Eric Geller @ericgeller
ITI's John Miller recommends: "feasible" timelines (≥72 hrs), confidentiality protections (says may need to update 2015 CISA law), harmonize w/ existing regs, "appropriate" reporting thresholds (limit to verified incidents), and limit reporting to impacted entities, not vendors. — PolitiTweet.org