CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
CIRCIA: Required Reporting (Sec. 2242)

CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) CIRCIA-2242c5: Required Contents of a Ransom Payment Report

The ransom payment report must include, to the extent applicable and available: a description of the ransomware attack including estimated date range; vulnerabilities/TTPs; actor identifying/contact information; the covered entity identity and contact; the date of payment; the ransom demand including virtual-currency type; payment instructions including the virtual-currency or physical address; and the amount paid.

Other controls in CIRCIA: Required Reporting (Sec. 2242)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.