<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H472B2AE12A884C9E905ABC270A4AA10A" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 6638 IH: Cybersecurity Disclosure Act of 2018</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2018-07-27</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">115th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 6638</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20180727">July 27, 2018</action-date><action-desc><sponsor name-id="H001047">Mr. Himes</sponsor> (for himself, <cosponsor name-id="R000583">Mr. Thomas J. Rooney of Florida</cosponsor>, <cosponsor name-id="M001137">Mr. Meeks</cosponsor>, and <cosponsor name-id="H001064">Mr. Heck</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HBA00">Committee on Financial Services</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To promote transparency in the oversight of cybersecurity risks at publicly traded companies.</official-title></form>
	<legis-body id="HB6150BD2AD5E4026B6D4647CC899D32C" style="OLC">
 <section id="H870CEA7CF07A439B97B35EA671AB552A" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Cybersecurity Disclosure Act of 2018</short-title></quote>.</text> </section><section id="HEF3EA844BD3F4B758F474BCAEBA98398"><enum>2.</enum><header>Cybersecurity transparency</header> <subsection id="H1B46027E99BF43DB89D16A39BF8856DF"><enum>(a)</enum><header>Definitions</header><text>In this section—</text>
 <paragraph id="HFECBB47E1FD8454EA005906D1D7EE2F9"><enum>(1)</enum><text>the term <term>Commission</term> means the Securities and Exchange Commission;</text> </paragraph><paragraph id="HCBB916E419AC413C968F6CD8675C1AF1"><enum>(2)</enum><text>the term <term>cybersecurity threat</term>—</text>
 <subparagraph id="HC79E8EB6D2B942CDA24A1EFA93192B27"><enum>(A)</enum><text>means an action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system; and</text>
 </subparagraph><subparagraph id="HBF809EE1A73242338C1273B4850AA473"><enum>(B)</enum><text>does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement;</text>
 </subparagraph></paragraph><paragraph id="H2A23E3B0F7BC46F59DDF3F9E5FD38FED"><enum>(3)</enum><text>the term <term>information system</term>—</text> <subparagraph id="H166B69ED09454FA79036888DD41D6ED1"><enum>(A)</enum><text>has the meaning given the term in section 3502 of title 44, United States Code; and</text>
 </subparagraph><subparagraph id="H25DBC63D3E454413AFB6C5CD4F0AFCE8"><enum>(B)</enum><text>includes industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers;</text>
 </subparagraph></paragraph><paragraph id="HE1DFEC30B0014F27837A174DDF7128CC"><enum>(4)</enum><text>the term <term>issuer</term> has the meaning given the term in section 3 of the Securities Exchange Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/15/78c">15 U.S.C. 78c</external-xref>);</text>
 </paragraph><paragraph id="HAE2004F656A84E8FACC92140D232696E"><enum>(5)</enum><text>the term <term>NIST</term> means the National Institute of Standards and Technology; and</text> </paragraph><paragraph id="HA98350C6A9A14879B741CD4B81CDD0FD"><enum>(6)</enum><text>the term <term>reporting company</term> means any company that is an issuer—</text>
 <subparagraph id="H9949AE10246945318526973721E12181"><enum>(A)</enum><text>the securities of which are registered under section 12 of the Securities Exchange Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/15/78l">15 U.S.C. 78l</external-xref>); or</text>
 </subparagraph><subparagraph id="H376EB41B05FE4C7998A167F41E2FE484"><enum>(B)</enum><text>that is required to file reports under section 15(d) of such Act (<external-xref legal-doc="usc" parsable-cite="usc/15/78o">15 U.S.C. 78o(d)</external-xref>).</text> </subparagraph></paragraph></subsection><subsection id="HF943D4623E5D414285EB2F9A713764CF"><enum>(b)</enum><header>Requirement To issue rules</header><text>Not later than 360 days after the date of enactment of this Act, the Commission shall issue final rules to require each reporting company, in the annual report submitted under section 13 or section 15(d) of the Securities Exchange Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/15/78m">15 U.S.C. 78m</external-xref> and 78o(d)) or the annual proxy statement submitted under section 14(a) of such Act (<external-xref legal-doc="usc" parsable-cite="usc/15/78n">15 U.S.C. 78n(a)</external-xref>)—</text>
 <paragraph id="H2B0F8041C59943D9AC8842D01758413E"><enum>(1)</enum><text>to disclose whether any member of the governing body, such as the board of directors or general partner, of the reporting company has expertise or experience in cybersecurity and in such detail as necessary to fully describe the nature of the expertise or experience; and</text>
 </paragraph><paragraph id="HD76370E5F38945E89C14CDEA2163AF44"><enum>(2)</enum><text>if no member of the governing body of the reporting company has expertise or experience in cybersecurity, to describe what other cybersecurity steps taken by the reporting company were taken into account by such persons responsible for identifying and evaluating nominees for any member of the governing body, such as a nominating committee.</text>
 </paragraph></subsection><subsection id="H5D90CB747665453DB04F14FDECD86447"><enum>(c)</enum><header>Cybersecurity expertise or experience</header><text>For purposes of subsection (b), the Commission, in consultation with NIST, shall define what constitutes expertise or experience in cybersecurity, such as professional qualifications to administer information security program functions or experience detecting, preventing, mitigating, or addressing cybersecurity threats, using commonly defined roles, specialities, knowledge, skills, and abilities, such as those provided in NIST Special Publication 800–181 entitled <quote>NICE Cybersecurity Workforce Framework</quote>, or any successor thereto.</text>
			</subsection></section></legis-body></bill>


