Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
IB
Union Calendar No. 518
116TH CONGRESS
2D SESSION
H. R. 1731
[Report No. 116–633]
To amend the Securities Exchange Act of 1934 to promote transparency
in the oversight of cybersecurity risks at publicly traded companies.
IN THE HOUSE OF REPRESENTATIVES
MARCH 13, 2019
Mr. HIMES (for himself, Mr. HECK, and Mr. MEEKS) introduced the following
bill; which was referred to the Committee on Financial Services
DECEMBER 8, 2020
Reported with an amendment, committed to the Committee of the Whole
House on the State of the Union, and ordered to be printed
[Strike out all after the enacting clause and insert the part printed in italic]
[For text of introduced bill, see copy of bill as introduced on March 13, 2019]
VerDate Sep 11 2014
03:37 Dec 09, 2020
Jkt 019200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6652
E:\BILLS\H1731.RH
H1731
SSpencer on DSK126QN23PROD with BILLS
2
•HR 1731 RH
A BILL
To amend the Securities Exchange Act of 1934 to promote
transparency in the oversight of cybersecurity risks at
publicly traded companies.
VerDate Sep 11 2014
02:03 Dec 09, 2020
Jkt 019200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6652
E:\BILLS\H1731.RH
H1731
SSpencer on DSK126QN23PROD with BILLS
3
•HR 1731 RH
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Cybersecurity Disclosure
4
Act of 2019’’.
5
SEC. 2. CYBERSECURITY TRANSPARENCY.
6
The Securities Exchange Act of 1934 (15 U.S.C. 78a
7
et seq.) is amended by inserting after section 14B (15
8
U.S.C. 78n–2) the following:
9
‘‘SEC. 14C. CYBERSECURITY TRANSPARENCY.
10
‘‘(a) DEFINITIONS.—In this section—
11
‘‘(1) the term ‘cybersecurity’ means any action,
12
step, or measure to detect, prevent, deter, mitigate, or
13
address any cybersecurity threat or any potential cy-
14
bersecurity threat;
15
‘‘(2) the term ‘cybersecurity threat’—
16
‘‘(A) means an action, not protected by the
17
First Amendment to the Constitution of the
18
United States, on or through an information sys-
19
tem that may result in an unauthorized effort to
20
adversely impact the security, availability, con-
21
fidentiality, or integrity of an information sys-
22
tem or information that is stored on, processed
23
by, or transiting an information system; and
24
VerDate Sep 11 2014
02:03 Dec 09, 2020
Jkt 019200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6203
E:\BILLS\H1731.RH
H1731
SSpencer on DSK126QN23PROD with BILLS
4
•HR 1731 RH
‘‘(B) does not include any action that solely
1
involves a violation of a consumer term of service
2
or a consumer licensing agreement;
3
‘‘(3) the term ‘information system’—
4
‘‘(A) has the meaning given the term in sec-
5
tion 3502 of title 44, United States Code; and
6
‘‘(B) includes industrial control systems,
7
such as supervisory control and data acquisition
8
systems, distributed control systems, and pro-
9
grammable logic controllers;
10
‘‘(4) the term ‘NIST’ means the National Insti-
11
tute of Standards and Technology; and
12
‘‘(5) the term ‘reporting company’ means any
13
company that is an issuer—
14
‘‘(A) the securities of which are registered
15
under section 12; or
16
‘‘(B) that is required to file reports under
17
section 15(d).
18
‘‘(b) REQUIREMENT TO ISSUE RULES.—Not later than
19
360 days after the date of enactment of this section, the
20
Commission shall issue final rules to require each reporting
21
company, in the annual report of the reporting company
22
submitted under section 13 or section 15(d) or in the an-
23
nual proxy statement of the reporting company submitted
24
under section 14(a)—
25
VerDate Sep 11 2014
02:03 Dec 09, 2020
Jkt 019200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6203
E:\BILLS\H1731.RH
H1731
SSpencer on DSK126QN23PROD with BILLS
5
•HR 1731 RH
‘‘(1) to disclose whether any member of the gov-
1
erning body, such as the board of directors or general
2
partner, of the reporting company has expertise or ex-
3
perience in cybersecurity and in such detail as nec-
4
essary to fully describe the nature of the expertise or
5
experience; and
6
‘‘(2) if no member of the governing body of the
7
reporting company has expertise or experience in cy-
8
bersecurity, to describe what other aspects of the re-
9
porting company’s cybersecurity were taken into ac-
10
count by any person, such as an official serving on
11
a nominating committee, that is responsible for iden-
12
tifying and evaluating nominees for membership to
13
the governing body.
14
‘‘(c) CYBERSECURITY EXPERTISE OR EXPERIENCE.—
15
For purposes of subsection (b), the Commission, in consulta-
16
tion with NIST, shall define what constitutes expertise or
17
experience in cybersecurity using commonly defined roles,
18
specialties, knowledge, skills, and abilities, such as those
19
provided in NIST Special Publication 800–181, titled ‘Na-
20
tional Initiative for Cybersecurity Education (NICE) Cy-
21
bersecurity Workforce Framework’, or any successor there-
22
to.’’.
23
VerDate Sep 11 2014
02:03 Dec 09, 2020
Jkt 019200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6203
E:\BILLS\H1731.RH
H1731
SSpencer on DSK126QN23PROD with BILLS
Union Calendar No. 518
116TH CONGRESS
2D SESSION
H. R. 1731
[Report No. 116–633]
A BILL
To amend the Securities Exchange Act of 1934 to
promote transparency in the oversight of cyberse-
curity risks at publicly traded companies.
DECEMBER 8, 2020
Reported with an amendment, committed to the Com-
mittee of the Whole House on the State of the Union,
and ordered to be printed
VerDate Sep 11 2014
03:37 Dec 09, 2020
Jkt 019200
PO 00000
Frm 00006
Fmt 6651
Sfmt 6651
E:\BILLS\H1731.RH
H1731
SSpencer on DSK126QN23PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.