[Congressional Record Volume 166, Number 116 (Wednesday, June 24, 2020)]
[Senate]
[Page S3233]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 1711. Mr. KING submitted an amendment intended to be proposed by
him to the bill S. 4049, to authorize appropriations for fiscal year
2021 for military activities of the Department of Defense, for military
construction, and for defense activities of the Department of Energy,
to prescribe military personnel strengths for such fiscal year, and for
other purposes; which was ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. ___. CYBERSECURITY REPORTING REQUIREMENTS FOR PUBLICLY
TRADED COMPANIES.
(a) Definitions.--Section 2(a) of the Sarbanes-Oxley Act of
2002 (15 U.S.C. 7201) is amended by adding at the end the
following:
``(18) Critical information system.--The term `critical
information system' means a set of activities--
``(A) involving people, processes, data, or technology; and
``(B) that enable an issuer to obtain, generate, use, and
communicate transactions and information in pursuit of the
core business objectives of the issuer.
``(19) Information security control.--The term `information
security control' means a safeguard or countermeasure that
is--
``(A) prescribed for an information system or an
organization; and
``(B) designed to--
``(i) protect the confidentiality, integrity, and
availability of information; and
``(ii) meet a set of defined security requirements.
``(20) Cybersecurity risk.--The term `cybersecurity risk'
means a significant vulnerability to, or a significant
deficiency in, the security and defense activities of an
information system.''.
(b) Corporate Responsibility for Financial Reports and
Critical Information Systems.--
(1) In general.--Section 302 of the Sarbanes-Oxley Act of
2002 (15 U.S.C. 7241) is amended--
(A) in the section heading, by inserting ``and critical
information systems'' after ``reports''; and
(B) in subsection (a)--
(i) in the matter preceding paragraph (1), by striking
``and the principal financial officer or officers'' and
inserting the following: ``, the principal financial officer
or officers, and the principal security, risk, or information
security officer or officers'';
(ii) in paragraph (4)--
(I) in subparagraph (A), by inserting ``, including
information security controls'' after ``internal controls'';
(II) in subparagraph (B), by inserting ``, including
information security controls,'' after ``internal controls'';
(III) in subparagraph (C), by inserting ``, including
information security controls,'' after ``internal controls'';
and
(IV) in subparagraph (D), by inserting ``, including
information security controls,'' after ``internal controls'';
(iii) in paragraph (5)(A), by inserting ``and all
significant cybersecurity risks in the critical information
systems of the issuer'' after ``internal controls''; and
(iv) in paragraph (6)--
(I) by inserting ``, including information security
controls,'' after ``significant changes in internal
controls'';
(II) by inserting ``, including information security
controls,'' after ``could significantly affect internal
controls''; and
(III) by striking ``significant deficiencies and'' and
inserting the following: ``cybersecurity risks, significant
deficiencies, and''.
(2) Clerical amendment.--The table of contents for the
Sarbanes-Oxley Act of 2002 (15 U.S.C. 7201 note) is amended
by striking the item relating to section 302 and inserting
the following:
``Sec. 302. Corporate responsibility for financial reports and critical
information systems.''.
(c) Management Assessments of Internal Controls and
Critical Information Systems.--
(1) In general.--Section 404 of the Sarbanes-Oxley Act of
2002 (15 U.S.C. 7262) is amended--
(A) in the section heading, by inserting ``and critical
information systems'' after ``controls'';
(B) in subsection (a)--
(i) in paragraph (1), by striking ``and'' at the end;
(ii) in paragraph (2), by striking ``of the issuer for
financial reporting.'' and inserting the following: ``of the
issuer for financial reporting and for maintaining internal
information security controls; and''; and
(iii) by adding at the end the following:
``(3) state the responsibility of management for
establishing and maintaining adequate internal information
security controls, which shall include penetration testing,
as applicable.'';
(C) by redesignating subsection (c) as subsection (d);
(D) by inserting after subsection (b) the following:
``(c) Information Security Control Evaluation and
Reporting.--With respect to the internal information security
control assessment required by subsection (a), any third-
party information security firm that prepares or issues a
cyber or information security risk assessment for the issuer,
other than an issuer that is an emerging growth company (as
defined in section 3 of the Securities Exchange Act of 1934
(15 U.S.C. 78c)), shall attest to, and report on, the
assessment made by the management of the issuer. An
attestation made under this subsection shall be made in
accordance with standards for attestation engagements issued
or adopted by the Board. Any such attestation shall not be
the subject of a separate engagement.'';
(E) in subsection (d), as so redesignated, by striking
``Subsection (b)'' and inserting ``Subsections (b) and (c)'';
and
(F) by adding at the end the following:
``(e) Guidance on Information Security Reporting.--The
Commission shall issue guidance regarding how to describe
information security issues under this section in a manner
that does not compromise the security controls of the
applicable reporting entity.''.
(2) Clerical amendment.--The table of contents for the
Sarbanes-Oxley Act of 2002 (15 U.S.C. 7201 note) is amended
by striking the item relating to section 404 and inserting
the following:
``Sec. 404. Management assessment of internal controls and critical
information systems.''.
______