[Congressional Record Volume 161, Number 154 (Wednesday, October 21, 2015)]
[Senate]
[Pages S7418-S7419]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2739. Mr. REED submitted an amendment intended to be proposed by 
him to the bill S. 754, to improve cybersecurity in the United States 
through enhanced sharing of information about cybersecurity threats, 
and for other purposes; which was ordered to lie on the table; as 
follows:

       At the appropriate place, insert the following:

     SEC. __. CYBERSECURITY TRANSPARENCY.

       (a) Definitions.--In this section--
       (1) the term ``Commission'' means the Securities and 
     Exchange Commission;
       (2) the term ``issuer'' has the meaning given the term in 
     section 3 of the Securities Exchange Act of 1934 (15 U.S.C. 
     78c); and
       (3) the term ``reporting company'' means any company that 
     is an issuer--
       (A) the securities of which are registered under section 12 
     of the Securities Exchange Act of 1934 (15 U.S.C. 78l); or
       (B) that is required to file reports under section 15(d) of 
     such Act (15 U.S.C. 78o(d)).
       (b) Requirement To Issue Rules.--Not later than 360 days 
     after the date of enactment of this Act, the Commission shall 
     issue final rules to require each reporting company, in the 
     annual report submitted under section 13 or section 15(d) of 
     the Securities Exchange Act of 1934 (15 U.S.C. 78m and 
     78o(d)) or the annual proxy statement submitted under section 
     14(a) of such Act (15 U.S.C. 78n(a))--
       (1) to disclose whether any member of the governing body, 
     such as the board of directors or general partner, of the 
     reporting company is a cybersecurity expert (based on minimum 
     standards established by the Commission, in consultation with 
     the Department of Homeland Security and the National

[[Page S7419]]

     Institute of Standards and Technology), in such detail as 
     necessary to fully describe the nature of the expertise; and
       (2) if no member of the governing body of the reporting 
     company is a cybersecurity expert, to briefly describe how 
     the absence of such expertise was taken into account by such 
     persons responsible for identifying and evaluating nominees 
     for any member of the governing body, such as a nominating 
     committee.
       (c) Considerations.--In establishing the minimum standards 
     for a cybersecurity expert for purposes of subsection (b), 
     the Commission, in consultation with the Department of 
     Homeland Security and the National Institute of Standards and 
     Technology, shall consider whether a person has substantive 
     experience with preventing and addressing cybersecurity 
     threats.
                                 ______