Cybersecurity Disclosure Act of 2015
This bill directs the Securities and Exchange Commission (SEC) to issue final rules requiring each reporting company to:
disclose in its mandatory annual report or annual proxy statement whether any member of its governing body has expertise or experience in cybersecurity, including details necessary to describe fully the nature of that expertise or experience; and if no member has such expertise or experience, describe what other company cybersecurity steps were taken into account by any persons, such as a nominating committee, responsible for identifying and evaluating nominees for the governing body. The SEC shall also, in coordination with the National Institute of Standards and Technology, define what constitutes expertise or experience in cybersecurity, such as professional qualifications to administer information security program functions or experience detecting, preventing, mitigating, or addressing cybersecurity threats.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.