§236.4. Mandatory cyber incident reporting procedures. — Inbound Citations
32 C.F.R. § 236.4
Statutory Authority
Cited by 2 regulations in release Current.
Citations to 32 C.F.R. § 236.4 as a whole
-
(f) As participants of the DIB CS Program, defense contractors are encouraged to share cyber threat indicators and information that they believe are valuable in alerting the Government and other DIB CS Program participants to better counter threat actor activity. Cyber activity that is not covered under § 236.4 may be of interest to DIB CS Program participants and DoD.
-
(g) Participation in these activities does not abrogate the Government's, or the DIB CS Program participants' rights or obligations regarding the handling, safeguarding, sharing, or reporting of information, or regarding any physical, personnel, or other security requirements, as required by law, regulation, policy, or a valid legal contractual obligation. However, participation in the voluntary activities of the DIB CS Program does not eliminate the requirement for DIB CS Program participants to report cyber incidents in accordance with § 236.4.