<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cybersecurity Expertise on the Board in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Cybersecurity-Expertise-on-the-Board/m-p/50619#M5765</link>
    <description>&lt;P&gt;A few news articles came out yesterday around the SEC's proposed rule changes, specifically section II. Proposed Amendments (E), on whether public companies will need to disclose if they have someone on their Board with cybersecurity expertise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.sec.gov/rules/proposed/2022/33-11038.pdf" target="_blank" rel="noopener"&gt;Proposed rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.forbes.com/sites/bobzukis/2022/04/18/the-sec-is-about-to-force-cisos-into-americas-boardrooms/?sh=10261a2368a9" target="_blank" rel="noopener"&gt;The SEC Is About To Force CISOs Into America’s Boardrooms (forbes.com)&lt;/A&gt; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For those that don't read the above links, 'cybersecurity expertise' is loosely defined as:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Whether&lt;/STRONG&gt; the director has prior work experience in cybersecurity, including, for&lt;BR /&gt;example, prior experience as an information security officer, security policy analyst,&lt;BR /&gt;security auditor, security architect or engineer, security operations or incident&lt;BR /&gt;response manager, or business continuity planner;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Whether&lt;/STRONG&gt; the director has obtained a certification or degree in cybersecurity; and&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Whether&lt;/STRONG&gt; the director has knowledge, skills, or other background in cybersecurity,&lt;BR /&gt;including, for example, in the areas of security policy and governance, risk&lt;BR /&gt;management, security assessment, control evaluation, security architecture and&lt;BR /&gt;engineering, security operations, incident handling, or business continuity planning.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There were also a few RFC's that I thought were interesting and might drive some further discussion here in the Community.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Would&lt;/STRONG&gt; proposed Item 407(j) disclosure provide information that investors would find useful? (Or if it would affect any decisions around using their services or products in your environment?)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Would&lt;/STRONG&gt;&lt;SPAN&gt; the Item 407(j) disclosure requirements have the unintended effect of undermining a&amp;nbsp;&lt;/SPAN&gt;company's cybersecurity defense efforts or otherwise impose undue burdens on companies?&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Should&lt;/STRONG&gt; any public companies be excluded? (Shortened for brevity)&lt;/LI&gt;&lt;LI&gt;And as always, any further thoughts from the Community on this issue.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Tue, 19 Apr 2022 14:28:40 GMT</pubDate>
    <dc:creator>tmekelburg1</dc:creator>
    <dc:date>2022-04-19T14:28:40Z</dc:date>
    <item>
      <title>Cybersecurity Expertise on the Board</title>
      <link>https://community.isc2.org/t5/Industry-News/Cybersecurity-Expertise-on-the-Board/m-p/50619#M5765</link>
      <description>&lt;P&gt;A few news articles came out yesterday around the SEC's proposed rule changes, specifically section II. Proposed Amendments (E), on whether public companies will need to disclose if they have someone on their Board with cybersecurity expertise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.sec.gov/rules/proposed/2022/33-11038.pdf" target="_blank" rel="noopener"&gt;Proposed rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.forbes.com/sites/bobzukis/2022/04/18/the-sec-is-about-to-force-cisos-into-americas-boardrooms/?sh=10261a2368a9" target="_blank" rel="noopener"&gt;The SEC Is About To Force CISOs Into America’s Boardrooms (forbes.com)&lt;/A&gt; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For those that don't read the above links, 'cybersecurity expertise' is loosely defined as:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Whether&lt;/STRONG&gt; the director has prior work experience in cybersecurity, including, for&lt;BR /&gt;example, prior experience as an information security officer, security policy analyst,&lt;BR /&gt;security auditor, security architect or engineer, security operations or incident&lt;BR /&gt;response manager, or business continuity planner;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Whether&lt;/STRONG&gt; the director has obtained a certification or degree in cybersecurity; and&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Whether&lt;/STRONG&gt; the director has knowledge, skills, or other background in cybersecurity,&lt;BR /&gt;including, for example, in the areas of security policy and governance, risk&lt;BR /&gt;management, security assessment, control evaluation, security architecture and&lt;BR /&gt;engineering, security operations, incident handling, or business continuity planning.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There were also a few RFC's that I thought were interesting and might drive some further discussion here in the Community.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Would&lt;/STRONG&gt; proposed Item 407(j) disclosure provide information that investors would find useful? (Or if it would affect any decisions around using their services or products in your environment?)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Would&lt;/STRONG&gt;&lt;SPAN&gt; the Item 407(j) disclosure requirements have the unintended effect of undermining a&amp;nbsp;&lt;/SPAN&gt;company's cybersecurity defense efforts or otherwise impose undue burdens on companies?&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Should&lt;/STRONG&gt; any public companies be excluded? (Shortened for brevity)&lt;/LI&gt;&lt;LI&gt;And as always, any further thoughts from the Community on this issue.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 19 Apr 2022 14:28:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Cybersecurity-Expertise-on-the-Board/m-p/50619#M5765</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2022-04-19T14:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cybersecurity Expertise on the Board</title>
      <link>https://community.isc2.org/t5/Industry-News/Cybersecurity-Expertise-on-the-Board/m-p/50680#M5776</link>
      <description>&lt;P&gt;If the board makes any budgetary recommendations then I think it would be prudent to have cyber security representation on there. You don't want cybersecurity to be underfunded because it's necessity was not understood.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 18:17:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Cybersecurity-Expertise-on-the-Board/m-p/50680#M5776</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2022-04-22T18:17:05Z</dc:date>
    </item>
  </channel>
</rss>

