Tucked away in the conclusion of this article is an interesting question: is the PCI Data Security Standard effective? Actually, the question as posed, which was whether the PCI Data Security Standard in its current form is effective, is not particularly interesting (at least to me). The more interesting question is whether the PCI DSS, or any self regulation can be an effective counter to information security threats. I don't know the answer, but the article gives some indication that that answer might be no.
Of course, the article itself did not tackle the question of self regulation versus governmental oversight. The article was devoted to describing a new set of guidelines which is intended to facilitate the process of becoming PCI compliant. Apparently, there is a perception that some businesses look at the PCI requirements, become overwhelmed by what's necessary to comply, and, as a result, do nothing. The hope is that, by breaking things down and ranking them in terms of priority, the new guidelines will make the task more manageable, and therefore increase compliance. The article then mentioned that these new efforts to increase compliance come at a time when the effectiveness of the PCI DSS is being questioned based on recent security breaches such as that at Heartland Payment Systems. The article mentioned that a spokesman from the PCI Security Standards council had said that there wasn't anything wrong with the standards. However, if that's true, it raises a bigger question - why are the breaches still happening?
One possible answer, the one I alluded to at the beginning of the post, is that breaches are still happening because self regulation isn't an effective means of influencing behavior. I think that position is probably too extreme - merchants do care about the PCI DSS. However, the fact that there is a perceived need for the current compliance campaign, and the fact that massive breaches like that at Heartland keep happening indicates that something needs to change. Maybe what that is is to add a dose of federal government enforcement power to the supposedly sufficient requirements of the PCI DSS.
Showing posts with label regulation. Show all posts
Showing posts with label regulation. Show all posts
Sunday, March 15, 2009
Monday, September 22, 2008
Self-Regulation by Advertisers
According to this article from Media Post the Interactive Advertising Bureau is pushing for the creation of an industry body to create non-governmental rules to protect consumer privacy online. The goal of this self-regulation, as is the case with most self-regulation, is to prevent actual regulations from being imposed by Congress. While generally, consumers appear apathetic about their privacy online, it appears that advertisers might have reason to worry. Specifically, Eileen Harrington deputy director of the Bureau of Consumer Protection, Federal Trade Commission has said that online privacy is a hot issue in Washington right now, and compared the situation of on-line advertisers to that of telemarketers before the government established the national Do-Not-Call-List. Given that kind of comparison, it makes sense that advertisers are thinking about regulating themselves, so they can convince Congress that regulation by government isn't necessary.
Of course, the elephant in this particular room is that it's too late - section 5 of the FTC act, which prohibits unfair or deceptive trade practices, already covers online advertisers. Moreover, the FTC already uses its authority under section 5 to prosecute online advertisers. For example, currently on the FTC's privacy site there's a link to an article about a 2.9 million dollar settlement which was wrung out of online advertiser ValueClick (link here so it isn't lost when the FTC's site is updated). While I can understand the IAB's desire to forestall more regulation, if their goal was to avoid any regulation, they're about 70 years too late.
Bonus non-legal observation: when you're making a comparison, do not say the following: "It's the same issue. What's really changed, really, is everything." It completely undermines whatever point you were trying to make by the comparison, and makes your reader/listener wonder why you drew the comparison between such dissimilar things in the first place.
Of course, the elephant in this particular room is that it's too late - section 5 of the FTC act, which prohibits unfair or deceptive trade practices, already covers online advertisers. Moreover, the FTC already uses its authority under section 5 to prosecute online advertisers. For example, currently on the FTC's privacy site there's a link to an article about a 2.9 million dollar settlement which was wrung out of online advertiser ValueClick (link here so it isn't lost when the FTC's site is updated). While I can understand the IAB's desire to forestall more regulation, if their goal was to avoid any regulation, they're about 70 years too late.
Bonus non-legal observation: when you're making a comparison, do not say the following: "It's the same issue. What's really changed, really, is everything." It completely undermines whatever point you were trying to make by the comparison, and makes your reader/listener wonder why you drew the comparison between such dissimilar things in the first place.
Labels:
online advertising,
regulation,
section 5 FTC act
Saturday, April 12, 2008
Utility of Regulations
Does computer security regulation actually improve security? No, says this article from Computer World. Instead, the article says that regulations which specify behavior for companies risk "actually weakening a business by enforcement actions that drive companies to spend unnecessarily on perceived but not genuine security risks." The article says that, instead of specifying behavior, regulation should be outcome based. The example of good outcome based regulation given in the article was California's SB 1386, which requires companies to notify consumers of unauthorized access to their personal data. However, after praising SB 1386, the article says that that legislation is also a problem, and advocates burying it with federal regulation which would preempt state security breach notification laws. The reason the article gives for needing this preemptive federal legislation: "to create a national baseline standard for protecting sensitive data."
As it happens, I disagree with almost everything this article said. First, I think the article's fear that regulation will cause companies to waste money on needless security measures is completely misplaced. I'm actually a little curious, what part of the current regulatory climate is it that he thinks is forcing businesses to spend money unnecessarily? Is it (for example) HIPAA's encryption requirements? It's unique user identifications? It's easy to complain about regulatory burden. However, I'm not sure that I'd want a business to have my health care records (or other personal data) if they didn't even bother to know who was on their systems, or properly encrypt my information. Second, I think the article's focus on SB1386 as the type of regulation that we need is completely wrong. Yes, that law is useful, in that it makes sure companies can't just sweep security breach incidents under the rug. However, it does nothing to prevent the breaches in the first place. To me, it makes sense to try and have regulations which prevent bad events (e.g., security breaches) from happening in the future place) rather than simply trying to clean up after when something goes wrong. Finally, the article advocates preemptive federal data security breach laws. I think this is dead wrong. Why not let individual states try and find their own balances between costs of notification and individual privacy? Having multiple state laws doesn't make it more difficult to comply...it just means that businesses need to know whose data they're storing, then comply with the most stringent standards which apply to that data. If we had some kind of federal amalgam of our current state legislation, the result would be that states could no longer make innovative laws like California's SB1386, and that would make people's information less, not more, secure.
Thus, while I think it's generally a good thing to discuss the appropriate level of regulation to protect information security, Computer World's article arguing that regulation is unhelpful can safely be skipped, as there isn't much there worth considering.
As it happens, I disagree with almost everything this article said. First, I think the article's fear that regulation will cause companies to waste money on needless security measures is completely misplaced. I'm actually a little curious, what part of the current regulatory climate is it that he thinks is forcing businesses to spend money unnecessarily? Is it (for example) HIPAA's encryption requirements? It's unique user identifications? It's easy to complain about regulatory burden. However, I'm not sure that I'd want a business to have my health care records (or other personal data) if they didn't even bother to know who was on their systems, or properly encrypt my information. Second, I think the article's focus on SB1386 as the type of regulation that we need is completely wrong. Yes, that law is useful, in that it makes sure companies can't just sweep security breach incidents under the rug. However, it does nothing to prevent the breaches in the first place. To me, it makes sense to try and have regulations which prevent bad events (e.g., security breaches) from happening in the future place) rather than simply trying to clean up after when something goes wrong. Finally, the article advocates preemptive federal data security breach laws. I think this is dead wrong. Why not let individual states try and find their own balances between costs of notification and individual privacy? Having multiple state laws doesn't make it more difficult to comply...it just means that businesses need to know whose data they're storing, then comply with the most stringent standards which apply to that data. If we had some kind of federal amalgam of our current state legislation, the result would be that states could no longer make innovative laws like California's SB1386, and that would make people's information less, not more, secure.
Thus, while I think it's generally a good thing to discuss the appropriate level of regulation to protect information security, Computer World's article arguing that regulation is unhelpful can safely be skipped, as there isn't much there worth considering.
Labels:
federal legislation,
regulation,
state legislation
Thursday, March 20, 2008
The Problem of Compensation
In my last post, I addressed what is a proper measure of damages for exposure of a person's private information. In response, the Dunning Letter put up a post responding to it, and providing some interesting statistics about the cost ($5720/victim) and prevalence (top complaint reported by FTC ID theft and consumer fraud survey) of identity theft. At that time, I considered preparing a responsive post, essentially playing devil's advocate and pointing out that providing compensation via lawsuits was really a poor way to combat the problem of information exposure, because, even if you could get the proper measure of damages, most people wouldn't take the trouble to file a lawsuit. Further, even if people did file lawsuits, the transaction costs associated with litigation (i.e., attorneys' fees) mean that, even if you did provide incentives to avoid data exposure, there would be a ton of lost effort involved.
However, this post brings the problem into even sharper focus, by describing the situation of a young woman who states the she reported an identity theft, which took between 20 minutes to an hour, and that she got NOTHING in return. If doesn't think it's worth an hour of her time to report an ID theft (and she's undoubtedly not alone in that), then you can bet there will be very few consumers who would be willing to spend the time (years) and money (thousands of dollars) which are necessary to go to court. The bottom line: while providing compensation is worthwhile, it isn't enough.
So what is enough? My proposal is regulation, clearly written and consistently enforced. Part of the problem is that businesses simply don't know what they need to do to avoid having security breaches. Also, businesses know that, even if there is a breach, there isn't much chance that individual plaintiffs will be able to successfully bring suit for damages. Clear regulation which is consistently enforced could solve those problems, both by providing clear guidance for businesses, and by providing a strong incentive (threat of government penalties) for following that standard. At the moment though, the U.S. model seems to be notification followed by individual litigation, which is, as set forth above, a highly suboptimal solution.
However, this post brings the problem into even sharper focus, by describing the situation of a young woman who states the she reported an identity theft, which took between 20 minutes to an hour, and that she got NOTHING in return. If doesn't think it's worth an hour of her time to report an ID theft (and she's undoubtedly not alone in that), then you can bet there will be very few consumers who would be willing to spend the time (years) and money (thousands of dollars) which are necessary to go to court. The bottom line: while providing compensation is worthwhile, it isn't enough.
So what is enough? My proposal is regulation, clearly written and consistently enforced. Part of the problem is that businesses simply don't know what they need to do to avoid having security breaches. Also, businesses know that, even if there is a breach, there isn't much chance that individual plaintiffs will be able to successfully bring suit for damages. Clear regulation which is consistently enforced could solve those problems, both by providing clear guidance for businesses, and by providing a strong incentive (threat of government penalties) for following that standard. At the moment though, the U.S. model seems to be notification followed by individual litigation, which is, as set forth above, a highly suboptimal solution.
Labels:
costs,
identify theft,
private suits,
regulation
Subscribe to:
Posts (Atom)