<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
>

<channel>
	<title>The Security Catalyst&#187; PCI</title>
	<atom:link href="http://www.securitycatalyst.com/tag/pci/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitycatalyst.com</link>
	<description>Michael Santarcangelo delivers Awareness that Works™</description>
	<lastBuildDate>Tue, 06 Jul 2010 08:52:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<!-- podcast_generator="Blubrry PowerPress/1.0.9" mode="advanced" entry="normal" -->
	<itunes:summary>Michael J. Santarcangelo, II is a human catalyst. An expert who speaks on information protection â including compliance, privacy and awareness â Michael energizes and inspires his audiences to change the way they protect information. His passion and approach gets results that change behaviors. 

As the voice of optimism in an industry of doomsayers, Michael has recently completed his first book, Into the Breach (www.intothebreach.com), which provides the wisdom and answers executives need to defend their organization against breaches while discovering how to increase revenue, protect the bottom line and efficiently manage people, information and risk.

In this podcast series, Michael shares ideas, research and strategies for your success. 
</itunes:summary>
	<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
	<itunes:explicit>clean</itunes:explicit>
	<itunes:image href="http://www.securitycatalyst.com/tsc_icon.png" />
	<itunes:owner>
		<itunes:name>Michael Santarcangelo | The Security Catalyst</itunes:name>
		<itunes:email>michael@securitycatalyst.com</itunes:email>
	</itunes:owner>
	<managingEditor>michael@securitycatalyst.com (Michael Santarcangelo | The Security Catalyst)</managingEditor>
	<copyright>Copyright 2009 The Security Catalyst. All Rights Reserved. </copyright>
	<itunes:subtitle>A catalyst for engaging, empowering and enabling individuals; turn insiders into allies who reduce business risk!</itunes:subtitle>
	<itunes:keywords>security, risk, privacy, compliance, breach, awareness, training, catalyst, confidentiality, integrity, availability, cissp, cism, cisa, cpp</itunes:keywords>
	<image>
		<title>The Security Catalyst&#187; PCI</title>
		<url>http://www.securitycatalyst.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.securitycatalyst.com</link>
	</image>
	<itunes:category text="Business">
		<itunes:category text="Management &amp; Marketing" />
	</itunes:category>
	<itunes:category text="Technology" />
	<itunes:category text="Education" />
		<item>
		<title>How Virtualization Affects GRC</title>
		<link>http://www.securitycatalyst.com/how-virtualization-affects-grc/</link>
		<comments>http://www.securitycatalyst.com/how-virtualization-affects-grc/#comments</comments>
		<pubDate>Wed, 24 Mar 2010 10:41:12 +0000</pubDate>
		<dc:creator>Dave Shackleford</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[grc]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2781</guid>
		<description><![CDATA[By Dave Shackleford Virtualization technology is becoming ubiquitous. More and more organizations are replacing physical infrastructure with virtualized systems, including desktops and servers, and application and storage virtualization are popular as well. Virtualization changes a number of paradigms across the information technology landscape – some obviously for the good, some possibly for the worse. In [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fhow-virtualization-affects-grc%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fhow-virtualization-affects-grc%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>By Dave Shackleford</strong><br />
Virtualization technology is becoming ubiquitous. More and more organizations are replacing physical infrastructure with virtualized systems, including desktops and servers, and application and storage virtualization are popular as well. Virtualization changes a number of paradigms across the information technology landscape – some obviously for the good, some possibly for the worse. In the realm of GRC, virtualization has some distinct points to consider, many of which may require changes in operations and policy, as well as overall information security management.</p>
<p>Where governance is concerned, virtualization brings about changes in <strong>separation of duties</strong> and <strong>policy definition</strong>.</p>
<p>In traditional IT environments, distinct teams with specialized skill sets manage and operate various pieces of the infrastructure. Network engineering and administration teams manage routers and switches, Windows systems admins manage Windows servers, etc. With virtualization technologies, all of these functions are collapsed into a generally cohesive management structure, such as VMware’s vCenter Server.</p>
<p>This leads invariably to challenges with “who manages what” – many IT shops tend to put the burden of managing VMware solutions on Windows admins, for example. These admins now manage the virtual machines, the underlying hypervisor platforms, the virtual networks, storage connections, etc. All of these can be regarded as separate disciplines, and having one team manage them all flies in the face of proper separation of duties.</p>
<p>Along with this problem comes the definition of policies governing the use and oversight of these technologies – who drafts the policies, and which teams are the policy owners?</p>
<p>The overall risk landscape changes dramatically with virtualization, too.</p>
<p>Many of the risks are similar to those we understand today, but are present in a somewhat different form. The lack of proper change management and configuration management programs are still viable risks that can lead to innumerable security issues, but they’re compounded by the operational nuances of virtualization technologies themselves. For example, the act of creating and provisioning systems is simplified immensely – keep a template, generate a new virtual machine from it, move the VM to a host platform, and flip the switch.</p>
<p>Without ensuring that a) the template configuration is patched and up to date, and b) the VM provisioning has gone through change control, the risk of having a new system online that has OS or application-specific vulnerabilities is exponentially higher. Threat vectors change, too – if the hypervisor platform is compromised by an attacker, the entire group of virtual machines hosted on that platform is immediately at risk, which tells us that new risks inherent in hypervisors hold much greater impacts than single-system risks that we’ve managed before this, potentially.</p>
<p>On the compliance front, there is a considerable amount of grey area around how virtualization plays a role. On the one hand, most compliance mandates (SOX, HIPAA, GLBA) are vague enough to leave the interpretation open to both auditors and auditees alike. Herein the issue lies, however – compliance mandates open to subjective interpretation are bad, since potentially unsafe practices may be considered acceptable by different auditors and organizations who don’t understand the risks, technologies, or both.</p>
<p>Even more prescriptive regulations like the PCI DSS don’t specifically address virtualization, which has led to a number of issues around interpretation. For example, PCI DSS section 2.2.1 mandates that all servers involved with payment card data should only have a single function, such as a dedicated Web server or database server. What about virtualization hosts like VMware ESX, though? It’s a single server, but runs VMs that perform a variety of different functions. Although a Virtualization Special Interest Group (SIG) has worked on this, there’s no clear timeframe for integrating their work into the standard. In addition, many auditors just don’t understand virtualization technology, and default to the most restrictive possible implementation methods “just to be safe” – any “knee jerk” reactions of this type are probably a bad thing, in either direction.</p>
<p>Virtualization can help organizations reduce operating costs, and many feel that it’s a key component to “Green IT” strategies aimed at reducing energy consumption. However, despite popular belief, it actually makes the IT environment more rather than less complex, and a number of new processes and approaches are needed to ensure that security and risk management keep pace with its adoption.</p>
<p><em>Dave Shackleford, Director of Security Assessments and Risk &amp; Compliance at Sword &amp; Shield Enterprise Security, is also a SANS Analyst, instructor, course author and GIAC technical director. He has consulted with hundreds of organizations in the areas of regulatory compliance, security, and network architecture and engineering. He&#8217;s worked as CSO for Configuresoft, CTO for the Center for Internet Security, and has also worked as a security architect, analyst, and manager for several Fortune 500 companies.</em>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fhow-virtualization-affects-grc%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fhow-virtualization-affects-grc%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/how-virtualization-affects-grc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst Update for Sunday, February 1, 2009</title>
		<link>http://www.securitycatalyst.com/security-catalyst-update-for-sunday-february-1-2009/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-update-for-sunday-february-1-2009/#comments</comments>
		<pubDate>Sun, 01 Feb 2009 15:10:41 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[News and Events]]></category>
		<category><![CDATA[inauguration]]></category>
		<category><![CDATA[ironkey]]></category>
		<category><![CDATA[nys]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[sandisk]]></category>
		<category><![CDATA[secure code]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1059</guid>
		<description><![CDATA[The conversations continue. Looking for results in your career? Join the conversation. Take responsibility. Make a difference! Discussion Forum Activity I have noticed an exciting trend in the community &#8211; more and more people are coming together to &#8220;create.&#8221; The community is reaching another level (and I will be forming a team of volunteers to [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-update-for-sunday-february-1-2009%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-update-for-sunday-february-1-2009%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>The conversations continue. Looking for results in your career? Join the conversation. Take responsibility. Make a difference!</p>
<h3>Discussion Forum Activity</h3>
<p>I have noticed an exciting trend in the community &#8211; more and more people are coming together to &#8220;create.&#8221; The community is reaching another level (and I will be forming a team of volunteers to help improve the available tools) &#8211; and it is exciting to realize that by working together, we really <strong>can</strong> make a difference. Here are some recent discussions ripe for contribution or learning:</p>
<ul>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=1112.0">What Are You Reading?</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=1110.0">Pre-Sales SE training</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=1101.0">SanDisk&#8217;s secure USB Flash Drive solution &#8211; competition for IronKey</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=1105.0">Guide to Protecting the Confidentiality of Personally Identifiable Information</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=1095.0">Network or security changes on inauguration day (1/20)?</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=1106.0">Process Credit Cards on the iPhone With ProcessAway</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=1091.0">New York drafts language demanding secure code</a></li>
</ul>
<h3>List of community blogger and podcasters</h3>
<p><a href="http://www.securitycatalyst.org/forums/index.php?topic=28.0">What Security Blogs and Podcasts are represented in this community?</a></p>
<h3>About the Security Catalyst Community</h3>
<p>We are a positively focused and supportive community that unites passionate professionals to achieve three goals:</p>
<ol>
<li>Provide a community where it is acceptable to be vulnerable and ask for help when you need it</li>
<li>Create a community where anyone with an idea can share their approach in the pursuit of helping another. If today is your first day in security, welcome &#8211; share what you have learned without fear.</li>
<li>Participate in a forum where members can share their passions, expand their thinking and find support with others who believe in making a positive difference.</li>
</ol>
<h3>Signing Up for the Security Catalyst Community</h3>
<p>Your participation is your currency (means no charge to join) &#8211; the more you contribute the more you learn and the more valuable the community becomes to everyone (so dive in and share). Please note: accounts dormant for 180 days are automatically removed. </p>
<p><strong>Registration Overview (NOTE THE NAMING CONVENTION)</strong></p>
<ol>
<li>Go here: <a href="http://www.securitycatalyst.org/forums/index.php">http://www.securitycatalyst.org/forums/</a></li>
<li>Select the register link</li>
<li><strong><span style="color: #ff0000;">Follow the naming standard: firstname.lastname (include the period between first and last names)</span></strong></li>
<li>Your account will be reviewed and approved</li>
<li>Jump in and share your thoughts!</li>
</ol>
<h3>Join The Security Catalyst LinkedIn Group</h3>
<p>If you are a current and active member of the Security Catalyst Community (which means you have either posted or otherwise contributed), join us: <a href="http://www.linkedin.com/groups?gid=27010">http://www.linkedin.com/groups?gid=27010</a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-update-for-sunday-february-1-2009%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-update-for-sunday-february-1-2009%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-update-for-sunday-february-1-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst Community: Discussion Forum Activity for June 30, 2008</title>
		<link>http://www.securitycatalyst.com/security-catalyst-community-discussion-forum-activity-for-june-30-2008/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-community-discussion-forum-activity-for-june-30-2008/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 13:09:20 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[News and Events]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[protocol security]]></category>
		<category><![CDATA[Security Catalyst Community]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=462</guid>
		<description><![CDATA[Happy Monday! The forums have really seen an uptick in membership and activity in the last few weeks. This is a supportive environment where professionals come together to ask for help, share ideas and get validated. Here is some recent activity (and darn good discussions): Incident Response Case Study: Shutdown the Network? Protocol Security: Where [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-community-discussion-forum-activity-for-june-30-2008%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-community-discussion-forum-activity-for-june-30-2008%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Happy Monday! The forums have really seen an uptick in membership and activity in the last few weeks. This is a supportive environment where professionals come together to ask for help, share ideas and get validated. Here is some recent activity (and darn good discussions):</p>
<ul>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=909.0">Incident Response Case Study: Shutdown the Network?</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=908.0">Protocol Security: Where does it belong?</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=872.0">Web Server vs Reverse Proxy</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=875.0">PCI DSS clarifies 6.6 Requirements</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=888.0">IPS Matrix</a></li>
</ul>
<div>Your participation is your currency (means no charge to join) &#8211; the more you contribute the more you learn and the more valuable the community becomes to everyone (so dive in and share). If you have not yet registered, please remember to use <strong>firstname.lastname</strong> as the standard.</div>
<div></div>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-community-discussion-forum-activity-for-june-30-2008%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-community-discussion-forum-activity-for-june-30-2008%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-community-discussion-forum-activity-for-june-30-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst Community: Discussion Forum Activity for June 26</title>
		<link>http://www.securitycatalyst.com/security-catalyst-community-discussion-forum-activity-2/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-community-discussion-forum-activity-2/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 11:35:52 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[News and Events]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[DFRWS]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[OMFW]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security Catalyst Community]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=461</guid>
		<description><![CDATA[I spent a great day in Rochester, NY yesterday. Here is some of the activity in the forums  - check it out to add your opinion or learn (lots here to learn from): Porn Scanner Reporting Incident Response Statistics Vulnerability Management Process/Workflow The cost of PCI compliance &#8212; or non-compliance &#8212; for small organizations DFRWS [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-community-discussion-forum-activity-2%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-community-discussion-forum-activity-2%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>I spent a great day in Rochester, NY yesterday. Here is some of the activity in the forums  - check it out to add your opinion or learn (lots here to learn from):</p>
<ul>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=906.0">Porn Scanner</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=903.0">Reporting Incident Response Statistics</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=878.0">Vulnerability Management Process/Workflow</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=886.0">The cost of PCI compliance &#8212; or non-compliance &#8212; for small organizations</a></li>
<li><a class="nav" href="http://www.securitycatalyst.org/forums/index.php?topic=907.0">DFRWS and OMFW</a></li>
</ul>
<div>Your participation is your currency (means no charge to join) &#8211; the more you contribute the more you learn and the more valuable the community becomes to everyone (so dive in and share). If you have not yet registered, please remember to use <strong>firstname.lastname</strong> as the standard.</div>
<div>Note: based on the increased level and quality of participation this week, I&#8217;d say the value of the community is going up. There is a real body of knowledge there. Thank you to those who participate.</div>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-community-discussion-forum-activity-2%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-community-discussion-forum-activity-2%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-community-discussion-forum-activity-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do Data-Breach Laws Give You The Power to Hold Corporations Liable?</title>
		<link>http://www.securitycatalyst.com/do-data-breach-laws-give-you-the-power-to-hold-corporations-liable-2/</link>
		<comments>http://www.securitycatalyst.com/do-data-breach-laws-give-you-the-power-to-hold-corporations-liable-2/#comments</comments>
		<pubDate>Thu, 01 Nov 2007 14:32:55 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Security Awareness Training]]></category>
		<category><![CDATA[tjx]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/2007/11/01/do-data-breach-laws-give-you-the-power-to-hold-corporations-liable-2/</guid>
		<description><![CDATA[Recently, state governments have begun to change this by imposing liability on the retail business and others, thereby opening the door for consumers to sue companies that do not adequately protect the personal information that they collect....  In the meantime, we’re going to ignite our series of articles exploring these laws and developments by analyzing some recent events.Minnesota PCI LegislationEffective August 1st 2007, Minnesota became the first state to require that all companies handling credit and debit card data comply with the Payment Card Industry (PCI) data security standard (in a future article or podcast, we’ll explore and debate the value of tying the PCI standard to the legislation - Michael).The state’s new Plastic Card Security Act would prohibit a company from retaining a credit card’s security code data, the PIN verification code number, or the full contents of any track of magnetic strip data....  In Pisciotta v. Old Nat’l Bancorp, the court held that there was no state statute supporting the compensation of incurred costs because “had the Indiana legislature intended that a cause of action should be available against a database owners for failing to protect adequately personal information, we believe it would have made some more definite statement of that intent.”  So for the time being, unless you have an actual showing of harm as a victim of identity theft, potential harm will not suffice.Consequences for the Courts As more states begin to enact legislation that requires companies to comply with PCI, courts may begin to allow litigants to be compensated as a result of a security break.  The argument that courts have made in cases like Pisciotta will clearly be much weaker as states legislatures conspicuously demonstrate their intent to punish companies by enacting specific statutes targeting the security of personal information....  Clearly, there is a way for the legislature of any state to write a statute that can pressure companies to improve their data security standards without crippling small business owners.  While the retail industry will continue to resist such legislation, there is strong support from banks and credit unions, since in the eyes of consumers they often blamed for such breaches....  Depending on how the case turns out, the burdens and cost of breaches will shift away from consumers, banks, and credit unions but will perhaps be shared by the retailers and others (of course, the consumer pays in the end).Preparing for the changeAs a consequence of new state and federal legislation, the landscape of data security will continue to evolve, sometimes in seemingly dramatic fashion....  Industries that have for now been able to get away with having minimum security standards will begin to take notice of their potential liability and hopefully, will improve the way they guard information.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fdo-data-breach-laws-give-you-the-power-to-hold-corporations-liable-2%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fdo-data-breach-laws-give-you-the-power-to-hold-corporations-liable-2%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>By Michael Santarcangelo and Patrick Romero</strong></p>
<p><img src="http://www.securitycatalyst.com/wp-content/uploads/2007/11/istock-000002494364xsmall1.jpg" height="180" width="269" border="1" align="left" hspace="4" vspace="4" alt="iStock_000002494364XSmall" title="iStock_000002494364XSmall" />There are roughly 40 states that have some sort of “data-breach” law or bill being considered that force notification of a company’s security breach (or suspected breach) to their consumers. These laws were enacted as a way to force companies to disclose the possibility that individuals personal information was compromised and that they could potentially become victims of identity theft.</p>
<p>Over the coming months, we’ll spend some time exploring how the different states are handling these statutes. When you peel the layers back a bit, and consider them from different angles, we can learn some interesting elements – useful to us from individual and organizational perspectives.</p>
<p>Even with these new laws in effect, it seems that there is little a person can due to hold a company liable for a data-breach based on their weak security standards. Recently, state governments have begun to change this by imposing liability on the retail business and others, thereby opening the door for consumers to sue companies that do not adequately protect the personal information that they collect.</p>
<p>This is a serious issue that has implications for everyone involved – and ultimately requires clear definitions, mutual understanding and will take years to sort through. In the meantime, we’re going to ignite our series of articles exploring these laws and developments by analyzing some recent events.</p>
<p><strong>Minnesota PCI Legislation</strong><br />
Effective August 1st 2007, <a href="http://www.revisor.leg.state.mn.us/bin/getpub.php?pubtype=STAT_CHAP_SEC&amp;year=current&amp;section=325e.61">Minnesota became the first state</a> to require that all companies handling credit and debit card data comply with the Payment Card Industry (PCI) data security standard <em>(in a future article or podcast, we’ll explore and debate the value of tying the PCI standard to the legislation &#8211; Michael</em>).</p>
<p>The state’s new <strong><em>Plastic Card Security Act</em></strong> would prohibit a company from retaining a credit card’s security code data, the PIN verification code number, or the full contents of any track of magnetic strip data. The new legislation is intended to target retailers who continue to store data in violation of PCI standards. The bill also makes it a violation for retailers to a credit card holder’s PIN number longer than 48 hours after authorization of their transaction. Similar bills are pending in Texas, Illinois, Connecticut, and Massachusetts.</p>
<p>The significant of this legislation is important in light of recent ruling by courts that have dismissed class action suits against companies following data-breaches. On August 23, 2007, the US Court of Appeals for the 7th Circuit held that identity-theft monitoring costs paid for by the plaintiffs were not compensable damages under Indian’s security breach notification statute. In <em><a href="http://www.scribd.com/doc/260744/pisciotta-v-old-national-bancorp">Pisciotta v. Old Nat’l Bancorp</a></em>, the court held that there was no state statute supporting the compensation of incurred costs because “had the Indiana legislature intended that a cause of action should be available against a database owners for failing to protect adequately personal information, we believe it would have made some more definite statement of that intent.”  So for the time being, unless you have an actual showing of harm as a victim of identity theft, potential harm will not suffice.</p>
<p><strong>Consequences for the Courts</strong><br />
As more states begin to enact legislation that requires companies to comply with PCI, courts may begin to allow litigants to be compensated as a result of a security break. The argument that courts have made in cases like <em>Pisciotta</em> will clearly be much weaker as states legislatures conspicuously demonstrate their intent to punish companies by enacting specific statutes targeting the security of personal information.</p>
<p>Federal and state courts will feel much more comfortable in their decision to expand their legal theories of liability when supported by statutes that explicitly creates private actions for security breaches. In this context, it is much more likely that Courts will not follow the ruling in Pisciotta until after states pass legislation similar to Minnesota. In other addition, plaintiffs might also receive some relief if a recent bipartisan bill in the U.S. Senate gets passed. The bill, known as the <strong><em><a href="http://www.govtrack.us/congress/bill.xpd?bill=s110-2168">Identity Theft Enforcement and Restitution Act of 2007</a></em></strong>, was introduced on October 16, 2007 and would give victims the ability to seek restitution for the loss of time and money as a result of identity theft. Such federal legislation could prove to be effective in jurisdictions with no state identity-theft laws.</p>
<p><strong>Consequences for Businesses<br />
</strong>Meanwhile, the retail lobby continues to argue against laws that would hold them liable by arguing that these laws would be too costly and burdensome, especially for small businesses. This apparently was the argument that convinced <a href="http://arstechnica.com/news.ars/post/20071016-governator-terminates-california-data-protection-law.html">Governor Schwarnenegger to veto a California law</a> that would have mandated the retail industry comply with PCI requirements. While this may be true, legislation in Minnesota limits this burden by exempting businesses with few than 20,000 transactions from their statute. Clearly, there is a way for the legislature of any state to write a statute that can pressure companies to improve their data security standards without crippling small business owners.</p>
<p>While the retail industry will continue to resist such legislation, there is strong support from banks and credit unions, since in the eyes of consumers they often blamed for such breaches. <a href="http://www.itbusinessedge.com/item/?ci=23960">TJX is currently being sued by several banks</a><br />
who seek compensation for having to re-issue credit cards and credit monitoring to thousands of their customers as a result of a massive security breach earlier this year. Depending on how the case turns out, the burdens and cost of breaches will shift away from consumers, banks, and credit unions but will perhaps be shared by the retailers and others (of course, the consumer pays in the end).</p>
<p><strong>Preparing for the change</strong><br />
As a consequence of new state and federal legislation, the landscape of data security will continue to evolve, sometimes in seemingly dramatic fashion. Individuals and businesses will most likely be able to get their day in court for incurred damages a result of security breaches by a third-party. Industries that have for now been able to get away with having minimum security standards will begin to take notice of their potential liability and hopefully, will improve the way they guard information. While the process is slow, it appears to be inevitable.</p>
<p>This isn&#8217;t doom and gloom.</p>
<p>Many of us have already begun to prepare for these changes by improving and writing security policies that make sense and can be understood, improving the process of protecting information and working to involve users in solution through training and awareness. Focus on the fundamentals of information protection and you&#8217;ll be less likely to be the test case.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fdo-data-breach-laws-give-you-the-power-to-hold-corporations-liable-2%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fdo-data-breach-laws-give-you-the-power-to-hold-corporations-liable-2%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/do-data-breach-laws-give-you-the-power-to-hold-corporations-liable-2/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
