Home > Security News > Group calls for federal data security breach notification law
Security News:
EMAIL THIS

Group calls for federal data security breach notification law

By SearchSecurity.com Staff
20 Apr 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The Cyber Security Industry Alliance (CSIA), a lobbying group comprised of a number of security vendors, is pressing Congressional legislators to pass a law governing disclosure in the event of a data security breach.

In the CSIA's annual report, the group criticized Congress for failing to pass a comprehensive data security law in 2006 requiring companies with data breaches to notify victims.

Currently 35 states require companies to publicly disclose security breaches involving personal information, such as credit card data and Social Security numbers. The group said it is too time consuming and costly for businesses to comply with the different laws.

The group is calling for a law that emphasizes encryption and promotes higher security standards that could reduce the number of data breaches. The group said the law would apply equally to all government agencies and businesses that collect and maintain personal information of consumers.

Cyber Security Industry Alliance:
Flurry of state disclosure laws creates confusion for CISOs: Now that nearly three dozen states have enacted breach disclosure laws, national companies face the challenge of reconciling a vast array of guidelines and their implications.

Group gives government low marks on data protection
: The Cyber Security Industry Alliance, a lobbying group of security vendors, gives the federal government and congress a D-grade for securing sensitive information.

Heavyweight CEOs align on security: A dozen security hardware, software and services vendors announced their union at RSA Conference '04. The Cyber Security Industry Alliance (CSIA) is a formidable conglomerate of the CEOs of 12 security heavyweights, including Symantec and CA.

A number of highly publicized data breaches have made the news in recent months, including the largest ever recorded, which took place at Framingham, Mass.-based retailer, TJX Cos. Last year a laptop containing the names, Social Security numbers and dates of birth of up to 26.5 million military veterans and some spouses was stolen from an official at the Department of Veterans Affairs. Several other agencies reported similar incidents of stolen laptops containing sensitive data.

The top cybersecurity job at the Department of Homeland Security (DHS) also sat vacant for more than a year until Gregory Garcia took the post in the fall.

The group's annual report also identified other specific actions for Congress to focus on for improving information security. The group is lobbying to toughen the Federal Information Security Management Act (FISMA), to strengthen enforcement and require government contractors to comply with the requirements. The group also said a dedicated system should be set up within the Department of Homeland Security that can monitor the communication infrastructure in the event of a major attack or disruption.

Members of the CSIA include Application Security, Inc.; Bharosa Inc.; BSI Management Systems; Crossroads Systems, Inc.; Entrust, Inc.; F-Secure Corp.; IBM Internet Security Systems Inc.; iPass Inc.; MXI Security; PGP Corporation; Qualys, Inc.; RSA, a division of EMC; Secure Computing Corp.; Surety, Inc.; SurfControl; TechGuard Security; and Vontu, Inc.; Symantec Corp.; and CA Inc.



Tags: Identity Theft and Data Security BreachesInformation Security Laws, Investigations and EthicsSecurity Industry Market Trends, Predictions and ForecastsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Identity Theft and Data Security Breaches
Chip and PIN adoption serves lesson for U.S. payment industry
Group to shed light on secure identity management threats
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Heartland CIO on PCI, E3 project
Visa probes tokens, encryption for PCI card data protection
University data breach exposes 163,000 women to identity theft
TJX thrives following breach, bucks sour economy
Security expert's PCI analysis misguided, says PCI Council GM
External attacks start with unintentional mistakes, survey finds

Information Security Laws, Investigations and Ethics
Melissa Hathaway urges more cooperation, government attention to cybersecurity
Cybersecurity czar candidate questions clout of new position
DHS fills National Cybersecurity Center post
FTC shutters rogue ISP for hosting malicious content, botnets
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Cybersecurity Act of 2009: Power grab, or necessary step?
Face-off: Who should be in charge of cybersecurity?
Feds should get private sector advice on cybersecurity

Security Industry Market Trends, Predictions and Forecasts
M86 buys Web security gateway vendor Finjan
Information Security Decisions 2009: Presentation downloads
Bruce Schneier on outsourcing, awareness training
Marcus Ranum on cyberwarfare, infosec careers
McAfee survey finds faults in midmarket enterprise security
Email archiving vendor sues Gartner over Magic Quadrant
Information Security magazine October issue PDF
Editor's Desk: Security 7 Winners Chronicle Trends That Shape The Industry
Information Security magazine Security 7 Award winners
Security Squad: Privacy gone awry
Security Industry Market Trends, Predictions and Forecasts Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
CISP-PCI  (SearchFinancialSecurity.com)
cookie poisoning  (SearchSecurity.com)
drive-by pharming  (SearchSecurity.com)
extrusion prevention  (SearchSecurity.com)
identity theft  (SearchSecurity.com)
parameter tampering  (SearchSecurity.com)
pretexting  (SearchCIO.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts