Data Breach: From Notification to Prevention Using PCI DSS

作者
Abraham Shaw
出处
期刊:Columbia Journal of Law and Social Problems [Brill]
卷期号:43 (4): 517- 被引量:31
摘要

With over 350 million records containing sensitive personal information having been compromised since 2005, it is evident that data breaches are an epidemic problem. After demonstrating the security breach problem, the Note begins by discussing California's pioneering data breach notification law, which requires breached entities to notify those affected that their personal information has been compromised. Drawing on various provisions found in California's notification law, the Note evaluates current state and federal data breach laws. To further explore the relationship between federal and state enforcement, two recent data breaches, the ChoicePoint and TJX breaches, are discussed in-depth. The Note then examines proposed federal and state legislation to strengthen the argument that data breach laws, which currently focus on notification, must also advance to breach prevention. Finally, the Note proposes a solution for preventing data breaches by increasing liability for merchants who fail to meet heightened security standards based on those used in the credit card industry. I. INTRODUCTION In an age when internet transactions have become a part of everyday life, both individual users and corporations have become more sophisticated. Users who used to receive content only passively now actively engage in e-commerce. Companies that used to only keep paper files now maintain digital databases worldwide. Because private information is increasingly available over the internet, there is a rising demand for data breach laws that protect private information. Approximately eighty to ninety percent of Fortune 500 companies and government agencies have experienced data breaches.1 Since January 2005, over 350 million records containing sensitive personal information have been compromised in data breaches.2 The leading cause of these security breaches is hacker intrusion, followed by stolen laptops and computers, and insider thefts of private information.3 Terrorists have also increasingly utilized the internet not only to communicate and recruit, but also to perpetrate online crimes to obtain financial support for their agendas.4 Furthermore, data breaches often result in fraud. The Internet Crime Complaint Center reported that fraud-related losses totaled $264.6 million in 2008, up from $239.1 million in 2007.5 These figures only address reported losses; computer crime experts agree that most computer-related crimes go either undetected or unreported.6 With personal information being compromised almost daily in data breaches,7 the main question is: what are state and federal governments doing about this problem? Having demonstrated that a security breach problem exists, this Note will go on to describe the current state and federal laws addressing the problem, highlight certain enforcement actions that have been undertaken in response to the problem, and, finally, propose that lawmakers craft legislation that focuses not only on notification of injured parties and damage control but also on data breach prevention. Part II begins by discussing California's pioneering data breach law and then draws on that law to evaluate current state data breach laws. Part III examines the current federal laws addressing data breach issues, specifically the Gramm-Leach-Bliley Act and various Federal Trade Commission acts. Part IV illuminates the need for legislation that goes beyond requiring consumer notification after data breaches to prevent such breaches. This section also explores the relationship between federal and state data breach laws using the Choice Point and TJX breaches. Part V discusses pending state and federal legislation to demonstrate that data breach laws need to progress toward preventing data breaches. Finally, Part VI proposes a solution: data breaches can be prevented by increasing liability for merchants who fail to meet heightened security standards based on those used in the credit card industry. …

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
gxy完成签到,获得积分10
1秒前
yl完成签到,获得积分10
2秒前
3秒前
笼中鸟完成签到,获得积分10
4秒前
Tori完成签到 ,获得积分10
4秒前
4秒前
5秒前
5秒前
qq发布了新的文献求助10
6秒前
传奇3应助飘逸的龙猫采纳,获得10
6秒前
vanitas关注了科研通微信公众号
7秒前
8秒前
9秒前
Aru完成签到 ,获得积分10
10秒前
Tori关注了科研通微信公众号
10秒前
科研通AI6.2应助innocence@x采纳,获得10
11秒前
JamesPei应助1126采纳,获得10
11秒前
李爱国应助cesin采纳,获得10
11秒前
12秒前
12秒前
12秒前
是个宝耶完成签到 ,获得积分10
13秒前
ccc完成签到 ,获得积分10
15秒前
动听的逍遥完成签到,获得积分10
16秒前
16秒前
Charlene发布了新的文献求助10
17秒前
希望天下0贩的0应助王子采纳,获得10
18秒前
snowing完成签到 ,获得积分10
18秒前
菜头完成签到 ,获得积分10
18秒前
18秒前
19秒前
20秒前
20秒前
orixero应助angew采纳,获得10
22秒前
23秒前
23秒前
23秒前
23秒前
23秒前
AthurMarcus发布了新的文献求助10
25秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
The anomeric effect 1314
Principles of town planning: translating concepts to applications 1000
1 Peter and Christ's Descent to the Dead in Its Early Christian Reception 700
Organizational Behavior 510
Management and the Arts 510
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7734324
求助须知:如何正确求助?哪些是违规求助? 9284698
关于积分的说明 20166402
捐赠科研通 7312141
什么是DOI,文献DOI怎么找? 3304642
关于科研通互助平台的介绍 2457279
邀请新用户注册赠送积分活动 2313831