Log4j is a java-based tool from Apache’s open source library used for parsing logs that never seems to have made headlines before this past weekend. Now, following the December 9th public announcement of a vulnerability in this tool, public and … [Read more] about CISA Issues Statement on Log4j Critical Vulnerability
The Cybersecurity Incident Reporting Requirements Fail in the Latest Version of the National Defense Authorization Act
On December 7, 2021, the House of Representatives passed the National Defense Authorization Act for Fiscal Year 2022 (NDAA), which notably excluded any cybersecurity incident reporting requirements. In September, the House approved a previous version … [Read more] about The Cybersecurity Incident Reporting Requirements Fail in the Latest Version of the National Defense Authorization Act
China’s Initial Draft Regulations on the Management of Online Data Security: Important Takeaways
On November 14, 2021, the Cyberspace Administration of China (CAC) released draft Regulations on the Management of Online Data Security (the “Regulations”) for China’s data privacy and security laws, including the Cybersecurity Law … [Read more] about China’s Initial Draft Regulations on the Management of Online Data Security: Important Takeaways
Federal Bank Regulatory Agencies Release Final Rule to Require Notification of Cyber Incidents
On November 18, 2021, the Office of the Comptroller of the Currency, the Board of Governors of the Federal Reserve System, and the Federal Deposit Insurance Corporation jointly announced the approval of a final rule to improve the sharing of … [Read more] about Federal Bank Regulatory Agencies Release Final Rule to Require Notification of Cyber Incidents
EDPB issues draft guidelines on the interplay between the GDPR’s provisions on territorial scope and international data transfers
On November 18, the European Data Protection Board (“EDPB”) released draft guidelines on the interplay between Article 3 GDPR – which sets out the GDPR’s territorial scope – and the provisions in Chapter V of the GDPR, which impose restrictions on … [Read more] about EDPB issues draft guidelines on the interplay between the GDPR’s provisions on territorial scope and international data transfers