Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Retain or restrain access logs?
Mark Rasch, 2006-06-12

A recent proposal by the U.S. Department of Justice that would mandate Internet Service Providers to retain certain records represents a dangerous trend of turning private companies into proxies for law enforcement or intelligence agencies against the interests of their clients or customers.

Comments Mode:
Retain or restrain access logs? 2006-06-12
Bob Radvanovsky
Retain or restrain access logs? 2006-06-12
Bob Radvanovsky
Retain or restrain access logs? 2006-06-13
Anonymous
Retain or restrain access logs? 2006-06-29
Jimmy Weg (1 replies)
Retain or restrain access logs? 2006-07-17
Anonymous
If they are going to require companies to retain these records then they also need to require that the companies due diligence and protect via encryption any records retained. Moreover the companies should be held to the same high standard of maintaining a clear chain of custody for records that are retained to ensure that the evidence presented or used for investigations has not been tampered with. The companies given the recent mishandling of data and the hourly loss or compromise of sensitive information some of which is covered by the Privacy Act should be required to comply with the requirements for FISMA and the recent OMB guidelines - for encrypting and securing data to include any and all outsourced data. Oh wait the federal government can't even do that....nevermind. It would be nice if someone thought these things through before making well intended but misguided decisions.


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/406/33816#33816
Retain or restrain access logs? 2006-07-19
Carl Shannon







 

Privacy Statement
Copyright 2009, SecurityFocus