California enacts full disclosure security breach law

Wednesday, 2 July 2003, 6:51 AM EST

From July 1 all firms doing business in California will be obliged to advise their customers what data might be disclosed if their systems are ever successfully attacked.

Under the Security Breach Information Act, companies whose systems are broken into by crackers will be expected to report attacks to customers directly or via a notice on their Web site in cases where credit card information or other sensitive customer data has been compromised.

Failure to disclose such embarrassing details at the pertinent time will open the way for California residents to sue offending companies.

The full disclosure regulations, a first of their kind, are designed to put a brake on the growing problem of identity theft - America's fastest growing crime.

[ Read more ]

Related items




Spotlight

Why vulnerability disclosure shouldn’t be a marketing tool

Brian Honan, CEO at BH Consulting, talks about a recent vulnerability disclosure trend – a trend that he believes may ultimately cause more harm than good: security vendors using vulnerability disclosure as a marketing tool with the goal of enhancing their company’s bottom line.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Wed, Jul 1st
    COPYRIGHT 1998-2015 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //