On the recordDecember 11, 2014
I thank Senator Johnson for his interest and support for this legislation and for his shared interest in strengthening cyber security. I also thank my colleague from South Dakota for drawing attention to the potential impact of this provision on financial regulatory authorities under the Banking Committee's jurisdiction, including those of the Consumer Financial Protection Bureau and the prudential regulators. I would like to assure the Senator that the consensus-based voluntary process for developing cyber security standards established in Title I of this bill is not intended to alter or limit financial regulatory agencies' regulatory authority in any way. Title I, particularly new section (e)(2) of the National Institute of Standards and Technology Act, encourages private entities to participate in NIST's standards development process, but is in no way a ``safe harbor'' for participants who are subject to the jurisdiction of financial regulatory agencies. An entity that participates in the standards development process established in Title I is still fully subject to the regulations, supervision, and other requirements of its financial regulatory agency. Sharing information with NIST as part of the process established in Title I is not a valid basis for withholding information from a regulator, including information about cyber threats. NIST is the Federal government's premier science and standards agency.…





