The final rules require annual
disclosure of a registrant’s processes, if any, for assessing,
identifying, and managing material risks from cybersecurity
threats, as well as description of whether any risks from
cybersecurity threats, including as a result of previous
cybersecurity incidents, have materially affected or are reasonably
likely to materially affect the registrant. The final rules also
require a description of the board of directors’ oversight of risks
from cybersecurity threats, and a description of management’s role
in assessing and managing the registrant’s material risks from
cybersecurity threats. The Commission estimates that the final
rules will result in an increase in the paperwork burden of
affected entities. For purposes of the PRA, the Commission
estimates that for Form 10-K the final rules will result in an
increase of 62,190 burden hours and $12,438,000 for the services of
outside professionals.
On behalf of this Federal agency, I certify that
the collection of information encompassed by this request complies
with 5 CFR 1320.9 and the related provisions of 5 CFR
1320.8(b)(3).
The following is a summary of the topics, regarding
the proposed collection of information, that the certification
covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a
benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control
number;
If you are unable to certify compliance with any of
these provisions, identify the item by leaving the box unchecked
and explain the reason in the Supporting Statement.