The Cyber Attack and Hacking Epidemic A Legal and Business Survival Guide



Similar documents
How To Comply With The Pci Ds.S.A.S

Mastering Data Privacy, Social Media, & Cyber Law

Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation

Mastering Data Privacy, Protection, & Forensics Law

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation

Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation

worldpay.com Understanding the 12 requirements of PCI DSS SaferPayments Be smart. Be compliant. Be protected.

Payment Card Industry Data Security Standards.

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

La règlementation VisaCard, MasterCard PCI-DSS

PCI Security Compliance

PCI Compliance: How to ensure customer cardholder data is handled with care

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

And Take a Step on the IG Career Path

PAYMENT CARD INDUSTRY (PCI) SECURITY STANDARDS COUNCIL

Josiah Wilkinson Internal Security Assessor. Nationwide

FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY

COLORADO STATE UNIVERSITY Financial Procedure Statements FPI 6-6

12/4/2013. Regulatory Updates. Eric M. Wright, CPA, CITP. Schneider Downs & Co., Inc. December 5, 2013

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS)

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Frequently Asked Questions

How To Protect Your Business From A Hacker Attack

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012

Information for merchants. Program implementation details for merchants. Payment Card Industry Data Security Standard (PCI DSS)

An article on PCI Compliance for the Not-For-Profit Sector

PCI Compliance Top 10 Questions and Answers

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

Merchant guide to PCI DSS

PCI Compliance: Protection Against Data Breaches

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No MERCHANT DEBIT AND CREDIT CARD RECEIPTS

PCI DSS Payment Card Industry Data Security Standard. Merchant compliance guidelines for level 4 merchants

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE

Payment Card Industry Data Security Standards Compliance

PCI Standards: A Banking Perspective

PCI Compliance. Top 10 Questions & Answers

Two Approaches to PCI-DSS Compliance

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism

PLACE GROUP UK LONDON STUDENT HOUSING GROUP PAYMENT CARD INDUSTRY DATA SECURITY STANDARD COMPLIANCE STATEMENT PCI DSS (09) VERSION: 2009PCIDSSP4S01

Security Breaches and Vulnerability Experiences Overview of PCI DSS Initiative and CISP Payment Application Best Practices Questions and Comments

How To Protect Your Credit Card Information From Being Stolen

PCI-DSS: A Step-by-Step Payment Card Security Approach. Amy Mushahwar & Mason Weisz

Credit Card Processing Overview

PCI Data Security Standards

Western Australian Auditor General s Report. Information Systems Audit Report

How To Protect Visa Account Information

Strategies To Effective PCI Scoping ISACA Columbus Chapter Presentation October 2008

PCI DATA SECURITY STANDARD OVERVIEW

PCI COMPLIANCE GUIDE For Merchants and Service Members

Appendix 1 Payment Card Industry Data Security Standards Program

PCI DSS COMPLIANCE DATA

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development

Payment Card Industry Security Standards PCI DSS, PCI-PTS and PA-DSS

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

CardControl. Credit Card Processing 101. Overview. Contents

Fraud Protection, You and Your Bank

Need to be PCI DSS compliant and reduce the risk of fraud?

Accelerating PCI Compliance

Payment Card Industry Data Security Standard (PCI DSS) v1.2

PCI DSS. Payment Card Industry Data Security Standard.

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

Client Advisory October Data Security Law MGL Chapter 93H and 201 CMR 17.00

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

Click&DECiDE s PCI DSS Version 1.2 Compliance Suite Nerys Grivolas The V ersatile BI S o l uti on!

Protecting Personal Information: The Massachusetts Data Security Regulation (201 CMR 17.00)

PREPARING FOR THE NEW PCI DATA SECURITY STANDARDS

Accepting Payment Cards and ecommerce Payments

WHITEPAPER. Achieving Network Payment Card Industry Data Security Standard (PCI DSS) Compliance with NetMRI

Project Title slide Project: PCI. Are You At Risk?

Preventing. Payment Card Fraud. Is your business protected?

SecurityMetrics Introduction to PCI Compliance

PCI (Payment Card Industry) Compliance For Healthcare Offices By Ron Barnett

White Paper. Guide to PCI Application Security Compliance for Merchants and Service Providers

E Pay. A Case Study in PCI Compliance. Illinois State Treasurer. Dan Rutherford

Transcription:

The Cyber Attack and Hacking Epidemic A Legal and Business Survival Guide Practising Law Institute January 9, 2012 Melissa J. Krasnow, Partner, Dorsey & Whitney LLP, and Certified Information Privacy Professional This presentation was created by Dorsey & Whitney LLP, 50 South Sixth Street, Suite 1500, Minneapolis, MN 55402. This presentation is intended for general information purposes only and should not be construed as legal advice or legal opinions on any specific facts or circumstances. An attorney-client relationship is not created or continued by sending and/or receiving this presentation. Members of?dorsey & Whitney will be pleased to provide further information regarding the matters discussed in this presentation.

SEC Guidance on Cybersecurity and Cyber Incident Disclosure Securities and Exchange Commission (SEC) guidance about public company disclosure of cybersecurity risks and cyber incidents: not a rule, regulation or statement of the SEC no disclosure requirement specifically refers to cybersecurity risks and cyber incidents certain disclosure obligations may require discussion of cybersecurity risks and cyber incidents

SEC Guidance on Cybersecurity and Cyber Incident Disclosure risk factors (if among the most significant factors that make an investment in the company speculative or risky), for example: aspects of the company s business that give rise to material cybersecurity risks and the potential costs and consequences description of material cyber incidents experienced by the company and the costs and other consequences

SEC Guidance on Cybersecurity and Cyber Incident Disclosure management s discussion and analysis of financial condition and results of operations description of business (if materially affects its products, services, relationships with customers or suppliers or competitive conditions) legal proceedings (where a party to a material pending legal proceeding that involves a cyber incident) disclosure controls and procedures (where poses a risk to the company s ability to record, process, summarize and report information required to be disclosed in SEC filings) financial statement disclosure

Legislative Response to Cyber Attacks and Breaches Cybersecurity legislation with critical infrastructure focus called for by the Obama administration Calls for national breach notification law Amendments to state breach notification laws (e.g., California, Illinois and Texas)

Massachusetts Privacy Regulation Covers an entity (regardless of whether in Massachusetts) with access to Massachusetts resident personal information (including name plus Social Security number, name plus driver's license number or name plus financial account number or credit or debit card number)

Massachusetts Privacy Regulation Requires an entity to implement a written information security program (WISP): encryption of personal information transmitted wirelessly and stored on portable devices third party service provider to an entity by contract provision must implement and maintain appropriate security measures for personal information (March 1, 2012 deadline for contracts entered into on or before March 1, 2010; effective for contracts entered into after March 1, 2010) documentation of actions taken in response to incident involving a breach and mandatory post-incident review to make changes in business practices for protection of personal information

Massachusetts Privacy Regulation Reporting a breach to the Massachusetts attorney general (which is required under the Massachusetts breach notification law) could trigger an investigation of a reporting entity, including that the entity submit its WISP for review Massachusetts attorney general enforcement actions Other states have laws addressing security procedures (e.g., California) and encryption (e.g., Nevada)

PCI DSS Payment Card Industry Security Standards Council (PCI SSC) comprises payment card brands American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. PCI SSC sets the Payment Card Industry Data Security Standard (PCI DSS) and works on a threeyear lifecycle to update PCI DSS PCI DSS is the global data security standard for all entities that process, store or transmit cardholder data, consisting of 12 requirements

PCI DSS Requirements 1. Install and maintain a firewall configuration to protect cardholder data 2. Do not use vendor-supplied defaults for system passwords and other security parameters 3. Protect stored cardholder data 4. Encrypt transmission of cardholder data across open, public networks 5. Use and regularly update anti-virus software or programs 6. Develop and maintain secure systems and applications

PCI DSS Requirements 7. Restrict access to cardholder data by business need-to-know 8. Assign a unique ID to each person with computer access 9. Restrict physical access to cardholder data 10.Track and monitor all access to network resources and cardholder data 11. Regularly test security systems and processes 12.Maintain a policy that addresses information security for all personnel

PCI DSS Compliance and Validation Compliance is the continuous state of adhering to the standard Validation is a point-in-time event that attempts to measure and describe the level of adherence to the standard 21% of entities were found fully compliant at the completion of their initial report on compliance (2011 Verizon PCI Compliance Report) 11% of entities suffering payment card breaches were compliant with PCI DSS at the time of the breach based on the last official audit or selfassessment (2011 Verizon Data Breach Investigations Report)

Payment Card Brand Requirements and State Requirements Relating to PCI DSS Each payment card brand has its own program for compliance, validation levels and enforcement Minnesota, Nevada and Washington have laws addressing compliance with PCI DSS In March 2011 Massachusetts attorney general enforcement action, company is required to comply with PCI DSS and verify compliance with the Massachusetts attorney general s office