Salesforce.com IncMentioned as one of the incidents analyzed; highlights regulatory reporting burdens from cyberattacks, which could increase compliance costs.
BreachRxが発表した新たな調査によると、大規模なサイバー攻撃は規制当局、顧客、パートナー、保険会社、その他の利害関係者に対して数百もの同時報告義務を生み出し、経営陣は事実が判明する前に意思決定を迫られることが明らかになった。報告書では、Change Healthcare、Snowflake、SalesforceのOAuthキャンペーン、700Credit、Salt Typhoonの5つの影響の大きいインシデントを分析し、規制の同時性によって1つの組織内で100件以上、影響を受けた少数の事業体全体で200件以上、さらにインシデントが接続されたサードパーティシステムに連鎖的に波及した場合には300件以上の報告義務が発生することを突き止めた。調査では、垂直的、水平的、連鎖的、定義主導型、制約主導型という5つの繰り返し現れるパターンが特定され、インシデント報告はセキュリティ、法務、プライバシー、広報、経営幹部にまたがるシステム規模の調整問題となっていると結論づけている。BreachRxは、規制の同時性を大規模に管理するための6つの運用能力を推奨しており、これにはリアルタイムの義務マッピング、一元化されたクロック台帳、意思決定の根拠の記録が含まれ、これらは同社のRex Platformで運用化されている。
Salesforce.com IncMentioned as one of the incidents analyzed; highlights regulatory reporting burdens from cyberattacks, which could increase compliance costs.
Snowflake Inc.Mentioned as one of the incidents analyzed; highlights regulatory reporting burdens from cyberattacks, which could increase compliance costs.
BreachRx is the subject of the article; its research and platform are promoted as solutions to the regulatory concurrency problem, likely driving demand for its services.
Mentioned as one of the incidents analyzed; highlights regulatory reporting burdens from cyberattacks, which could increase compliance costs.