← Independent regulator rules (SEC/Fed/FDIC/SBA/FTC/NCUA/CPSC/FHFA/EEOC/NLRB)

Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure

SEC · final-rule · Published 2023-08-04 · Effective 2023-09-05 · 88 FR 51896

Document

Document number
2023-16194
Federal Register citation
88 FR 51896
CFR reference
17 CFR 229
Type
Rule
Action
Final rule.
Category
final-rule
Agency
US Securities and Exchange Commission
Publication date
2023-08-04
Effective date
2023-09-05
Docket
Release Nos. 33-11216

Abstract

The Securities and Exchange Commission ("Commission") is adopting new rules to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance, and incidents by public companies that are subject to the reporting requirements of the Securities Exchange Act of 1934. Specifically, we are adopting amendments to require current disclosure about material cybersecurity incidents. We are also adopting rules requiring periodic disclosures about a registrant's processes to assess, identify, and manage material cybersecurity risks, management's role in assessing and managing material cybersecurity risks, and the board of directors' oversight of cybersecurity risks. Lastly, the final rules require the cybersecurity disclosures to be presented in Inline eXtensible Business Reporting Language ("Inline XBRL").

Source

Authoritative
Federal Register document
Machine
JSON-LD · Markdown