SEC Cybersecurity Disclosure Rules
What a public company must tell investors: a material cybersecurity incident on Form 8-K Item 1.05 within four business days, and its risk-management and board oversight annually under Reg S-K Item 106.
Release Nos. 33-11216; 34-97989 · US Securities and Exchange Commission · published 2023-07-26
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
SEC Cybersecurity Disclosure Rules is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Named and tracked only; disclosure obligations not modelled as a control catalog.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Incident materiality determination · Form 8-K Item 1.05 · Regulation S-K Item 106 · Board oversight disclosure · Inline XBRL tagging
- Applies to
- public companies · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-06
03Version ledger
| Release Nos. 33-11216; 34-97989 | Current edition | 2023-07-26 |
06Related frameworks
- Sarbanes-Oxley ICFRSOX Sections 302 and 404; PCAOB AS 2201
Also applies to public companies · The US public-company regime for management assessment and, where applicable, independent audit of internal control over financial reporting. SOX does not prescribe one universal IT-control catalog, and registry tracking is not an audit opinion.
- COBIT 2019 (SOX ITGC reference)COBIT 2019
Also applies to public companies · SOX requires management and auditor assessment of internal control over financial reporting but does not prescribe one IT-control catalog. COBIT 2019 is licensed governance guidance often used to design and map IT general controls; neither this record nor COBIT is a SOX certification.
Also applies to public companies · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.
- APRA CPS 2302026 determination (effective 2026-07-01)
Same framework family · Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.