[Congressional Record Volume 161, Number 154 (Wednesday, October 21, 2015)]
[Senate]
[Pages S7418-S7419]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2739. Mr. REED submitted an amendment intended to be proposed by
him to the bill S. 754, to improve cybersecurity in the United States
through enhanced sharing of information about cybersecurity threats,
and for other purposes; which was ordered to lie on the table; as
follows:
At the appropriate place, insert the following:
SEC. __. CYBERSECURITY TRANSPARENCY.
(a) Definitions.--In this section--
(1) the term ``Commission'' means the Securities and
Exchange Commission;
(2) the term ``issuer'' has the meaning given the term in
section 3 of the Securities Exchange Act of 1934 (15 U.S.C.
78c); and
(3) the term ``reporting company'' means any company that
is an issuer--
(A) the securities of which are registered under section 12
of the Securities Exchange Act of 1934 (15 U.S.C. 78l); or
(B) that is required to file reports under section 15(d) of
such Act (15 U.S.C. 78o(d)).
(b) Requirement To Issue Rules.--Not later than 360 days
after the date of enactment of this Act, the Commission shall
issue final rules to require each reporting company, in the
annual report submitted under section 13 or section 15(d) of
the Securities Exchange Act of 1934 (15 U.S.C. 78m and
78o(d)) or the annual proxy statement submitted under section
14(a) of such Act (15 U.S.C. 78n(a))--
(1) to disclose whether any member of the governing body,
such as the board of directors or general partner, of the
reporting company is a cybersecurity expert (based on minimum
standards established by the Commission, in consultation with
the Department of Homeland Security and the National
[[Page S7419]]
Institute of Standards and Technology), in such detail as
necessary to fully describe the nature of the expertise; and
(2) if no member of the governing body of the reporting
company is a cybersecurity expert, to briefly describe how
the absence of such expertise was taken into account by such
persons responsible for identifying and evaluating nominees
for any member of the governing body, such as a nominating
committee.
(c) Considerations.--In establishing the minimum standards
for a cybersecurity expert for purposes of subsection (b),
the Commission, in consultation with the Department of
Homeland Security and the National Institute of Standards and
Technology, shall consider whether a person has substantive
experience with preventing and addressing cybersecurity
threats.
______