The Securities and Exchange Commission issued a lengthy “guidance” document on October 13 outlining how and when publicly traded companies should report hacking incidents and cybersecurity risk. Some major companies that are known to have had significant digital security breaches have said nothing about the incidents in regulatory filings. Senator Rockefeller is taking a closer look at the SEC rules and wants the full commission to issue guidance on when companies must disclose cybersecurity risks and what theyre doing to minimize those risks. The SEC language may prompt whistleblower reports from dissatisfied IT and security staff.”]
Source: https://taosecurity.blogspot.com/2012/05/sec-guidance-is-really-big-deal.html