Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Strict liability for data breaches?
Mark Rasch, 2006-02-20

A recent case involving a stolen laptop containing 550,000 people's full credit information sheds new night on what "reasonable" protections a company must make to secure its customer data - and what customers need to prove in order to sue for damages.

Comments Mode:
Strict liability for data breaches? 2006-02-21
Adam (1 replies)
Re: Strict liability for data breaches? 2006-02-22
Mark D. Rasch (1 replies)
Strict liability for data breaches? 2006-02-21
Jim (Sydney, Australia) (1 replies)
Strict liability for data breaches? 2006-02-21
Ron Jennings (2 replies)
Re: Strict liability for data breaches? 2006-02-23
Doug
I'm not defending Brazos on this one but your comment is a little unreasonable. How many people do you know that lock their laptops up in a safe at the end of the day? The more appropriate control would be desktop encryption or not having that data on a laptop in the first place. But anyone who works in the security industry knows that desktop encryption isn't the most widely used technology yet. And who's fault is that? Its easy for security professionals to call out companies for doing seemingly stupid things, but maybe instead of criticizing, we should do a better job educating.

Guin picked the wrong battle. He couldn't prove his data was on the laptop nor could he prove any injury. Data breach laws are still maturing. Challenging the law in a case where the laptop was stolen from a house probably wasn't the best move. There are numerous companies out there that have done much worse.

Whether the defendent was truly negligent or just under educated on proper security controls will never be known. With laws in their current form, I think the courts made the right decision.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/387/33174#33174
Strict liability for data breaches? 2006-02-21
Stephen T (1 replies)
Re: Strict liability for data breaches? 2006-02-22
Anonymous (1 replies)
Shameful ruling 2006-02-22
Torquemada
Strict liability for data breaches? 2006-02-22
Frank, Hsv, AL
Strict liability for data breaches? 2006-02-23
Anonymous (2 replies)
Re: Strict liability for data breaches? 2006-02-23
Mark D. Rasch
Re: Strict liability for data breaches? 2006-02-23
Anonymous (1 replies)
Judge Made Law 2006-02-24
Mark D. Rasch (1 replies)
Re: Judge Made Law 2006-03-05
Anonymous (1 replies)
Re: Re: Judge Made Law 2006-03-15
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus