
SEC Cybersecurity Risk Governance Requirements - Christopher Hetner - CSP #122
About this episode
In April, the SEC is expected to finalize new rules on cybersecurity. The rules will require every publicly traded company to file disclosures with descriptions of their security strategy, governance, and risk management. Companies will need to explain to shareholders how they assess cyber risk, describe their security policies, and demonstrate a significant level of board oversight on cybersecurity issues. The SEC rules are qualitatively different from existing cyber regulatory frameworks, such as HIPAA and PCI DSS, which skew toward enforcing technical controls handled by the IT department. The SEC rules, in contrast, demand that C-suites and boards get more involved and demonstrate a strategic approach to managing cyber risk.
Visit https://securityweekly.com/csp for all the latest episodes!
Follow us on Twitter: https://www.twitter.com/cyberleaders
Follow us on LinkedIn: https://www.linkedin.com/company/cybersecuritycollaborative/
Show Notes: https://securityweekly.com/csp122
Get every episode summarized
Each time CISO Stories Podcast (Audio) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from CISO Stories Podcast (Audio)

Attack Surface Management - Matt Lea - CSP #227
CISO Stories Podcast (Audio)

Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Nea...
CISO Stories Podcast (Audio)

Critical Infrastructure: The Risk Hiding in Plain Sight - Jason Manar - CSP #225
CISO Stories Podcast (Audio)

IAM for MSSPs: The Hidden Risk of Blind Trust - Dustin Sachs - CSP #224
CISO Stories Podcast (Audio)