Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Strict liability for data breaches?
Mark Rasch, 2006-02-20

A recent case involving a stolen laptop containing 550,000 people's full credit information sheds new night on what "reasonable" protections a company must make to secure its customer data - and what customers need to prove in order to sue for damages.

Comments Mode:
Strict liability for data breaches? 2006-02-21
Adam (1 replies)
Re: Strict liability for data breaches? 2006-02-22
Mark D. Rasch (1 replies)
Strict liability for data breaches? 2006-02-21
Jim (Sydney, Australia) (1 replies)
Strict liability for data breaches? 2006-02-21
Stephen T (1 replies)
Re: Strict liability for data breaches? 2006-02-22
Anonymous (1 replies)
Shameful ruling 2006-02-22
Torquemada
Strict liability for data breaches? 2006-02-22
Frank, Hsv, AL
Strict liability for data breaches? 2006-02-23
Anonymous (2 replies)
Re: Strict liability for data breaches? 2006-02-23
Mark D. Rasch
Re: Strict liability for data breaches? 2006-02-23
Anonymous (1 replies)
Judge Made Law 2006-02-24
Mark D. Rasch (1 replies)
Virtually all of tort law is judge made. There are almost no statutes on the books proscribing what constitutes "negligence" or "reasonable care." Indeed, the entire CONCEPT of negligence exists only in the common law (judge made.)

Indeed, the LAW doesnt need to be changed -- its relatively simple - DO WHAT IS REASONABLE. The problem is, is "reasonable" defined by what IS being done, or what can reasonably be done? The legislature can mandate specific things (e.g., seat belts), but thats probably not a good approach for network security, since FAILING to mention some new technology might convince people that they need NOT apply that technology. Indeed, most regulated entities would prefer a mere reasonableness standard, other than legislatures defining specific (and outdated) procedures. We actually need better informed litigators, not more laws. At least in my opion. More jobs for lawyers -- that cant be bad!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/387/33181#33181
Re: Judge Made Law 2006-03-05
Anonymous (1 replies)
Re: Re: Judge Made Law 2006-03-15
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus