DocuCrunch.com » Can Congress get data security law right?

Can Congress get data security law right?

May 24, 2010 by Steve Hannaford
Posted in: In this week's e-newsletter, Latest News & Views, Regulations & Compliance

A surprising 70% of data security professionals in a recent survey urged the federal government to pass national data security laws. But are the feds up to the task?

The survey, conducted for security audit toolmaker nCircle, talked to 257 experts nationwide.

One of the key reasons for a federal law is that state after state is now passing data collection and breach laws with different provisions, giving national companies an increasingly tangled set of requirement for customer consent, notification and liability when a data breach occurs.

“Security professionals know that allowing private industry to ‘self-regulate’ on security issues hasn’t worked so far,” stated nCircle CEO Abe Kleinfeld, and it’s unlikely to improve without some external stimulus. “A federal data breach law could become a catalyst for increased security investment and awareness for businesses of every size.”

But…

The big problem is passing any meaningful legislation in a U.S. Congress that is riven with partisan strife, powerful interest groups and vast technical ignorance.

The latest attempt at such a bill, the so-called Boucher Bill, drafted by several congressmen from both parties, deals with companies that gather and store information about consumers online, The draft bill has been submitted to get conversation started. Has it ever! The proposal has been strongly attacked by both corporate interests and by consumer groups.

Here’s a sample of the reactions:

  • The Direct Marketing Association is going ballistic over requirements that before companies collect marketing information on consumers, that they get the consent of that consumer.
  • The Progress and Freedom Association, an industry trade group, claimed that the bill would be the death of the “free” Internet.
  • The Electronic Privacy Information Center declared that the law doesn’t do anything but maintain the unsatisfactory status quo.
  • Consumer Action is complaining that the privacy provisions of the law are actually far weaker than those already in place for some states, and that the law would limit liability in cases where critical personal information leaks out and harms a consumer.

Companies like Microsoft and Google are holding their fire, “welcoming” the chance to discuss the bill. But you know that they and many others who have built a business on collecting such data have lobbyists lining up to write in exceptions to the already mild provisions of the bill.

Count us as cynical, but even if a law gets passed, it will be so watered-down and filled with loopholes that it will create more problems than it solves.

  • Share/Bookmark

DocuCrunch.com delivers the latest IT and Imaging news once a week to the inboxes of over 200,000 IT and Imaging professionals.

Click here to sign up and start your FREE subscription to DocuCrunch!

Tags: , ,


One Response to “Can Congress get data security law right?”

  1. Bob Says:

    In the US, we have sector-specific regulations, like HIPPA and GLBA. In England and the EU, there are more comprehensive laws such as the Data Protection Act (DPA-1998)

    The DPA covers all uses of consumer information, called “personal data”, and maintains that the consumer OWNS information about them. In addition, the DPA specifies a comprehensive and consolidated list of requirements for handling or storing personal data.

    All sectors, including universities, banks, hospitals, etc… must adhere to the same set of rules, and must implement similar controls. This makes exchanging information much easier because you have one set of controls to assess, as opposed to various controls and requirements for different types of information (as in the US today, where HIPPA and GLB requirements for medical and financial data, respectively, may be completely different)

    Moreover, all members of the EU are required to have laws enacting the DPA, or equivalent to the DPA. The DPA is also the model for most non-EU countries.

    Today, for US-based companies to do business with the EU, there is a “Safe Harbour” provision, stating that any US-based company can “self-attest” to DPA controls and practices — obviously not an ideal situation.

    If the US were to adopt a version of the DPA, this would greatly simplify the need for sector-specific regulation, interaction with EU countries, and information exchange.

    The problem is that credit reporting companies, who make tons of money buying and selling personal information, would be forced out of business, or their business model would have to drastically change. The problem with getting everyone on board with DPA-like laws is that lobbyists and special interest groups have more control over legislation than the voters….


advertisement


Whitepapers

  • How to Select a Web Host
    November 27, 2011 by marketing

    Creating a new website?  Not sure how to choose from among all the options?  Need shared hosting, small business hosting, or VPS hosting?  Lots of email accounts? 5-star reliability rating? Fortunately, there’s information available to help. The Best Web Hosts is great resource that will help you select the best web hosting company. It features reviews, rankings, and definitions that can help make your job of selecting a new web host more effective.

  • SMART Steps Towards Workload Automation
    January 19, 2010 by Luke Marchie

    Consolidating job scheduling into a single, comprehensive workload automation solution is a critical first step to effective Workload Automation (WLA).

    Download the free whitepaper here! More…

  • Identifying and Thwarting Malicious Intrusions
    January 12, 2010 by Luke Marchie

    Identifying and Thwarting Malicious Intrusions

    The phenomenal growth in social media has opened the door for all new malicious intrusions from gangs of cyber criminals. Utilizing the trusted relationships in social networking and benefiting from immature security and content controls, hackers are seeing increased performance in their attacks.

    Download the free whitepaper here More…

  • The Security Issues with Web 2.0
    January 12, 2010 by Luke Marchie

    The collaborative benefits of Web 2.0 technologies have fueled rapid growth in online consumer markets and now are being adopted by businesses worldwide. With these technologies come new types of attack vectors.

    Download the free whitepaper here

    More…

  • Network-Critical Physical Infrastructure: Optimizing Business Value
    December 29, 2009 by Luke Marchie

    To stay competitive in today’s rapidly changing business world, companies must update the way they view the value of their investment in Network-Critical Physical Infrastructure (NCPI). No longer are simple availability and upfront costs sufficient to make adequate business decisions. Agility, or business flexibility, and low total cost of ownership have become equally important to companies that will succeed in a global, ever-changing marketplace.

    Download the free whitepaper here! More…

  • The New World of eCrime: Targeted Brand Attacks and How to Combat Them
    December 26, 2009 by Luke Marchie

    Nothing is more valuable to a business than its reputation. That is why brand attacks, which leverage a company’s valuable brand for nefarious purposes, must be battled on every possible front. Brand attacks are the new form of eCrime, and they’re being launched with new and rapidly evolving exploits, including phishing and—most recently—malware.

    Download the free whitepaper here! More…

  • DDoS: The Mother of All Cyber Threats
    December 16, 2009 by Luke Marchie

    DDoS: The Mother of All Cyber Threats

    Don’t wait until your business is targeted. A Forrester Consulting study commissioned by VeriSign revealed that nearly 75 percent of the 400 study respondents have experienced one or more DDoS attacks in the past year. Yet, most e-commerce businesses are not prepared for a large-scale DDoS attack. Could your business afford three or more hours of downtime? Avoid that revenue loss by registering for this free white paper

    Click here to download the free white paper More…

  • View more offers


    Quick Vote

    • Does your office have a color printer or copier?

      • Yes (75%, 3 Votes)
      • We're looking into buying one (25%, 1 Votes)
      • No (0%, 0 Votes)

      Total Voters: 4

      Loading ... Loading ...

  • advertisement