Agency Information Collection Activities: Service Request Form for Enterprise Assessment Services

Download PDF
Federal RegisterOct 22, 2024
89 Fed. Reg. 84372 (Oct. 22, 2024)
Document Headings

Document headings vary by document type but may contain the following:

  • the agency or agencies that issued and signed a document
  • the number of the CFR title and the number of each part the document amends, proposes to amend, or is directly related to
  • the agency docket number / agency internal file number
  • the RIN which identifies each regulatory action listed in the Unified Agenda of Federal Regulatory and Deregulatory Actions
  • See the Document Drafting Handbook for more details.

    Department of Homeland Security
  • [Docket No. CISA-2024-0007]
  • AGENCY:

    Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS).

    ACTION:

    30-Day notice and request for comments.

    SUMMARY:

    The Cybersecurity Division (CSD) within Cybersecurity and Infrastructure Security Agency (CISA) will submit the following information collection request (ICR) to the Office of Management and Budget (OMB) for review and clearance. CISA previously published this information collection request (ICR) in the Federal Register on February 15, 2024 for a 60-day public comment period. 0 comments were received by CISA. The purpose of this notice is to allow additional 30-days for public comments.

    DATES:

    Comments are encouraged and will be accepted until November 21, 2024. Submissions received after the deadline for receiving comments may not be considered.

    ADDRESSES:

    Written comments and recommendations for the proposed information collection should be sent within 30 days of publication of this notice to www.reginfo.gov/public/do/PRAMain. Find this particular information collection by selecting “Currently under 30-day Review—Open for Public Comments” or by using the search function.

    The Office of Management and Budget is particularly interested in comments which:

    1. Evaluate whether the proposed collection of information is necessary for the proper performance of the functions of the agency, including whether the information will have practical utility;

    2. Evaluate the accuracy of the agency's estimate of the burden of the proposed collection of information, including the validity of the methodology and assumptions used;

    3. Enhance the quality, utility, and clarity of the information to be collected; and

    4. Minimize the burden of the collection of information on those who are to respond, including through the use of appropriate automated, electronic, mechanical, or other technological collection techniques or other forms of information technology, e.g., permitting electronic submissions of responses.

    FOR FURTHER INFORMATION CONTACT:

    Jonathan Pereira, 202.794.3427, vulnerability@cisa.dhs.gov.

    SUPPLEMENTARY INFORMATION:

    The Cybersecurity and Infrastructure Security Agency (CISA) Cybersecurity Division (CSD) offers cybersecurity assessments to help reduce risk for federal, state, local, tribal, territorial and private sector critical infrastructure partners. Information collected is used by CISA CSD staff to engage with customers and provide cybersecurity assessment services. For more information on the specific questions asked, please see www.reginfo.gov/public/do/PRAMain. Under 6 U.S.C. 659(c)(6), CISA provides, upon request, “. . . timely technical assistance, risk management support, and incident response capabilities to Federal and non-Federal entities with respect to cyber threat indicators, defensive measures, cybersecurity risks, and incidents, which may include attribution, mitigation, and remediation . . .”

    Number of Respondents: CISA estimates the number of respondents will be 5,000.

    Estimated Time per Respondent: CISA assumes the majority of individuals who will complete this form are Chief Information Officers or equivalent. The estimated time to complete the form was determined to be .11 hours after user testing.

    Total Annual Burden Cost: $97,674 from Economist review.

    Annual Burden Hours: The annual burden hours is 825 hours (5,000 respondents × 1.5 responses per respondent × .11 hour per response).

    Analysis

    Agency: Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS).

    Title: Service Request Form for Enterprise Assessment Services.

    OMB Number: 1670-NEW.

    Frequency: Information is required when an organization would initially request cybersecurity assessments or requests additional cybersecurity assessments. These requests are made at the discretion of the requestor therefore the program office is not able to determine when or how often such requests will occur.

    Affected Public: Business or Other For-Profit, Not-For-Profit Institutions, Federal Government, State, Local or Tribal Government.

    Number of Respondents: 5,000.

    Estimated Time per Respondent: 0.11 hours.

    Total Burden Hours: 825 hours.

    Estimated Annual Industry Cost: $97,674.

    Estimated Annual Federal Government Cost: $163,150.

    Robert J. Costello,

    Chief Information Officer, Department of Homeland Security, Cybersecurity and Infrastructure Security Agency.

    [FR Doc. 2024-24220 Filed 10-21-24; 8:45 am]

    BILLING CODE 9111-LF-P