Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
117TH CONGRESS
1ST SESSION
S. 808
To amend the Securities Exchange Act of 1934 to promote transparency
in the oversight of cybersecurity risks at publicly traded companies.
IN THE SENATE OF THE UNITED STATES
MARCH 17 (legislative day, MARCH 16), 2021
Mr. REED (for himself, Ms. COLLINS, Mr. WARNER, Mr. CRAMER, Ms. COR-
TEZ MASTO, and Mr. WYDEN) introduced the following bill; which was
read twice and referred to the Committee on Banking, Housing, and
Urban Affairs
A BILL
To amend the Securities Exchange Act of 1934 to promote
transparency in the oversight of cybersecurity risks at
publicly traded companies.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Cybersecurity Disclo-
4
sure Act of 2021’’.
5
SEC. 2. CYBERSECURITY TRANSPARENCY.
6
The Securities Exchange Act of 1934 (15 U.S.C. 78a
7
et seq.) is amended by inserting after section 14B (15
8
U.S.C. 78n–2) the following:
9
VerDate Sep 11 2014
04:36 Apr 03, 2021
Jkt 019200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\S808.IS
S808
pbinns on DSKJLVW7X2PROD with BILLS
2
•S 808 IS
‘‘SEC. 14C. CYBERSECURITY TRANSPARENCY.
1
‘‘(a) DEFINITIONS.—In this section—
2
‘‘(1) the term ‘cybersecurity’ means any action,
3
step, or measure to detect, prevent, deter, mitigate,
4
or address any cybersecurity threat or any potential
5
cybersecurity threat;
6
‘‘(2) the term ‘cybersecurity threat’—
7
‘‘(A) means an action, not protected by the
8
First Amendment to the Constitution of the
9
United States, on or through an information
10
system that may result in an unauthorized ef-
11
fort to adversely impact the security, avail-
12
ability, confidentiality, or integrity of an infor-
13
mation system or information that is stored on,
14
processed by, or transiting an information sys-
15
tem; and
16
‘‘(B) does not include any action that sole-
17
ly involves a violation of a consumer term of
18
service or a consumer licensing agreement;
19
‘‘(3) the term ‘information system’—
20
‘‘(A) has the meaning given the term in
21
section 3502 of title 44, United States Code;
22
and
23
‘‘(B) includes industrial control systems,
24
such as supervisory control and data acquisition
25
VerDate Sep 11 2014
04:36 Apr 03, 2021
Jkt 019200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\S808.IS
S808
pbinns on DSKJLVW7X2PROD with BILLS
3
•S 808 IS
systems, distributed control systems, and pro-
1
grammable logic controllers;
2
‘‘(4) the term ‘NIST’ means the National Insti-
3
tute of Standards and Technology; and
4
‘‘(5) the term ‘reporting company’ means any
5
company that is an issuer—
6
‘‘(A) the securities of which are registered
7
under section 12; or
8
‘‘(B) that is required to file reports under
9
section 15(d).
10
‘‘(b) REQUIREMENT TO ISSUE RULES.—Not later
11
than 360 days after the date of enactment of this section,
12
the Commission shall issue final rules to require each re-
13
porting company, in the annual report of the reporting
14
company submitted under section 13 or section 15(d) or
15
in the annual proxy statement of the reporting company
16
submitted under section 14(a)—
17
‘‘(1) to disclose whether any member of the
18
governing body, such as the board of directors or
19
general partner, of the reporting company has exper-
20
tise or experience in cybersecurity and in such detail
21
as necessary to fully describe the nature of the ex-
22
pertise or experience; and
23
‘‘(2) if no member of the governing body of the
24
reporting company has expertise or experience in cy-
25
VerDate Sep 11 2014
04:36 Apr 03, 2021
Jkt 019200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\S808.IS
S808
pbinns on DSKJLVW7X2PROD with BILLS
4
•S 808 IS
bersecurity, to describe what other aspects of the re-
1
porting company’s cybersecurity were taken into ac-
2
count by any person, such as an official serving on
3
a nominating committee, that is responsible for iden-
4
tifying and evaluating nominees for membership to
5
the governing body.
6
‘‘(c) CYBERSECURITY
EXPERTISE
OR
EXPERI-
7
ENCE.—For purposes of subsection (b), the Commission,
8
in consultation with NIST, shall define what constitutes
9
expertise or experience in cybersecurity using commonly
10
defined roles, specialties, knowledge, skills, and abilities,
11
such as those provided in NIST Special Publication 800–
12
181, entitled ‘National Initiative for Cybersecurity Edu-
13
cation (NICE) Cybersecurity Workforce Framework’, or
14
any successor thereto.’’.
15
Æ
VerDate Sep 11 2014
04:36 Apr 03, 2021
Jkt 019200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6301
E:\BILLS\S808.IS
S808
pbinns on DSKJLVW7X2PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.