CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
CIRCIA: Information Protections (Sec. 2245)

CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) CIRCIA-2245a: Authorized Use, Retention and Digital Security of Reports

Reported information may be disclosed, retained and used only for defined purposes (cybersecurity, identifying a cyber threat or vulnerability, mitigating specific threats of harm, or prosecuting an offence arising from a reported incident); reports must be stored and protected at a minimum at the FIPS-199 moderate baseline and personal information protected.

Other controls in CIRCIA: Information Protections (Sec. 2245)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.