<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Resolution to Overturn SEC Cyber Disclosure Rule Introduced in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Resolution-to-Overturn-SEC-Cyber-Disclosure-Rule-Introduced/m-p/64783#M6540</link>
    <description>&lt;P&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;A &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A class="Hyperlink SCXW102205617 BCX0" href="https://garbarino.house.gov/sites/evo-subsites/garbarino.house.gov/files/evo-media-document/resolution-text-sec-cyber-rule-cra.pdf" target="_blank" rel="noreferrer noopener"&gt;&lt;SPAN class="TextRun Underlined SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0" data-ccp-charstyle="Hyperlink"&gt;joint resolution&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; was introduced by Representatives Andrew Garbarino (R-NY) &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;in the House &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;and Thom Tillis (R-NC) &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;in the&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; Senate&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;, &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;on November 14, &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW102205617 BCX0"&gt;2023&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; that, if passed, would overturn the Securities and Exchange Commission’s (SEC) recent&amp;nbsp; "&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A class="Hyperlink SCXW102205617 BCX0" href="https://www.sec.gov/files/rules/final/2023/33-11216.pdf" target="_blank" rel="noreferrer noopener"&gt;&lt;SPAN class="TextRun Underlined SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0" data-ccp-charstyle="Hyperlink"&gt;Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; final rules.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;ISC2 has previously expressed concerns over the new rules particularly, that they leave considerable ambiguity, especially &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;regarding&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; the definition and measure of risk, along with not making a definitive ruling on cybersecurity skills and experience requirements for public company boards. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;To be successful both t&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;he House and Senate must vote to approve the resolution and the president must sign it. So &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;far, during the current Executive administration, 7 CRA resolutions have been introduced, all have been&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; vetoed. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;Members should periodically review incident reporting processes against the SEC ruling to understand in advance what materiality means for their organization, and factor incident risk reporting into their processes. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;Several helpful ISC2 resources can be found &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;on ISC2 Insights&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;:&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;A class="Hyperlink SCXW102205617 BCX0" href="https://www.isc2.org/Insights/2023/11/Resolution-to-Overturn-SEC-Cyber-Disclosure-Rule-Introduced" target="_blank" rel="noreferrer noopener"&gt;&lt;SPAN class="TextRun Underlined SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0" data-ccp-charstyle="Hyperlink"&gt;https://www.isc2.org/Insights/2023/11/Resolution-to-Overturn-SEC-Cyber-Disclosure-Rule-Introduced&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;SPAN class="EOP SCXW102205617 BCX0" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2023 14:12:50 GMT</pubDate>
    <dc:creator>mborchardt</dc:creator>
    <dc:date>2023-11-21T14:12:50Z</dc:date>
    <item>
      <title>Resolution to Overturn SEC Cyber Disclosure Rule Introduced</title>
      <link>https://community.isc2.org/t5/Industry-News/Resolution-to-Overturn-SEC-Cyber-Disclosure-Rule-Introduced/m-p/64783#M6540</link>
      <description>&lt;P&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;A &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A class="Hyperlink SCXW102205617 BCX0" href="https://garbarino.house.gov/sites/evo-subsites/garbarino.house.gov/files/evo-media-document/resolution-text-sec-cyber-rule-cra.pdf" target="_blank" rel="noreferrer noopener"&gt;&lt;SPAN class="TextRun Underlined SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0" data-ccp-charstyle="Hyperlink"&gt;joint resolution&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; was introduced by Representatives Andrew Garbarino (R-NY) &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;in the House &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;and Thom Tillis (R-NC) &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;in the&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; Senate&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;, &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;on November 14, &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW102205617 BCX0"&gt;2023&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; that, if passed, would overturn the Securities and Exchange Commission’s (SEC) recent&amp;nbsp; "&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A class="Hyperlink SCXW102205617 BCX0" href="https://www.sec.gov/files/rules/final/2023/33-11216.pdf" target="_blank" rel="noreferrer noopener"&gt;&lt;SPAN class="TextRun Underlined SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0" data-ccp-charstyle="Hyperlink"&gt;Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; final rules.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;ISC2 has previously expressed concerns over the new rules particularly, that they leave considerable ambiguity, especially &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;regarding&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; the definition and measure of risk, along with not making a definitive ruling on cybersecurity skills and experience requirements for public company boards. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;To be successful both t&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;he House and Senate must vote to approve the resolution and the president must sign it. So &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;far, during the current Executive administration, 7 CRA resolutions have been introduced, all have been&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt; vetoed. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;Members should periodically review incident reporting processes against the SEC ruling to understand in advance what materiality means for their organization, and factor incident risk reporting into their processes. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="TextRun SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;Several helpful ISC2 resources can be found &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;on ISC2 Insights&lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0"&gt;:&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;A class="Hyperlink SCXW102205617 BCX0" href="https://www.isc2.org/Insights/2023/11/Resolution-to-Overturn-SEC-Cyber-Disclosure-Rule-Introduced" target="_blank" rel="noreferrer noopener"&gt;&lt;SPAN class="TextRun Underlined SCXW102205617 BCX0" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXW102205617 BCX0" data-ccp-charstyle="Hyperlink"&gt;https://www.isc2.org/Insights/2023/11/Resolution-to-Overturn-SEC-Cyber-Disclosure-Rule-Introduced&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;SPAN class="EOP SCXW102205617 BCX0" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 14:12:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Resolution-to-Overturn-SEC-Cyber-Disclosure-Rule-Introduced/m-p/64783#M6540</guid>
      <dc:creator>mborchardt</dc:creator>
      <dc:date>2023-11-21T14:12:50Z</dc:date>
    </item>
  </channel>
</rss>

