Retaliatory Hacking: Risky Business or Legitimate Corporate Security?
|
|
|
- Erin Morgan Page
- 10 years ago
- Views:
Transcription
1 Retaliatory Hacking: Risky Business or Legitimate Corporate Security? 1
2 Presenter: Sean L. Harrington Cybersecurity Partnership Manager and information security risk assessor in the banking industry; Digital forensics examiner in private practice; Graduate with honors from Taft Law School, and holds the MCSE, CISSP, CHFI, CCFP, and CSOXP certifications; Has served on the board of the Minnesota Chapter of the High Technology Crime Investigation Association; Current member of Infragard, FS-ISAC, the Financial Services Roundtable s legislative and regulatory working groups, Chamber of Commerce Cyber Working Group, among others; Teaches digital forensics for Century College in Minnesota; An instructor for the new CCFP certification. 2
3 Not Legal Advice This presentation is based upon a scholarly work, and is intended to promote discussion and innovation. This presentation is not intended to convey legal advice. Readers should not act or refrain from acting based upon the presenter s oral or written statements 3
4 Resources The CIP Report, George Mason University Center for Infrastructure Protection and Homeland Security, Volume 12, No. 4 (Oct., 2013) Services.pdf, pp Cyber Security Active Defense: Playing with Fire or Sound Risk Management? 20 RICH. J.L. & TECH. 1 (2014) (draft copy available at 4
5 Preview 1.Key terms & concepts 2.Key statutes 3.Active Defense Approaches & associated legal, regulatory, ethical, and practical considerations 4.theories rationalizing active defense 5.Promising alternatives 5
6 TRIVIA When was the last time any substantive cyber security federal legislation was passed, and what was it? 6
7 TRIVIA The Computer Fraud and Abuse Act (CFAA) and Electronic Communications Privacy Act (ECPA) make reference to the Internet how many times? 7
8 Who cares? Lawyers Plaintiff & Defense In-house & outside counsel Compliance Attorneys CISO/ISO Boards and Organizational Leadership Information Security Professionals 8
9 Active Defense Hack Back Offensive Counter Measures ( OCM ) Retaliatory Hacking Protecting and defending 9 electronic information
10 Federal Statutory Prohibitions Computer Fraud and Abuse Act of 1986 Provides both civil and criminal penalties for violation Electronic Communications and Privacy Act of 1986 Provides both civil and criminal penalties for violation Title I: Wiretap Act Title II: Stored Communications Act Title III: pen register and trap and trace devices 18 U.S.C. 2252; 18 U.S.C. 2252A* Many states have counterpart statutes, some of which contain more specific language and are less antiquated. 10
11 CFAA Directed at criminal computer hacking Prohibits computer intrusions accessing computers without authorization, or exceed[ing] authorize[d] access, which statutory phrases have been the continuing subject of appellate review. Private parties who can show damage or loss in excess of $5,000, which can include the cost of hiring a forensic examiner plus his or her assessment of the damage caused to the victim s computer or business, can sue. The Government can pursue felony charges if damages are in excess of $5,000 House Judiciary Committee considering augmenting the Act all offenses would be felonies 11
12 ECPA Title I Update of the original wiretap law of 1968 Prohibits interception, disclosure, or use of wire, oral, and electronic communications in transit must be contemporaneous with transmission examples: , text/video messaging, keystrokes (some courts) Prohibits public Internet carriers from disclosing content of in-transit 12
13 Privacy CA and MN Data handling Data Breach Notification PCI DSS Gramm-Leach-Bliley Act: requires financial institutions to protect information collected about individuals, and prohibits disclosure of their customers' account numbers 13
14 ECPA Title II (Stored Communications Act) Applies to ISPs. Inapplicable to private companies internal systems. Restricts Government access to customer and subscriber information and records Providers may disclose protected information if: Consent is given by the sender, an addressee, or the recipient Content was inadvertently obtained and appears to contain evidence of the commission of a crime 14
15 Ethics Codes of Conduct describes the expected behavior of members of an association or practitioners of a profession, and generally seek to protect the organization or profession from the consequences of bad behavior of its members. ABA Model Rules 1.2, 5.3, 8.4(c) (ISC) 2 Code of Ethics Preamble* (ISC) 2 Code of Ethics Cannons** Model Rules 15
16 Active Defense Approaches Approaches Risks Beaconing Threat Intelligence Gathering Sinkholing Honeypots Retaliatory Hacking Legal Ethical Escalation Misattribution and collateral damage Goodwill & reputation 16
17 Active Defense Hack Back Theories advanced for justified retaliatory hacking: Recapture of chattels private necessity Castle doctrine private security guard doctrine 17
18 Promising Alternatives to Hack Back Preventive: Private companies collaboration with ISPs and industry partnerships to combat; Intelligence sharing and gathering (ISACs); Harden the perimeter Detective: tools; know your network traffic; Corrective: collaboration with government and other private corporations: (e.g., takedowns of Citadel, Zeus) Corrective: cyber legislation Risk transfer: outsourcing, cyber insurance 18
19 Common Sense Thoughts Develop and enforce sound initial security hardening practices Develop and enforce incident handling policies and procedures consistent with company position Develop and implement and participate in collaborative task forces among governmental and private companies with similar problems Caution and prudence before attempting to respond to a hack with affirmative defense approaches 19
20 Questions? Comments? 20
21 Thank You! Sean L. Harrington 21
JAN 2 2 2016. (a) The obstruction, impairment, or hindrance of the. (b) The obstruction, impairment, or hindrance of any
~ (c) S.B. NO. \ JAN 0 A BILL FOR AN ACT THE SENATE TWENTY-EIGHTH LEGISLATURE, 0 STATE OF HAWAII RELATING TO LAW ENFORCEMENT. BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF HAWAII: ' SECTION. Section
DEPARTMENT OF JUSTICE WHITE PAPER. Sharing Cyberthreat Information Under 18 USC 2702(a)(3)
DEPARTMENT OF JUSTICE WHITE PAPER Sharing Cyberthreat Information Under 18 USC 2702(a)(3) Background Improved information sharing is a critical component of bolstering public and private network owners
The Law of Web Application Hacking. CanSecWest March 9, 2011 Marcia Hofmann, EFF
The Law of Web Application Hacking CanSecWest March 9, 2011 Marcia Hofmann, EFF what we ll talk about today Three situations you should recognize and approach with caution when you re doing security research
CHAPTER 121 STORED WIRE AND ELECTRONIC COMMUNICATIONS AND TRANSACTIONAL RECORDS ACCESS
18 U.S.C. United States Code, 2010 Edition Title 18 - CRIMES AND CRIMINAL PROCEDURE PART I - CRIMES CHAPTER 121 - STORED WIRE AND ELECTRONIC COMMUNICATIONS AND TRANSACTIONAL RECORDS ACCESS CHAPTER 121
Legislative Language
Legislative Language SECTION 1. DEPARTMENT OF HOMELAND SECURITY CYBERSECURITY AUTHORITY. Title II of the Homeland Security Act of 2002 (6 U.S.C. 121 et seq.) is amended (a) in section 201(c) by striking
THE COUNTY OF MONTGOMERY POLICIES AND PROCEDURES FALSE CLAIMS AND WHISTLEBLOWER PROTECTIONS
THE COUNTY OF MONTGOMERY POLICIES AND PROCEDURES POLICY It is the obligation of the County of Montgomery (the County ) to prevent and detect any fraud, waste and abuse in its organization related to Federal
In an age where so many businesses and systems are reliant on computer systems,
Cyber Security Laws and Policy Implications of these Laws In an age where so many businesses and systems are reliant on computer systems, there is a large incentive for maintaining the security of their
Legal and Ethical Issues Facing Computer & Network Security Researchers
Legal and Ethical Issues Facing Computer & Network Security Researchers Aaron Burstein UC Berkeley School of Information November 23, 2009 Constraints on Network Research U.S. law is often unclear (and
Information Security Law: Control of Digital Assets.
Brochure More information from http://www.researchandmarkets.com/reports/2128523/ Information Security Law: Control of Digital Assets. Description: For most organizations, an effective information security
Please see Section IX. for Additional Information:
The Florida Senate BILL ANALYSIS AND FISCAL IMPACT STATEMENT (This document is based on the provisions contained in the legislation as of the latest date listed below.) BILL: CS/CS/SB 222 Prepared By:
Cyber Warfare. Global Economic Crime Survey. Causes of Cyber Attacks. David Childers, CEO Compli Vivek Krishnamurthy, Foley Hoag LLP. Why Cybercrime?
Cyber Warfare David Childers, CEO Compli Vivek Krishnamurthy, Foley Hoag LLP Global Economic Crime Survey Cyber crime is the fastest growing economic crime up more than 2300% since 2009 1 in 10 companies
114 th Congress March, 2015. Cybersecurity Legislation and Executive Branch Activity I. ADMINSTRATION S CYBERSECURITY PROPOSALS
114 th Congress March, 2015 Cybersecurity Legislation and Executive Branch Activity I. ADMINSTRATION S CYBERSECURITY PROPOSALS On January 13, 2015, the Administration wrote a letter to Congress urging
UNITED STATES DISTRICT COURT DISTRICT OF MINNESOTA Criminal No.:
UNITED STATES DISTRICT COURT DISTRICT OF MINNESOTA Criminal No.: UNITED STATES OF AMERICA, ) ) Plaintiff, ) DEFERRED PROSECUTION ) AGREEMENT v. ) ) BIXBY ENERGY SYSTEMS, INC., ) ) Defendant. ) The United
Cyber-insurance: Understanding Your Risks
Cyber-insurance: Understanding Your Risks Cyber-insurance represents a complete paradigm shift. The assessment of real risks becomes a critical part of the analysis. This article will seek to provide some
Cyber Security for the Private Sector: What Companies and Their Lawyers Need to Know
Cyber Security for the Private Sector: What Companies and Their Lawyers Need to Know Gus Coldebella, Goodwin Procter LLP John Geschke, VP and General Counsel, Zendesk, Inc. Jim Jaeger, VP, Cybersecurity
ESTABLISHING POLICY AND PROCEDURES FOR COMPLIACE WITH 42 USC 139a(a)(68), False Claims and Whistle Blower Protections
RESOLUTION NO. COA-falseclaimsandwhistlesrev. 93-10 Date: 2/23/2010 ESTABLISHING POLICY AND PROCEDURES FOR COMPLIACE WITH 42 USC 139a(a)(68), False Claims and Whistle Blower Protections BY: Mr. George
VNSNY CORPORATE. DRA Policy
VNSNY CORPORATE DRA Policy TITLE: FEDERAL DEFICIT REDUCTION ACT OF 2005: POLICY REGARDING THE DETECTION & PREVENTION OF FRAUD, WASTE AND ABUSE AND APPLICABLE FEDERAL AND STATE LAWS APPLIES TO: VNSNY ENTITIES
Cybercrime: A Sketch of 18 U.S.C. 1030 and Related Federal Criminal Laws
Order Code RS20830 Updated February 25, 2008 Cybercrime: A Sketch of 18 U.S.C. 1030 and Related Federal Criminal Laws Summary Charles Doyle Senior Specialist American Law Division The federal computer
HB659 151295-1. By Representative Hall. RFD: Judiciary. First Read: 23-APR-13. Page 0
HB -1 By Representative Hall RFD: Judiciary First Read: -APR-1 Page 0 -1:n:0/0/01:JET/mfc LRS01-1 1 1 1 1 1 1 1 1 0 1 SYNOPSIS: Under existing law, a court or magistrate may issue a warrant for the search
PRINCIPLES AND PRACTICE OF INFORMATION SECURITY
PRINCIPLES AND PRACTICE OF INFORMATION SECURITY Protecting Computers from Hackers and Lawyers Linda Volonino, Ph.D. Canisius College Stephen R. Robinson Verity Partners, LLC with contributions by Charles
Cybersecurity Issues for Community Banks
Eastern Massachusetts Compliance Network Cybersecurity Issues for Community Banks Copyright 2014 by K&L Gates LLP. All rights reserved. Sean P. Mahoney [email protected] K&L Gates LLP State Street
SUBSCRIBER PRIVACY NOTICE
PRIVACY AND SECURITY NewWave will provide you with a copy of its privacy notice at the time Service is installed, and annually afterwards, or as otherwise permitted by law. Customer can view the most current
Fraud, Waste and Abuse Prevention and Education Policy
Corporate Compliance Fraud, Waste and Abuse Prevention and Education Policy The Compliance Program at the Cortland Regional Medical Center (CRMC) demonstrates our commitment to uphold all federal and state
Computer Forensics US-CERT
Computer Forensics US-CERT Overview This paper will discuss the need for computer forensics to be practiced in an effective and legal way, outline basic technical issues, and point to references for further
Joe A. Ramirez Catherine Crane
RIMS/RMAFP PRESENTATION Joe A. Ramirez Catherine Crane RISK TRANSFER VIA INSURANCE Most Common Method Involves Assessment of Risk and Loss Potential Risk of Loss Transferred For a Premium Insurance Contract
Communications and Privacy: The Impact of Changing Regulations and Technology on an Organization s Privacy and Data Protection Policies
Communications and Privacy: The Impact of Changing Regulations and Technology on an Organization s Privacy and Data Protection Policies K.C. Halm, Davis Wright Tremaine, LLP Greg Kopta, Davis Wright Tremaine,
Cyber Risks in the Boardroom
Cyber Risks in the Boardroom Managing Business, Legal and Reputational Risks Perspectives for Directors and Executive Officers Preparing Your Company to Identify, Mitigate and Respond to Risks in a Changing
Secretary of the Senate. Chief Clerk of the Assembly. Private Secretary of the Governor
Senate Bill No. 467 Passed the Senate September 10, 2013 Secretary of the Senate Passed the Assembly September 9, 2013 Chief Clerk of the Assembly This bill was received by the Governor this day of, 2013,
Summary of Privacy and Data Security Bills- 112 th Congress. Prepared for September 15, 2011 CT Privacy Forum
Summary of Privacy and Data Security Bills- 112 th Congress Prepared for September 15, 2011 CT Privacy Forum GEOLOCATION TRACKING The Location Privacy Protection Act of 2011 (S. 1223)- introduced by s
U. S. Attorney Office Northern District of Texas March 2013
U. S. Attorney Office Northern District of Texas March 2013 What Is Cybercrime? Hacking DDOS attacks Domain name hijacking Malware Other computer related offenses, i.e. computer and internet used to facilitate
Committee on Civil Liberties, Justice and Home Affairs - The Secretariat - Background Note on
Committee on Civil Liberties, Justice and Home Affairs - The Secretariat - Background Note on US Legal Instruments for Access and Electronic Surveillance of EU Citizens Introduction This note presents
EXECUTIVE SUMMARY Compliance Program and False Claims Recovery
EXECUTIVE SUMMARY Compliance Program and False Claims Recovery INTRODUCTION: The Federal Deficit Reduction Act of 2005, also known as the DRA, requires that providers give their employees, medical staff,
Social Media In the Workplace
Social Media In the Workplace By Randy Green and John Michael Ekblad 306 West Church Street, Champaign, IL 61820 (217)352-1800 Overview: Social Media What is it? Risks Presented Properly Regulating Employee
VILLAGECARE CORPORATE COMPLIANCE POLICY AND PROCEDURE MANUAL ORIGINAL EFFECTIVE DATE: JANUARY 1, 2007
VILLAGECARE CORPORATE COMPLIANCE POLICY AND PROCEDURE MANUAL SUBJECT: COMPLIANCE WITH FEDERAL AND STATE FALSE CLAIMS LAWS AND DETECTION AND PREVENTION OF FRAUD, WASTE AND ABUSE LAST POLICY REVISION EFFECTIVE
What are you trying to secure against Cyber Attack?
Cybersecurity Legal Landscape Bonnie Harrington Executive Counsel EHS and Product Safety & Cybersecurity GE Energy Management Imagination at work. What are you trying to secure against Cyber Attack? Personally
Minnesota State Colleges and Universities System Procedures Chapter 5 Administration. Guideline 5.23.1.4 Information Security Incident Response
Minnesota State Colleges and Universities System Procedures Chapter 5 Administration Information Security Incident Response Part 1. Purpose. This guideline establishes the minimum requirements for Information
12.809 COURT ORDERS FOR TELEPHONE RECORDS
12.809 COURT ORDERS FOR TELEPHONE RECORDS References: United States Code (USC) 18USC2510-18USC2522, et al - Federal Wiretap Statutes 18USC2703 - Release of Subscriber Information to Law Enforcement under
The Cyber Attack and Hacking Epidemic A Legal and Business Survival Guide
The Cyber Attack and Hacking Epidemic A Legal and Business Survival Guide Practising Law Institute January 9, 2012 Melissa J. Krasnow, Partner, Dorsey & Whitney LLP, and Certified Information Privacy Professional
Fraud-Related Compliance
Fraud-Related Compliance Investigating and Reporting 2015 Association of Certified Fraud Examiners, Inc. Investigations, Reporting, and Compliance Investigations benefit victim organizations by: Recovering
technical factsheet 176
technical factsheet 176 Data Protection CONTENTS 1. Introduction 1 2. Register with the Information Commissioner s Office 1 3. Period protection rights and duties remain effective 2 4. The data protection
2. "Consumer" means an individual. (same as 15 U.S.C. 1681a(c))
Combo security freeze bill with consensus areas. Where no consensus: AG language in left column, CDIA language in right column. In some cases, differences on specific points are identified in text of bill.
CYBERCRIME LAWS OF THE UNITED STATES
CYBERCRIME LAWS OF THE UNITED STATES United States Code, Title 18, Chapter 121 STORED WIRE AND ELECTRONIC COMMUNICATIONS AND TRANSACTIONAL RECORDS ACCESS 2701. Unlawful access to stored communications
E-mail Marketing: CAN- SPAM Act Compliance David J. Ervin and Christopher M. Loeffler, Kelley Drye and Warren LLP
E-mail Marketing: CAN- SPAM Act Compliance David J. Ervin and Christopher M. Loeffler, Kelley Drye and Warren LLP This Practice Note is published by Practical Law Company on its PLC Law Department web
Comparison of Information Sharing, Monitoring and Countermeasures Provisions in the Cybersecurity Bills
April 4, 2012 Comparison of Information Sharing, Monitoring and Countermeasures Provisions in the Cybersecurity Bills The chart below compares on civil liberties grounds four bills that seek to promote
FEDERAL & NEW YORK STATUTES RELATING TO FILING FALSE CLAIMS
FEDERAL & NEW YORK STATUTES RELATING TO FILING FALSE CLAIMS I. FEDERAL LAWS False Claims Act (31 USC 3729-3733) The False Claims Act ("FCA") provides, in pertinent part, that: (a) Any person who (1) knowingly
Department of Justice Revises Policies Regarding Waiver of Privilege. Gabriel L. Imperato, Esq.*
Department of Justice Revises Policies Regarding Waiver of Privilege Gabriel L. Imperato, Esq.* The Department of Justice recently modified its Principles for Federal Prosecution of Business Organizations,
Privacy Law Basics and Best Practices
Privacy Law Basics and Best Practices Information Privacy in a Digital World Stephanie Skaff [email protected] What Is Information Privacy? Your name? Your phone number or home address? Your email address?
North Shore LIJ Health System, Inc.
North Shore LIJ Health System, Inc. POLICY TITLE: Detecting and Preventing Fraud, Waste, Abuse and Misconduct POLICY #: 800.09 System Approval Date: 6/23/14 Site Implementation Date: Prepared by: Office
Cybersecurity for Nonprofits: How to Protect Your Organization's Data While Still Fulfilling Your Mission. June 25, 2015
Cybersecurity for Nonprofits: How to Protect Your Organization's Data While Still Fulfilling Your Mission June 25, 2015 1 Your Panelists Kenneth L. Chernof Partner, Litigation, Arnold & Porter LLP Nicholas
SOUTH NASSAU COMMUNITIES HOSPITAL One Healthy Way, Oceanside, NY 11572
SOUTH NASSAU COMMUNITIES HOSPITAL One Healthy Way, Oceanside, NY 11572 POLICY TITLE: Compliance with Applicable Federal and State False Claims Acts POLICY NUMBER: OF-ADM-232 DEPARTMENT: Hospital-wide CROSS-REFERENCE:
Cyber Security and Privacy Services. Working in partnership with you to protect your organisation from cyber security threats and data theft
Cyber Security and Privacy Services Working in partnership with you to protect your organisation from cyber security threats and data theft 2 Cyber Security and Privacy Services What drives your security
How Cybersecurity Initiatives May Impact Operators. Ross A. Buntrock, Partner [email protected] 202.669.0495
How Cybersecurity Initiatives May Impact Operators Ross A. Buntrock, Partner [email protected] 202.669.0495 Agenda! Rise in Data Breaches! Effects of Increase in Cybersecurity Threats! Cybersecurity
Ten Questions Your Board Should be asking about Cyber Security. Eric M. Wright, Shareholder
Ten Questions Your Board Should be asking about Cyber Security Eric M. Wright, Shareholder Eric Wright, CPA, CITP Started my career with Schneider Downs in 1983. Responsible for all IT audit and system
S. ll IN THE SENATE OF THE UNITED STATES A BILL
TH CONGRESS ST SESSION S. ll To codify mechanisms for enabling cybersecurity threat indicator sharing between private and government entities, as well as among private entities, to better protect information
Employers Guide to Best Practices. For Use of Background Checks in Employment Decisions. Copyright 2010 Lawyers Committee for Civil Rights Under Law
Employers Guide to Best Practices For Use of Background Checks in Employment Decisions A 2010 poll of the Society of Human Resource Management shows that approximately 60 percent of employers use credit
THE AMERICAN LAW INSTITUTE Continuing Legal Education. Estate Planning for the Family Business Owner
91 THE AMERICAN LAW INSTITUTE Continuing Legal Education Estate Planning for the Family Business Owner Cosponsored by the ABA Section of Real Property, Trust and Estate Law and the ABA Section of Taxation
requires the legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation.
LEGAL ETHICS OPINION 1814 UNDISCLOSED RECORDING OF THIRD PARTIES IN CRIMINAL MATTERS In this hypothetical, a Criminal Defense Lawyer represents A who is charged with conspiracy to distribute controlled
Digital Evidence Collection and Use. CS 585 Fall 2009
Digital Evidence Collection and Use CS 585 Fall 2009 Outline I. II. III. IV. Disclaimers Crime Scene Processing Legal considerations in Processing Digital Evidence A Question for Discussion Disclaimers
Hit ratios are still very low for Security & Privacy coverage: What are companies waiting for?
Hit ratios are still very low for Security & Privacy coverage: What are companies waiting for? Authored by Neeraj Sahni and Tim Stapleton Neeraj Sahni is Director, Insurance Channel at Kroll Cyber Investigations
Sharing Cybersecurity Threat Info With the Government -- Should You Be Afraid To Do So?
Sharing Cybersecurity Threat Info With the Government -- Should You Be Afraid To Do So? Bruce Heiman K&L Gates September 10, 2015 [email protected] (202) 661-3935 Why share information? Prevention
JOINT EXPLANATORY STATEMENT TO ACCOMPANY THE CYBERSECURITY ACT OF 2015
JOINT EXPLANATORY STATEMENT TO ACCOMPANY THE CYBERSECURITY ACT OF 2015 The following consists of the joint explanatory statement to accompany the Cybersecurity Act of 2015. This joint explanatory statement
Electronic Communications: E-Mail, Voicemail, Telephones, Internet and Computers
Electronic Communications: E-Mail, Voicemail, Telephones, Internet and Computers Key Points Put employees on notice through policies that they should have no expectation of privacy arising from their use
SUMMARY OF PUBLIC LAW 108-187 THE CAN-SPAM ACT OF 2003
SUMMARY OF PUBLIC LAW 108-187 THE CAN-SPAM ACT OF 2003 On December 16, 2003, President Bush signed into law the CAN-SPAM Act of 2003. CAN-SPAM stands for "Controlling the Assault of Non-Solicited Pornography
Law Firm Cyber Security & Compliance Risks
ALA WEBINAR Law Firm Cyber Security & Compliance Risks James Harrison CEO, INVISUS Breach Risks & Trends 27.5% increase in breaches in 2014 (ITRC) Over 500 million personal records lost or stolen in 2014
Accountability Report Card Summary 2013 New Mexico
Accountability Report Card Summary 2013 New Mexico New Mexico has a pretty strong state whistleblower law: Scoring 72 out of a possible 100 points; Ranking 4 th out of 51 (50 states and the District of
HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT OF 1996 HIPAA
TRAINING MANUAL HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT OF 1996 HIPAA Table of Contents INTRODUCTION 3 What is HIPAA? Privacy Security Transactions and Code Sets What is covered ADMINISTRATIVE
COUNTY OF ORANGE. False Claims Act and Whistleblower Provisions Policy and Procedures
COUNTY OF ORANGE False Claims Act and Whistleblower Provisions Policy and Procedures COUNTY OF ORANGE FALSE CLAIMS ACT AND WHISTLEBLOWER PROVISIONS POLICY AND PROCEDURES I. Purpose. The County of Orange
ISBA Advisory Opinion on Professional Conduct
ISBA Advisory Opinion on Professional Conduct ISBA Advisory Opinions on Professional Conduct are prepared as an educational service to members of the ISBA. While the Opinions express the ISBA interpretation
Chicago-Kent College of Law: Career Services Office Public Interest Career Plan
Chicago-Kent College of Law: Career Services Office Public Interest Career Plan When you have completed this survey, please schedule an appointment with Michelle Mohr Vodenik in the Career Services Office,
The DMA s Analysis of Can Spam Act of 2003
The DMA s Analysis of Can Spam Act of 2003 December 11, 2003 The following is a Direct Marketing Association analysis of the Can Spam Act of 2003 (S. 877), which Congress sent to the President for signing
Data Breach and Senior Living Communities May 29, 2015
Data Breach and Senior Living Communities May 29, 2015 Todays Objectives: 1. Discuss Current Data Breach Trends & Issues 2. Understanding Why The Senior Living Industry May Be A Target 3. Data Breach Costs
OKLAHOMA LAWS RELATING TO IDENTITY THEFT
OKLAHOMA LAWS RELATING TO IDENTITY THEFT Prepared for VICARS by Legal Aid Services of Oklahoma Introduction: OKLAHOMA LAWS RELATING TO IDENTITY THEFT Identity theft takes place when someone uses your personal
SECTION-BY-SECTION. Section 1. Short Title. The short title of the bill is the Cybersecurity Act of 2012.
SECTION-BY-SECTION Section 1. Short Title. The short title of the bill is the Cybersecurity Act of 2012. Section 2. Definitions. Section 2 defines terms including commercial information technology product,
