CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
CIRCIA: Enforcement and Noncompliance (Sec. 2244)

CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) CIRCIA-2244b: Response to a CISA Request for Information

If CISA has reason to believe a covered entity experienced a covered cyber incident or made a ransom payment but failed to report, it may request additional information; the entity should respond to confirm whether a reportable event occurred.

Other controls in CIRCIA: Enforcement and Noncompliance (Sec. 2244)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.