nuclear Security Administra - tion (NNSA) and Nuclear Regulatory Commission (NRC) enforce cybersecurity for nuclear facilities and contractors handling classified data, with strict protections under Title 10, Code of Federal Regula - tions (CFR) Part 73 and the Department of Energy Cybersecurity Program Plan (CSP). • DIB – the Cybersecurity Maturity Model Certifica - tion (CMMC) and DFARS 252.204-7012 require defence contractors handling Controlled Unclassi - fied Information to meet National Institute of Stand - ards and Technology (NIST) SP 800-171 standards for cybersecurity and separate departmental requirements obligate certain entities to report identified categories of cyber-incidents. • Healthcare – HIPAA mandates cybersecurity protections for electronic protected health infor - mation (“ePHI”) under the HIPAA Security Rule, with breach reporting obligations under the HIPAA Breach Notification Rule (see 6.3 Cybersecurity in the Healthcare Sector for more on HIPAA).
• Other entities handling personal health records – entities not regulated by HIPAA that handle per - sonal health records (PHRs) are required to notify affected individuals under the FTC’s Health Breach Notification Rule (HBNR). 2.2 Critical Infrastructure Cybersecurity Requirements In the USA, critical infrastructure cybersecurity is governed by sector-specific regulations designed to address the unique risks faced by each industry. These requirements aim to enhance resilience against cyberthreats by mandating proactive risk manage - ment, incident reporting, and adherence to best prac - tices. There are a number of sector-specific cybersecurity requirements, as follows. • Energy sector – the FERC’s CIP Standards require cybersecurity plans, access controls and periodic risk assessments. • Water and wastewater systems sector – the EPA mandates water utilities to incorporate cybersecu - rity into risk assessments and develop emergency response plans under the AWIA. • Nuclear sector – NRC licensees must implement extensive cybersecurity safeguards, including access controls, network monitoring, supply chain risk management and incident response protocols to prevent cyberthreats from compromising reactor operations or sensitive nuclear materials. • Transportation sectors – TSA’s cybersecurity directives require critical infrastructure owners to implement vulnerability assessments, mitigation measures and cybersecurity plans. Other particular requirements apply to the rail and aviation sectors. • Healthcare sector – see 6.3 Cybersecurity in the Healthcare Sector . • Financial services sector – see 3. Financial Sector Operational Resilience Regulation (in particular, 3.1 Scope of Financial Sector Operational Resil- ience Regulation ). • DIB – the CMMC framework establishes tiered cybersecurity requirements for defence contrac - tors handling controlled unclassified information (CUI), with higher levels requiring measures such
465 CHAMBERS.COM
Powered by FlippingBook