We in Telegram
Add news
March 2010 April 2010 May 2010 June 2010 July 2010
August 2010
September 2010 October 2010
November 2010
December 2010
January 2011
February 2011 March 2011 April 2011 May 2011 June 2011 July 2011 August 2011 September 2011 October 2011 November 2011 December 2011 January 2012 February 2012 March 2012 April 2012 May 2012 June 2012 July 2012 August 2012 September 2012 October 2012 November 2012 December 2012 January 2013 February 2013 March 2013 April 2013 May 2013 June 2013 July 2013 August 2013 September 2013 October 2013 November 2013 December 2013 January 2014 February 2014 March 2014 April 2014 May 2014 June 2014 July 2014 August 2014 September 2014 October 2014 November 2014 December 2014 January 2015 February 2015 March 2015 April 2015 May 2015 June 2015 July 2015 August 2015 September 2015 October 2015 November 2015 December 2015 January 2016 February 2016 March 2016 April 2016 May 2016 June 2016 July 2016 August 2016 September 2016 October 2016 November 2016 December 2016 January 2017 February 2017 March 2017 April 2017 May 2017 June 2017 July 2017 August 2017 September 2017 October 2017 November 2017 December 2017 January 2018 February 2018 March 2018 April 2018 May 2018 June 2018 July 2018 August 2018 September 2018 October 2018 November 2018 December 2018 January 2019 February 2019 March 2019 April 2019 May 2019 June 2019 July 2019 August 2019 September 2019 October 2019 November 2019 December 2019 January 2020 February 2020 March 2020 April 2020 May 2020 June 2020 July 2020 August 2020 September 2020 October 2020 November 2020 December 2020 January 2021 February 2021 March 2021 April 2021 May 2021 June 2021 July 2021 August 2021 September 2021 October 2021 November 2021 December 2021 January 2022 February 2022 March 2022 April 2022 May 2022 June 2022 July 2022 August 2022 September 2022 October 2022 November 2022 December 2022 January 2023 February 2023 March 2023 April 2023 May 2023 June 2023 July 2023 August 2023 September 2023 October 2023 November 2023 December 2023 January 2024 February 2024 March 2024 April 2024
News Every Day |

Navigating the SEC Cybersecurity Ruling

3

The latest SEC ruling on cybersecurity will almost certainly have an impact on risk management and post-incident disclosure, and CISOs will need to map this to their specific environments and tooling. I asked our cybersecurity analysts Andrew Green, Chris Ray, and Paul Stringfellow what they thought, and I amalgamated their perspectives.

What Is the Ruling?

The new SEC ruling requires disclosure following an incident at a publicly traded company. This should come as no surprise to any organization already dealing with data protection legislation, such as the GDPR in Europe or California’s CCPA. The final rule has two requirements for public companies:

  • Disclosure of material cybersecurity incidents within four business days after the company determines the incident is material.
  • Disclosure annually of information about the company’s cybersecurity risk management, strategy, and governance.

The first requirement is similar to what GDPR enforces, that breaches must be reported within a set time (72 hours for GDPR, 96 for SEC). To do this, you need to know when the breach happened, what was contained in the breach, who it impacted, and so on. And keep in mind that the 96 hours begins not when a breach is first discovered, but when it is determined to be material.

The second part of the SEC ruling relates to annual reporting of what risks a company has and how they are being addressed. This doesn’t create impossible hurdles—for example, it’s not a requirement to have a security expert on the board. However, it does confirm a level of expectation: companies need to be able to show how expertise has come into play and is acted on at board level.

What are Material Cybersecurity Incidents?

Given the reference to “material” incidents, the SEC ruling includes a discussion of what materiality means: simply put, if your business feels it’s important enough to take action on, then it’s important enough to disclose. This does beg the question of how the ruling might be gamed, but we don’t advise ignoring a breach just to avoid potential disclosure.

In terms of applicable security topics to help companies implement a solution to handle the ruling, this aligns with our research on proactive detection and response (XDR and NDR), as well as event collation and insights (SIEM) and automated response (SOAR). SIEM vendors, I reckon, would need very little effort to deliver on this, as they already focus on compliance with many standards. SIEM also links to operational areas, such as incident management.

What Needs to be Disclosed in the Annual Reporting?

The ruling doesn’t constrain how security is done, but it does need the mechanisms used to be reported. The final rule focuses on disclosing management’s role in assessing and managing material risks from cybersecurity threats, for example.

In research terms, this relates to topics such as data security posture management (DSPM), as well as other posture management areas. It also touches on governance, compliance, and risk management, which is hardly surprising. Yes, indeed, it would be beneficial to all if overlaps were reduced between top-down governance approaches and middle-out security tooling.

What Are the Real-World Impacts?

Overall, the SEC ruling looks to balance security feasibility with action—the goal is to reduce risk any which way, and if tools can replace skills (or vice versa), the SEC will not mind. While the ruling overlaps with GDPR in terms of requirements, it is aimed at different audiences. The SEC ruling’s aim is to enable a consistent view for investors, likely so they can feed into their own investment risk planning. It therefore feels less bureaucratic than GDPR and potentially easier to follow and enforce.

Not that public organizations have any choice, in either case. Given how hard the SEC came down following the SolarWinds attack, these aren’t regulations any CISO will want to ignore.

The post Navigating the SEC Cybersecurity Ruling appeared first on Gigaom.

Симферополь

Выставка-панорама героической истории "Вехи памяти и славы" ко Дню Победы в Великой Отечественной войне

China’s Huawei launches new software brand for intelligent driving

NYU Hospital on Long Island performs miraculous surgery

Fans slam ‘worst thing I’ve ever seen from EFL ref’ as John Eustace sent off after heated touchline bust-up

Chat log from R7 of 2024: Gold Coast vs West Coast

Ria.city






Read also

Indonesian ‘Ring of Fire’ volcano erupts AGAIN forcing thousands to flee their homes & closing international airport

WATCH: Nancy Pelosi SNAPS at MSNBC’s Katy Tur After Being Fact-Checked in Real Time About Trump’s Jobs Numbers (VIDEO)

New York DA issues apology after being caught berating police during traffic stop: 'I'm disciplining myself'

News, articles, comments, with a minute-by-minute update, now on Today24.pro

News Every Day

NYU Hospital on Long Island performs miraculous surgery

Today24.pro — latest news 24/7. You can add your news instantly now — here


News Every Day

Tyson Fury vs Oleksandr Usyk undercard: Who is fighting on huge Saudi bill?



Sports today


Новости тенниса
Рафаэль Надаль

Теннисист Надаль навестил в больнице 16-летнюю российскую теннисистку Корнееву



Спорт в России и мире
Москва

Вокруг парка на электромобиле: что будет доступно напрокат в Москве



All sports news today





Sports in Russia today

Москва

Хоккейный клуб из Балашихи выиграл Кубок Регионов


Новости России

Game News

Шапки женские на Wildberries — скидки от 398 руб. (на новые оттенки)


Russian.city


Москва

Тарифы речного электротранспорта в Москве изменятся с 1 мая


Губернаторы России
Бато Багдаев

Театр, искуство, Россия и дети: кукольная фотосессия в Бурятии


Мизулина попросит СК проверить рэпершу Hofmannita из-за поцелуев с девушками

Шапки женские на Wildberries — скидки от 398 руб. (на новые оттенки)

Электрокроссовер Voyah Free получил новую версию для России. Ее представили в Москве

Тарифы речного электротранспорта в Москве изменятся с 1 мая


Лепс отдыхает: звезда «Пацанок» Михеева била телефоны фанатов на концерте в Москве

звезды шоу-бизнеса посетили весеннюю неделю моды estet fashion week

Певец Стас Михайлов заявил, что в детстве пел шансон заключенному за деньги

Сергей Трофимов выступит с летним концертом в Зеленом Театре ВДНХ


Шикарный и практичный стиль Елены Джокович из базовых вещей

16-летняя теннисистка Андреева обновила рекорд турниров WTA-1000

Рублёв победил Давидович-Фокину в 3-м круге «Мастерса» в Мадриде, отыгравшись с 0:5 на тай-брейке

Россиянка Михайлова стала чемпионкой Франции по настольному теннису



Хоккейный клуб из Балашихи выиграл Кубок Регионов

Эхо стрельбы под Цимлянском долетело до Москвы

Вокруг парка на электромобиле: что будет доступно напрокат в Москве

Героическое участие армян в СВО. Часть третья


Вечная любовь Валерия Гаркалина

Частота страховых случаев по ОСАГО для такси в 6,6 раза выше, чем по полисам на другие легковые машины – ЦБ РФ

Сергей Собянин. Главное за день

«Динамо» подложило под «Зенит» бомбу! «Краснодар» может возглавить РПЛ за четыре тура до конца


В России отмечают День пожарной охраны

Жителей Москвы предупредили о притворяющихся коммунальщиками мошенниках

Папа прокурор, который отмажет? На историческую родину вместе с папой! Навсегда!

Представители Самарской области – финалисты программы «Лига экскурсоводов»



Путин в России и мире






Персональные новости Russian.city
Певец

Певец Прохор Шаляпин вызвал слухи о помолвке, выложив фото с кольцом



News Every Day

Fans slam ‘worst thing I’ve ever seen from EFL ref’ as John Eustace sent off after heated touchline bust-up




Friends of Today24

Музыкальные новости

Персональные новости