CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
CIRCIA: Required Reporting (Sec. 2242)

CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) CIRCIA-2242c4: Required Contents of a Covered Cyber Incident Report

The report must include, to the extent applicable and available: a description of the incident and affected systems/networks/devices; the nature of unauthorized access and impact on operations; the estimated date range; vulnerabilities exploited and security defenses in place plus tactics/techniques/procedures; identifying/contact information for the responsible actor; categories of information accessed; and the covered entity identity and contact information.

Other controls in CIRCIA: Required Reporting (Sec. 2242)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.