Securities and Exchange Commission March 23, 2022 – Federal Register Recent Federal Regulation Documents

Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
Document Number: 2022-05480
Type: Proposed Rule
Date: 2022-03-23
Agency: Securities and Exchange Commission, Agencies and Commissions
The Securities and Exchange Commission (``Commission'') is proposing rules to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance, and cybersecurity incident reporting by public companies that are subject to the reporting requirements of the Securities Exchange Act of 1934. Specifically, we are proposing amendments to require current reporting about material cybersecurity incidents. We are also proposing to require periodic disclosures about a registrant's policies and procedures to identify and manage cybersecurity risks, management's role in implementing cybersecurity policies and procedures, and the board of directors' cybersecurity expertise, if any, and its oversight of cybersecurity risk. Additionally, the proposed rules would require registrants to provide updates about previously reported cybersecurity incidents in their periodic reports. Further, the proposed rules would require the cybersecurity disclosures to be presented in Inline eXtensible Business Reporting Language (``Inline XBRL''). The proposed amendments are intended to better inform investors about a registrant's risk management, strategy, and governance and to provide timely notification of material cybersecurity incidents.
Submission for OMB Review; Comment Request
Document Number: 2022-06151
Type: Notice
Date: 2022-03-23
Agency: Securities and Exchange Commission, Agencies and Commissions
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.