[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-253708-105":53,"doc-detail-253708-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","iti-policy-principles-for-security-incident-reporting-in-the-us-july-2021","ITI Policy Principles for Security Incident Reporting in the U.S. - July 2021","","ITI develops policy principles to improve security incident reporting in the United States, emphasizing that effective reporting should inform incident response, contain or prevent further impacts, and enable accurate assessment by federal agencies. The guidance distinguishes security incident reporting from cyber threat information sharing and data breach notification, and recommends structuring reporting via severity-based categorization, feasible 72-hour verification timelines, and limiting reporting obligations to compromised entities. It also focuses on confidentiality and practical implementation.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/iti-policy-principles-for-security-incident-reporting-in-the-us-july-2021/253708/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/iti-policy-principles-for-security-incident-reporting-in-the-us-july-2021/253708.png","ImageObject",442,249,{"name":88,"@type":89},"Mia  ","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-09-19","2026-09-13",true,{"@type":98,"interactionType":99,"userInteractionCount":79},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"How does security incident reporting differ from cyber threat information sharing and data breach notification?","Question",{"text":108,"@type":109},"Security incident reporting focuses on past details of a cybersecurity incident and can include compromise vectors, impacted systems, and attacker behavior. Cyber threat information sharing is proactive and future-oriented, while data breach notification specifically targets unauthorized access or disclosure of personally identifiable or sensitive privacy data.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"What is the purpose of an incident categorization matrix?",{"text":113,"@type":109},"An incident categorization matrix maps reporting thresholds to objective criteria and incident severity levels tied to identifiable harms. It helps prioritize incidents, improves reporting precision, and reduces burden and informational overload for relevant authorities and security teams.",{"name":115,"@type":106,"acceptedAnswer":116},"What reporting timeline does the guidance recommend?",{"text":117,"@type":109},"Legislation should provide a reporting window aligned with global best practices, including at least 72 hours after an entity verifies the incident. Shorter timelines increase the risk of inaccurate or poorly contextualized reporting and can undermine remediation efforts.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},253708,1789269204,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":79,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":79,"language":135,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":136,"faqs":137,"seo_title":138,"seo_description":61,"update_tm":125,"read_time":73},687207024478,"https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd","ITI Policy Principles for Security Incident Reporting in  \nthe U.S.  \nJuly 2021  \nThe SolarWinds compromise has demonstrated how the cyber threat landscape is constantly evolving, resulting in the emergence of new threats. In search of a suitable policy response, policymakers have increasingly turned to incident reporting policy regimes as a potentially appropriate tool. The proposals introduced to date often conflate multiple issues and misunderstand the goals and the applicability of  \nsecurity incident reporting.  \nITI recognizes the importance of cybersecurity incident reporting to inform actions to respond to incidents and to contain or prevent further impacts. ITI views the concepts related to security incident reporting as distinct from those of cyber threat information sharing or a data breach notification (see box for details) . If areport provides sufficient technical details about the suffered incident, federal agencies can understand the nature of the attack and take steps to mitigate the associated risk. Likewise, actionable reporting may help government officials to prioritize incident response assistance to affected organizations, particularly while dealing with an active campaign targeting multiple organizations. This assumes that affected organizations required support and that the principles articulated below have been fully adopted.  \nAs such, if carefully crafted, incident reporting has the potential to be a helpful policy lever. It is through this lens that we offer our recommendations on several key areas that policymakers should consider in developing an effective, efficient security incident reporting regime.  \nSecurity incident reporting is distinct from other concepts with which it is often confused: data breach notification and cyberthreat information sharing. While some incidents may blur the line between these concepts, it is important to understand the difference between these terms and what each process is meant to achieve.  \nSecurity Incident Reporting focuses on the past because it reports on the details ofa cybersecurity incident that has already occurred. This could include the vector of compromise, the systems and information compromised or targeted by the attacker, and any attributes of the attacker’s behavior.  \nReports may focus on the actual or the potential harm caused by an incident. Information conveyed in the reporting highly depends on the reporting timeline, reporting purpose (and use) and segment needs.  \nData Breach Notification relates specifically to the unauthorized access to or disclosure of personally identifiable information or other sensitive privacy data. In the United States, there are more than 50 state and local laws focused on data breach notification.  \nCyberthreat Information Sharing focuses on the future and refers to the proactive sharing of threat information to help all entities understand threats and take steps to prevent successful cyberattacks. Threat information sharing should be voluntary and may include indicators such as anomalous network activity or methods of circumventing security controls.  \nDevelop and Adopt an Incident Categorization Matrix  \nPolicymakers should ensure that the threshold for reporting requirements is mapped to specific objective criteria and specific incident severity levels related to identifiable harms, such as to public  \nhealth and safety, or operational disruption.1 Reporting requirements should only focus on severe and significant attacks that cause actual disruption or loss and should include specific parameters. An incident categorization matrix2 can represent the severity of an incident more accurately which helps with the prioritization of incidents and ultimately supports more precise reporting. Focused reporting that is limited to severe incidents reduces the burden on information security teams and frees resources for the essential tasks of examining and remediating incidents and securing the organization’s systems. Mor","cbCaiaOLF7gkl5W7","https://ap.wps.com/l/cbCaiaOLF7gkl5W7","pdf",322956,"English","# Security incident reporting principles\n## Distinctions from related concepts\n## Develop and adopt an incident categorization matrix\n## Establish feasible reporting timelines commensurate with severity\n## Limit responsibility to the compromised entity\n## Ensure confidentiality and appropriate handling","[{\"question\":\"How does security incident reporting differ from cyber threat information sharing and data breach notification?\",\"answer\":\"Security incident reporting focuses on past details of a cybersecurity incident and can include compromise vectors, impacted systems, and attacker behavior. Cyber threat information sharing is proactive and future-oriented, while data breach notification specifically targets unauthorized access or disclosure of personally identifiable or sensitive privacy data.\"},{\"question\":\"What is the purpose of an incident categorization matrix?\",\"answer\":\"An incident categorization matrix maps reporting thresholds to objective criteria and incident severity levels tied to identifiable harms. It helps prioritize incidents, improves reporting precision, and reduces burden and informational overload for relevant authorities and security teams.\"},{\"question\":\"What reporting timeline does the guidance recommend?\",\"answer\":\"Legislation should provide a reporting window aligned with global best practices, including at least 72 hours after an entity verifies the incident. Shorter timelines increase the risk of inaccurate or poorly contextualized reporting and can undermine remediation efforts.\"}]","ITI Policy Principles for Security Incident Reporting in the U.S. - July 2021 | PDF"]