Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Strict liability for data breaches?
Mark Rasch, 2006-02-20

A recent case involving a stolen laptop containing 550,000 people's full credit information sheds new night on what "reasonable" protections a company must make to secure its customer data - and what customers need to prove in order to sue for damages.

Comments Mode:
Strict liability for data breaches? 2006-02-21
Adam (1 replies)
Re: Strict liability for data breaches? 2006-02-22
Mark D. Rasch (1 replies)
Strict liability for data breaches? 2006-02-21
Jim (Sydney, Australia) (1 replies)
Re: Strict liability for data breaches? 2006-02-22
Anonymous
Lovely - I work at a credit card processing company (not CardSystems!). We have annual training for all employees on PCI - Payment Card Industry security regs. Our IT department is required to conduct periodic security tests. All card numbers (PAN - Personal Account Number) on non-production systems are required to be masked (partially obscured) in every table of every database. We are not allowed to retain any personally indentifiable information for more than the few seconds it takes to verify a transaction. Etc. Etc. I'm sure management here would like to eliminate those costs but it is required and should be required of any organization with this type of information. The really sad thing is, there are hundreds of spreadsheets with customer info floating around unsecured. All those online orders you submit through SSL? Some are probably re-typed into Excel, including those super-secret, never-to-be-stored CCV digits on the back of your card.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/387/33170#33170
Strict liability for data breaches? 2006-02-21
Stephen T (1 replies)
Re: Strict liability for data breaches? 2006-02-22
Anonymous (1 replies)
Shameful ruling 2006-02-22
Torquemada
Strict liability for data breaches? 2006-02-22
Frank, Hsv, AL
Strict liability for data breaches? 2006-02-23
Anonymous (2 replies)
Re: Strict liability for data breaches? 2006-02-23
Mark D. Rasch
Re: Strict liability for data breaches? 2006-02-23
Anonymous (1 replies)
Judge Made Law 2006-02-24
Mark D. Rasch (1 replies)
Re: Judge Made Law 2006-03-05
Anonymous (1 replies)
Re: Re: Judge Made Law 2006-03-15
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus