None
EN
OIG: CISA Fails to Finalize Plans for Automated Cyber Threat Sharing After 2015 Cybersecurity Act Expiration
['Homeland Security Today', '.Wp-Block-Co-Authors-Plus-Coauthors.Is-Layout-Flow', 'Class', 'Wp-Block-Co-Authors-Plus', 'Display Inline', '.Wp-Block-Co-Authors-Plus-Avatar', 'Where Img', 'Height Auto Max-Width', 'Vertical-Align Bottom .Wp-Block-Co-Authors-Plus-Coauthors.Is-Layout-Flow .Wp-Block-Co-Authors-Plus-Avatar', 'Vertical-Align Middle .Wp-Block-Co-Authors-Plus-Avatar Is .Alignleft .Alignright']
HSToday
Why the OIG Did This AuditThe Cybersecurity Information Sharing Act of 2015 requires the Department of Homeland Security to establish a capability and process for Federal entities to receive cyber threat information from non-Federal entities.
Section 107 of the Act requires Inspectors General from the Intelligence Community and select agencies to submit a joint report to Congress every 2 years on actions to share cyber threat information.
What the OIG FoundThe Cybersecurity and Infrastructure Security Agency (CISA) met requirements of the Cybersecurity Information Sharing Act of 2015.
However, CISA has not finalized its plans for the continued use of Automated Indicator Sharing (AIS).
What the OIG RecommendThe OIG made one recommendation for CISA to determine whether to maintain AIS beyond September 30, 2025.