On August 8, 2023, the National Institute of Standards and Technology (“NIST”) released a draft of The NIST Cybersecurity Framework (CSF) 2.0,1 (the “CSF” or “Framework”) along with a Discussion Draft of the Implementation Examples.2 This draft makes the most
Inside Cybersecurity & Privacy Law
Exploring the evolution of cybersecurity and privacy law
Inside Cybersecurity & Privacy Law, published by Mayer Brown, focuses on legal developments and regulatory updates in cybersecurity, data privacy, and related compliance frameworks. The blog covers topics such as government cybersecurity regulations, data protection laws, artificial intelligence governance, and the impact of emerging technologies on privacy and security obligations. It also addresses sector-specific cybersecurity requirements, international directives, and enforcement trends. The content is aimed at helping organizations understand and navigate the evolving legal landscape surrounding cybersecurity and privacy risks, including contractual and legislative changes affecting businesses globally.
Latest from Inside Cybersecurity & Privacy Law - Page 4
Oregon Passes Privacy Law With Narrow Financial Institution Exemption
Oregon has joined 10 other states in enacting a comprehensive data privacy law.1 On July 18, 2023, Governor Tina Kotek signed the Oregon Consumer Privacy Act (the “Oregon Privacy Law”) into law. The law imposes a range of new…
SEC Adopts Final Rules on Public Company Cybersecurity Disclosures of Incidents and Processes
On July 26, 2023, the U.S. Securities and Exchange Commission (the “SEC”) issued a release, adopting final rules (the “Final Rules”) aimed at standardizing and enhancing disclosure relating to cybersecurity incidents and risk management processes. The SEC had proposed rules…
Biden-Harris Administration Announces IoT Cybersecurity Labeling Program
On July 18, 2023, the Biden-Harris Administration announced its “U.S. Cyber Trust Mark” initiative.1 Under this program, the Federal Communications Commission (FCC) will establish a voluntary certification and labeling program to guide and inform consumers purchasing Internet of Things…
Biden Administration Invites Public Comment on Harmonizing Cybersecurity Regulations
On July 19, 2023, the Office of the National Cyber Director (ONCD) issued a request for information (RFI) on cybersecurity regulatory harmonization.1 The RFI is intended to be a step toward the Biden Administration’s goal, as stated in the…
Draft Technical Standards for DORA Now Available
The EU Digital Operational Resilience Act (“DORA”) entered into force in January 16, 2023, setting forth security requirements for network and information systems of organizations operating in the financial sector;
Obligations under DORA are to be further detailed by Regulatory…
EU Commission Adopts Adequacy Decision for EU-US Data Privacy Framework
On July 10, 2023, the European Commission (“Commission”) adopted an adequacy decision for the EU-US Data Privacy Framework (“DPF”). The DPF is the successor to the EU-US Privacy Shield, which the Court of Justice of the European Union (“CJEU”) declared invalid in…
Webinar: The Newly Revised NYDFS Cyber Requirements for Financial Services Companies: What you Need to Know About the Proposal
The New York Department of Financial Services (NYDFS) has proposed revisions to its cybersecurity regulation for banks, insurance companies and other financial services companies. The proposal significantly expands requirements for covered entities, including new requirements for larger companies, expanded governance…
President Biden Convenes with AI Industry Leaders; Senator Schumer Proposes New SAFE AI Innovation Framework
On Tuesday, June 20, 2023, President Joe Biden met with industry experts at the intersection of technology and society to discuss the opportunities and challenges of artificial intelligence (AI) development. President Biden emphasized the “need to manage the risks to…
UK’s Approach to Regulating the Use of Artificial Intelligence
The UK Government published its AI White Paper on 29 March 2023, setting out its proposals for regulating the use of artificial intelligence (AI) in the United Kingdom. The White Paper is a continuation of the AI Regulation Policy Paper…