Auditen
Home / Frameworks / SEC Cyber Disclosure / Board oversight and management's role

Board oversight and management's role

The SEC requires public companies to disclose the processes by which their board of directors oversees cybersecurity risks and the specific role management plays in assessing and managing those risks. This means you must document and describe who is responsible for cyber risk, how information flows from technical teams to leadership, and how the board exercises its oversight.

What it means

In practice, this requirement moves cybersecurity from a purely technical "IT issue" to a corporate governance obligation. The SEC wants to see that there is a structured relationship between the people managing the day-to-day security operations (management) and those responsible for the company's overall risk appetite and strategic direction (the board).

The scope includes identifying which management positions or committees are tasked with cybersecurity duties and describing the board’s expertise in this area. If the board relies on a specific committee or external experts to provide oversight, that mechanism must be clearly defined and operationalized.

Crucially, this is about the *process* of oversight. It is not enough to have a CISO; the organization must demonstrate how that CISO informs the board and how the board uses that information to make risk-based decisions regarding materiality and resource allocation.

How to meet it

Evidence an auditor asks for

  • Board and committee meeting minutes showing cybersecurity was discussed, questions were asked, and decisions were made.
  • Updated Board Charters or Committee Charters that explicitly include oversight of cybersecurity risk as a core responsibility.
  • Organizational charts and job descriptions detailing the reporting lines between the CISO/security team and executive leadership/the board.
  • Copies of management reports or dashboards presented to the board that track key cyber risk indicators and mitigation progress.
  • The written policy or procedure used to determine if a cybersecurity event is "material" and requires escalation to the board.

Common pitfalls

  • Treating oversight as a "checkbox" exercise where the board receives a report but there is no evidence of active questioning or governance.
  • Failing to document the *process* of communication, leaving it to informal conversations that cannot be evidenced during an audit.
  • Over-reliance on technical jargon in reports to the board, which prevents directors from exercising meaningful oversight because they do not understand the business risk.
  • Lack of alignment between the reported governance structure and the actual daily operational reality of how risks are escalated.