Cybersecurity Rules for Cloud Giants Face Repeal Amid Agency Turf War
The Federal Communications Commission (FCC) is poised to reverse its own cybersecurity rules for major cloud providers, less than a year after they were first adopted. This surprising move comes after a jurisdictional dispute with another federal agency, signalling a major shift in policy.
The original regulations were a direct response to the "Salt Typhoon" hack, a campaign by a Chinese state-sponsored group that targeted U.S. critical infrastructure. The rules required cloud service providers like AWS, Google, and Microsoft to report any data breaches, aiming to bolster national security.
However, the plan quickly ran into a roadblock. The Cybersecurity and Infrastructure Security Agency (CISA) objected, stating that it holds the primary authority over this area. CISA's jurisdiction is established under the Cyber Incident Reporting for Critical Infrastructure Act, creating a classic case of regulatory overlap between government bodies.
To avoid "duplicative, and potentially conflicting, reporting requirements," FCC Chairwoman Jessica Rosenworcel has proposed the reversal. The commission believes this will clarify regulatory lines and prevent confusion for the tech industry. A final vote on repealing the rules is scheduled for the FCC's open meeting on June 6.
Comments
Post a Comment