[Congressional Record Volume 166, Number 116 (Wednesday, June 24, 2020)]
[Senate]
[Page S3233]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 1711. Mr. KING submitted an amendment intended to be proposed by 
him to the bill S. 4049, to authorize appropriations for fiscal year 
2021 for military activities of the Department of Defense, for military 
construction, and for defense activities of the Department of Energy, 
to prescribe military personnel strengths for such fiscal year, and for 
other purposes; which was ordered to lie on the table; as follows:

       At the appropriate place, insert the following:

     SEC. ___. CYBERSECURITY REPORTING REQUIREMENTS FOR PUBLICLY 
                   TRADED COMPANIES.

       (a) Definitions.--Section 2(a) of the Sarbanes-Oxley Act of 
     2002 (15 U.S.C. 7201) is amended by adding at the end the 
     following:
       ``(18) Critical information system.--The term `critical 
     information system' means a set of activities--
       ``(A) involving people, processes, data, or technology; and
       ``(B) that enable an issuer to obtain, generate, use, and 
     communicate transactions and information in pursuit of the 
     core business objectives of the issuer.
       ``(19) Information security control.--The term `information 
     security control' means a safeguard or countermeasure that 
     is--
       ``(A) prescribed for an information system or an 
     organization; and
       ``(B) designed to--
       ``(i) protect the confidentiality, integrity, and 
     availability of information; and
       ``(ii) meet a set of defined security requirements.
       ``(20) Cybersecurity risk.--The term `cybersecurity risk' 
     means a significant vulnerability to, or a significant 
     deficiency in, the security and defense activities of an 
     information system.''.
       (b) Corporate Responsibility for Financial Reports and 
     Critical Information Systems.--
       (1) In general.--Section 302 of the Sarbanes-Oxley Act of 
     2002 (15 U.S.C. 7241) is amended--
       (A) in the section heading, by inserting ``and critical 
     information systems'' after ``reports''; and
       (B) in subsection (a)--
       (i) in the matter preceding paragraph (1), by striking 
     ``and the principal financial officer or officers'' and 
     inserting the following: ``, the principal financial officer 
     or officers, and the principal security, risk, or information 
     security officer or officers'';
       (ii) in paragraph (4)--

       (I) in subparagraph (A), by inserting ``, including 
     information security controls'' after ``internal controls'';
       (II) in subparagraph (B), by inserting ``, including 
     information security controls,'' after ``internal controls'';
       (III) in subparagraph (C), by inserting ``, including 
     information security controls,'' after ``internal controls''; 
     and
       (IV) in subparagraph (D), by inserting ``, including 
     information security controls,'' after ``internal controls'';

       (iii) in paragraph (5)(A), by inserting ``and all 
     significant cybersecurity risks in the critical information 
     systems of the issuer'' after ``internal controls''; and
       (iv) in paragraph (6)--

       (I) by inserting ``, including information security 
     controls,'' after ``significant changes in internal 
     controls'';
       (II) by inserting ``, including information security 
     controls,'' after ``could significantly affect internal 
     controls''; and
       (III) by striking ``significant deficiencies and'' and 
     inserting the following: ``cybersecurity risks, significant 
     deficiencies, and''.

       (2) Clerical amendment.--The table of contents for the 
     Sarbanes-Oxley Act of 2002 (15 U.S.C. 7201 note) is amended 
     by striking the item relating to section 302 and inserting 
     the following:

``Sec. 302. Corporate responsibility for financial reports and critical 
              information systems.''.
       (c) Management Assessments of Internal Controls and 
     Critical Information Systems.--
       (1) In general.--Section 404 of the Sarbanes-Oxley Act of 
     2002 (15 U.S.C. 7262) is amended--
       (A) in the section heading, by inserting ``and critical 
     information systems'' after ``controls'';
       (B) in subsection (a)--
       (i) in paragraph (1), by striking ``and'' at the end;
       (ii) in paragraph (2), by striking ``of the issuer for 
     financial reporting.'' and inserting the following: ``of the 
     issuer for financial reporting and for maintaining internal 
     information security controls; and''; and
       (iii) by adding at the end the following:
       ``(3) state the responsibility of management for 
     establishing and maintaining adequate internal information 
     security controls, which shall include penetration testing, 
     as applicable.'';
       (C) by redesignating subsection (c) as subsection (d);
       (D) by inserting after subsection (b) the following:
       ``(c) Information Security Control Evaluation and 
     Reporting.--With respect to the internal information security 
     control assessment required by subsection (a), any third-
     party information security firm that prepares or issues a 
     cyber or information security risk assessment for the issuer, 
     other than an issuer that is an emerging growth company (as 
     defined in section 3 of the Securities Exchange Act of 1934 
     (15 U.S.C. 78c)), shall attest to, and report on, the 
     assessment made by the management of the issuer. An 
     attestation made under this subsection shall be made in 
     accordance with standards for attestation engagements issued 
     or adopted by the Board. Any such attestation shall not be 
     the subject of a separate engagement.'';
       (E) in subsection (d), as so redesignated, by striking 
     ``Subsection (b)'' and inserting ``Subsections (b) and (c)''; 
     and
       (F) by adding at the end the following:
       ``(e) Guidance on Information Security Reporting.--The 
     Commission shall issue guidance regarding how to describe 
     information security issues under this section in a manner 
     that does not compromise the security controls of the 
     applicable reporting entity.''.
       (2) Clerical amendment.--The table of contents for the 
     Sarbanes-Oxley Act of 2002 (15 U.S.C. 7201 note) is amended 
     by striking the item relating to section 404 and inserting 
     the following:

``Sec. 404. Management assessment of internal controls and critical 
              information systems.''.
                                 ______