Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Transcript: Debate on the foreign intelligence surveillance act - El Paso Times
  • Updating Maps on the Spot and Sharing the Fixes
  • Critical FBI Network Full of Security Holes, Government Auditors Report
  • Rulings Leave Online Student Speech Rights Unresolved
  • Do We Really Need a Security Industry?
  • Big Brother! ActyMac DutyWatch spies on your employees
  • TSA Launches Blog To Reach Out to Shoe-Removing Travelers

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Data security: What the law requires of IT

Submitted by MacRonin on August 30, 2008 - 1:44am
  • Companies
  • Hmmm
  • How-To
  • Industry
  • Laws
  • Legal
  • Privacy
  • Remember
  • Security
  • Standards

Data security: What the law requires of IT - Via InfoWorld | Analysis | 2008-08-18 | By Thomas J. Smedinghoff :

IT's legal duty to secure sensitive data is complex and continuously evolving. Here's how to avoid the legal ramifications of a data breach 

        
For most IT organizations, securing corporate data against compromise is priority No. 1. Girding the enterprise against breaches is a constant, thankless task requiring foresight, vigilance, and much in the way of IT expenditures. Keep up with the latest threats, or find your company in the headlines -- and your job on the line.

Such is the shift in attitude toward security in IT. In the Wild West, when Jesse James and Butch Cassidy robbed banks, we felt sorry for the banks and hunted down the outlaws. Today, when someone breaks into a company's computer system, our response is totally different: We blame the company for failing to provide adequate security.

Codifying this shift is a complex blend of laws and regulations enacted to protect the confidentiality and integrity of valuable personal data and the individuals who might be harmed by a breach. Not complying with these mandates can result in grave legal consequences should your organization suffer a breach.

Here you will find a framework for understanding these legal initiatives, which, when viewed as a group, impose two key legal obligations on your organization: the duty to implement reasonable security measures to protect data, and the duty to disclose breaches to those affected.

The duty to provide security
There is no single statute or regulation that governs all of your company's information security obligations. Instead, an ever-expanding patchwork of legal requirements is continuously evolving to impose a comprehensive duty to provide "reasonable" or "appropriate" security to protect your corporate data.

At the center of this patchwork are numerous state and federal regulations: privacy laws that require companies to protect personal data; e-transaction laws that govern the accessibility and integrity of electronic records; corporate governance legislation that requires appropriate controls to protect public companies and their shareholders, investors, and business partners; and unfair-business-practice laws now interpreted to include failure to provide adequate security as an unfair business practice.

(Read Original Article - Via InfoWorld | Analysis | 2008-08-18 | By Thomas J. Smedinghoff.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • FBI Hoaxes Boost Online Fraud
  • NetFlix Cancels Recommendation Contest After Privacy Lawsuit
  • Advertising - Instant Ads Set the Pace on the Web
  • Best Practices for Government Datasets: Wrap-Up
  • TJX Hacking Conspirator Gets 4 Years
  • The Beginning of the End of Data Retention
  • Wanted: Trust Detector
  • Wikibooks Cryptography Textbook
  • Feds: TSA Worker Tried to Sabotage Terror Database
  • Hi-tech governments growing keener on snooping, says report
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.