Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
116TH CONGRESS
1ST SESSION
S. 592
To amend the Securities Exchange Act of 1934 to promote transparency
in the oversight of cybersecurity risks at publicly traded companies.
IN THE SENATE OF THE UNITED STATES
FEBRUARY 28, 2019
Mr. REED (for himself, Ms. COLLINS, Mr. WARNER, Mr. KENNEDY, and Mr.
JONES) introduced the following bill; which was read twice and referred
to the Committee on Banking, Housing, and Urban Affairs
A BILL
To amend the Securities Exchange Act of 1934 to promote
transparency in the oversight of cybersecurity risks at
publicly traded companies.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Cybersecurity Disclo-
4
sure Act of 2019’’.
5
SEC. 2. CYBERSECURITY TRANSPARENCY.
6
The Securities Exchange Act of 1934 (15 U.S.C. 78a
7
et seq.) is amended by inserting after section 14B (15
8
U.S.C. 78n–2) the following:
9
VerDate Sep 11 2014
00:22 Mar 07, 2019
Jkt 089200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\S592.IS
S592
kjohnson on DSK79L0C42 with BILLS
2
•S 592 IS
‘‘SEC. 14C. CYBERSECURITY TRANSPARENCY.
1
‘‘(a) DEFINITIONS.—In this section—
2
‘‘(1) the term ‘cybersecurity’ means any action,
3
step, or measure to detect, prevent, deter, mitigate,
4
or address any cybersecurity threat or any potential
5
cybersecurity threat;
6
‘‘(2) the term ‘cybersecurity threat’—
7
‘‘(A) means an action, not protected by the
8
First Amendment to the Constitution of the
9
United States, on or through an information
10
system that may result in an unauthorized ef-
11
fort to adversely impact the security, avail-
12
ability, confidentiality, or integrity of an infor-
13
mation system or information that is stored on,
14
processed by, or transiting an information sys-
15
tem; and
16
‘‘(B) does not include any action that sole-
17
ly involves a violation of a consumer term of
18
service or a consumer licensing agreement;
19
‘‘(3) the term ‘information system’—
20
‘‘(A) has the meaning given the term in
21
section 3502 of title 44, United States Code;
22
and
23
‘‘(B) includes industrial control systems,
24
such as supervisory control and data acquisition
25
VerDate Sep 11 2014
00:22 Mar 07, 2019
Jkt 089200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\S592.IS
S592
kjohnson on DSK79L0C42 with BILLS
3
•S 592 IS
systems, distributed control systems, and pro-
1
grammable logic controllers;
2
‘‘(4) the term ‘NIST’ means the National Insti-
3
tute of Standards and Technology; and
4
‘‘(5) the term ‘reporting company’ means any
5
company that is an issuer—
6
‘‘(A) the securities of which are registered
7
under section 12; or
8
‘‘(B) that is required to file reports under
9
section 15(d).
10
‘‘(b) REQUIREMENT TO ISSUE RULES.—Not later
11
than 360 days after the date of enactment of this section,
12
the Commission shall issue final rules to require each re-
13
porting company, in the annual report of the reporting
14
company submitted under section 13 or section 15(d) or
15
in the annual proxy statement of the reporting company
16
submitted under section 14(a)—
17
‘‘(1) to disclose whether any member of the
18
governing body, such as the board of directors or
19
general partner, of the reporting company has exper-
20
tise or experience in cybersecurity and in such detail
21
as necessary to fully describe the nature of the ex-
22
pertise or experience; and
23
‘‘(2) if no member of the governing body of the
24
reporting company has expertise or experience in cy-
25
VerDate Sep 11 2014
00:22 Mar 07, 2019
Jkt 089200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\S592.IS
S592
kjohnson on DSK79L0C42 with BILLS
4
•S 592 IS
bersecurity, to describe what other aspects of the re-
1
porting company’s cybersecurity were taken into ac-
2
count by any person, such as an official serving on
3
a nominating committee, that is responsible for iden-
4
tifying and evaluating nominees for membership to
5
the governing body.
6
‘‘(c) CYBERSECURITY
EXPERTISE
OR
EXPERI-
7
ENCE.—For purposes of subsection (b), the Commission,
8
in consultation with NIST, shall define what constitutes
9
expertise or experience in cybersecurity using commonly
10
defined roles, specialties, knowledge, skills, and abilities,
11
such as those provided in NIST Special Publication 800–
12
181, entitled ‘National Initiative for Cybersecurity Edu-
13
cation (NICE) Cybersecurity Workforce Framework’, or
14
any successor thereto.’’.
15
Æ
VerDate Sep 11 2014
00:22 Mar 07, 2019
Jkt 089200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6301
E:\BILLS\S592.IS
S592
kjohnson on DSK79L0C42 with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.