Showing posts with label Cybersecurity Governance. Show all posts
Showing posts with label Cybersecurity Governance. Show all posts

Saturday, April 17, 2021

S 808 Introduced - Cybersecurity Disclosure Act of 2021

Last month Sen Reed (D,RI) introduced S 808, the Cybersecurity Disclosure Act of 2021. The bill would require the Securities and Exchange Commission to establish rules requiring the reporting of whether there was cybersecurity expertise on the board of directors or other governing body of each company required to file annual reports. The bill is nearly identical to S 592 that was introduced last session. No action was taken on the earlier bill.

Moving Forward

Reed is a member of the Senate Banking, Housing, and Urban Affairs Committee to which this bill was assigned for consideration as are three of his cosponsors {Cortez-Masto (D,NV), Cramer (R,ND), and Warner (D,VA)}. This means that there should be enough influence to see the bill considered in Committee. I would expect there to be some resistance to this bill from business supporters in the Republican conference. With the increasing concern, however, in Congress about cybersecurity issues, there should be somewhat reduced opposition to this bill. That means that the bill could pass in Committee with some bipartisan support.

This bill will not make it directly to the floor of the Senate. The bill is not important enough to take the time required for the normal debate and amendment process. That would leave just the unanimous consent process as the means for this bill to make it to the floor; there will be at least one Republican Senator that would object to the consideration of the bill. The bill could make it to the floor as an amendment to a must pass spending or authorization bill.

Commentary

I would like to reiterate a point I made in my discussion of S 592 back in 2019, is this realistic? Does every corporation in the United States (no matter the size) need to have a cybersecurity expert on their Board? According to Scott A Hodge, at the TaxFoundation.org, in 2014 there were 1.7 million C corporations and 7.4 million partnerships and S Corporations in the United States. Where are all of the cybersecurity experts going to come from?

Thursday, September 13, 2018

HR 6638 Introduced – Cybersecurity Governance


Back in July Rep. Himes (D,CT) introduced HR 6638, the Cybersecurity Disclosure Act of 2018. The bill directs the Security and Exchange Commission to require reporting companies to include in annual reports a listing of senior personnel with expertise or experience in cybersecurity.

The bill gives the gives the Commission 360 days to issue final rules requiring reporting companies “disclose whether any member of the governing body, such as the board of directors or general partner, of the reporting company has expertise or experience in cybersecurity and in such detail as necessary to fully describe the nature of the expertise or experience” {2(b)(1)}.

Moving Forward


Himes and his two Democratic cosponsors {Rep. Meeks (D,NY) and Rep. Heck (D,WA)} are members of the House Financial Affairs Committee two which this bill was assigned for consideration. Normally, this could provide them with sufficient influence to have the bill considered in Committee. This late in the session, however, such consideration is unlikely.

Business interests with no cybersecurity representation (probably a large majority of middle size and smaller businesses) would be expected to oppose such reporting requirements. Since this is a major Republican constituency, I expect that there will be little or no support from Republicans on this bill.

Commentary


There is something odd about the way this bill was written. It includes a list of definitions in §2(a), two of which are never used in the bill. Those two definitions are the only reason that I am discussing the bill. The two terms? “Cybersecurity Threat” and “Information System”.

The first term is defined in two parts. The first {§2(a)(2)(A)}:

An action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system.”

The second part of the definition is the now obligatory {§2(a)(2)(B)}:

Does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.

Nothing new or interesting here; it is a now standard IT-centric cybersecurity definition. The next term would normally also fall within that description, but the crafters of this bill included an addendum to one of the standard ‘information system’ definitions {§2(a)(3)(B)}:

Includes industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers.

We have seen both of these in other pieces of legislation, but the odd thing here is that neither definition has anything to do with the requirements of the bill. The definition of the key term in the bill; ‘expertise or experience in cybersecurity’ is left for the Commission to define; in consultation with NIST.

The best that I can figure is that Hines is using these two definitions to establish congressional intent that cybersecurity (for the purposes of this particular Commission regulation) includes control system security. Whether or not this would encourage reporting companies to include people with an ICS background in their governing bodies remains to be seen, but it might (should?) encourage the SEC to allow for such eventuality in their definition of ‘expertise or experience in cybersecurity’.

Friday, May 6, 2016

HR 5069 Introduced – Cybersecurity Reporting

Last week Rep. McDermott (D,WA) introduced HR 5069, the Cybersecurity Systems and Risks Reporting Act. The bill would modify the Sarbanes-Oxley (SOX) Act of 2002 (15 USC Chapter 98) adding cybersecurity reporting requirements to the financial reporting requirements of that Act.

Definitions


Section 2 of the bill starts out by modifying some existing definitions in the SOX Act. The definition of audit {15 USC 7201(a)(2)} is modified by adding ‘and information systems’ after the words ‘financial statements’. In the term ‘audit committee’ {§7201(a)(3)} the bill would replace ‘financial reporting processes’ with ‘financial, and cybersecurity systems reporting processes’. Finally, in §7201(a)(3), the definition of ‘professional standards’ would be modified by adding ‘cybersecurity systems standards and practices,’ after the ‘quality control policies and procedures,’.

Three new definitions would then be added to the SOX Act list of definitions. The new terms would be:

• Information System;
• Cybersecurity System; and
• Cybersecurity Risk

The key definition here is ‘information system’. It is defined this way {new §7201(a)(18)}:

“The term ‘information system’ means a set of activities, involving people, processes, data, or technology, which enable the issuer to obtain, generate, use, and communicate transactions and information to maintain accountability and measure and review the issuer’s performance or progress towards achievement of objectives.”

Cybersecurity Requirements


The bill goes on to modify three additional sections of the SOX Act where it conflates cybersecurity with financial systems. For example, it changes the title of §7241 to “Corporate responsibility for financial reports and information systems” [added verbiage] and makes internal changes adding requirements for the newly listed ‘principal cybersecurity systems officer’.

Again in §7262, the new title is “Management assessment of internal controls and information systems” [added verbiage] with added instructions for “adequate internal control and cybersecurity systems structures and procedures for financial and information systems reporting”. The bill would essentially duplicate current financial reporting requirements for information systems.

Finally, in §7265, the new title is “Disclosure of audit committee financial and cybersecurity systems experts” [added verbiage]. The new language would require the Securities and Exchange Commission (SEC) to consult with the Secretaries of Homeland Security and Commerce to come up with an appropriate definition of ‘cybersecurity systems expert’.

Moving Forward


McDermott is not a member of the House Financial Services Committee; the committee to which this bill was assigned for consideration. This makes it unlikely that this bill will receive consideration in that Committee. There is an outside chance that this bill could be offered as a floor amendment to the Financial Services spending bill, but it is unlikely that it would survive a vote on the floor. Corporate opposition to the huge expansion of the SOX Act requirements proposed in this bill would be fierce.

Commentary


Ignoring for the moment the question of just how effective the SOX Act has been in preventing financial irregularities in corporate finances, conflating cybersecurity issues with financial governance seems to be counter-productive. Adding corporate cybersecurity governance requirements to the SOX Act makes a certain amount of sense, but they would probably have been more effective if they had been added as a new and separate section of the Act.

Of course, the bigger issue here (as elsewhere in cybersecurity regulation) is where would the SEC come up with the trained personnel to properly evaluate (and ultimately investigate) cybersecurity governance. Not only would these people need a background in cybersecurity (of which there is already an ever-growing mismatch between positions and trained personnel), but they would also have to have a background (or training) in managing corporate cybersecurity programs. It will be a long time coming for there to be many folks with that background available for government service.


Finally, it absolutely astounds me that this bill would so specifically restrict cybersecurity governance to IT and financial systems. While there are certainly more companies that are at risk for financial harm to attacks on these systems, there are still a very large number of companies (and that includes some very large companies) whose financial stability relies on the consistent operation of their industrial control systems. Ignoring that set of cybersecurity risks in a cybersecurity governance regulation system just makes no sense.
 
/* Use this with templates/template-twocol.html */