|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Miller, Terry (Terry.Miller
finra.org)
Date: Wed Mar 12 2008 - 09:15:56 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Note that on March 4 the SEC proposed expanding privacy Regulation S-P
which is based on GLBA. The proposed expansion, which is based in large
part on existing banking and FTC regulations, would include a national
notification requirement. The requirement may preempt certain state
laws which allow for such preemption.
Here is the proposal, which is now out for comment.
http://www.sec.gov/rules/proposed/2008/34-57427.pdf
Terry
-----Original Message-----
From: dataloss-bounces
attrition.org
[mailto:dataloss-bounces
attrition.org] On Behalf Of Rob Shavell
Sent: Wednesday, March 12, 2008 8:30 AM
To: dataloss
attrition.org
Subject: Re: [Dataloss] A data security breach legislation question
hi all,
the question i have around US data breach notification legislation is
this:
"why are we counting states?"
if most legislation applies to affected record-holders if they are
residents and 95% of breaches already either happen in a state with a
law or include records of persons residing in such states, then...
hasn't this basically become a necessity?
in other words, organizations had better just notify to be in
compliance.
following from this: what is the importance to an organization of
reading through particulars of state by state legislation when they
can just follow California, notify everyone, and be in compliance?
bonus question: in your opinion, why are so many companies choosing to
include credit monitoring services for those affected? a) altruism b)
just not that costly c) concern about downstream law-suits d) ?
rgds,
rob
On 10/03/2008, Susan Orr <susan
susanorrconsulting.com> wrote:
> I was just looking at the various states the other day, and there are
> some differences - some exempt encrypted information, some exclude
> financial institutions and others that are covered under other
existing
> federal and state laws like GLBA. One state I believe exempts "state
> agencies" Oklahoma I think.
>
> Didn't know it was up to 40, last I saw was 38. I'll have to check
it
> out, thanks.
>
>
> Rebecca Herold wrote:
> > Counting the District of Columbia, as of the end of October it was
40; see
> >
http://www.privacyguidance.com/files/statebreachnotificationlaws10.19.07
.pdf
> >
> > Best regards,
> >
> > Rebecca Herold
> > ----- Original Message -----
> > From: "Kalter, Sarah " <skalter
affiniongroup.com>
> > To: "lyger" <lyger
attrition.org>; <dataloss
attrition.org>
> > Sent: Monday, March 10, 2008 10:07 AM
> > Subject: [Dataloss] A data security breach legislation question
> >
> >
> >
> >> Hi All,
> >>
> >> Does anyone happen to know how many states have enacted data
security
> >> breach laws/legislation? And if so, which states?
> >>
> >> Thank you so much!
> >>
> >> Best,
> >> Sarah
> >> _______________________________________________
> >> Dataloss Mailing List (dataloss
attrition.org)
> >> http://attrition.org/dataloss
> >>
> >> Tenable Network Security offers data leakage and compliance
monitoring
> >> solutions for large and small networks. Scan your network and
monitor your
> >> traffic to find the data needing protection before it leaks out!
> >> http://www.tenablesecurity.com/products/compliance.shtml
> >>
> >
> > _______________________________________________
> > Dataloss Mailing List (dataloss
attrition.org)
> > http://attrition.org/dataloss
> >
> > Tenable Network Security offers data leakage and compliance
monitoring
> > solutions for large and small networks. Scan your network and
monitor your
> > traffic to find the data needing protection before it leaks out!
> > http://www.tenablesecurity.com/products/compliance.shtml
> >
>
> _______________________________________________
> Dataloss Mailing List (dataloss
attrition.org)
> http://attrition.org/dataloss
>
> Tenable Network Security offers data leakage and compliance
monitoring
> solutions for large and small networks. Scan your network and monitor
your
> traffic to find the data needing protection before it leaks out!
> http://www.tenablesecurity.com/products/compliance.shtml
>
>
>
_______________________________________________
Dataloss Mailing List (dataloss
attrition.org)
http://attrition.org/dataloss
Tenable Network Security offers data leakage and compliance monitoring
solutions for large and small networks. Scan your network and monitor
your
traffic to find the data needing protection before it leaks out!
http://www.tenablesecurity.com/products/compliance.shtml
This email, including attachments, may include confidential and/or
proprietary information, and may be used only by the person or entity
to which it is addressed. If the reader of this email is not the
intended recipient or his or her authorized agent, the reader is
hereby notified that any dissemination, distribution or copying of this
email is prohibited. If you have received this email in error,
please notify the sender by replying to this message and delete this
email immediately.
_______________________________________________
Dataloss Mailing List (dataloss
attrition.org)
http://attrition.org/dataloss
Tenable Network Security offers data leakage and compliance monitoring
solutions for large and small networks. Scan your network and monitor your
traffic to find the data needing protection before it leaks out!
http://www.tenablesecurity.com/products/compliance.shtml
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]