Complying with U.S. Security Regulations
摘要
What security regulation(s) must your organization adhere to? What must you implement as part of that regulation? How important is it to adhere to security regulations? This section briefly addresses these issues and explains implications of non-compliance. In the United States, news agencies have reported that large companies found to violate security regulation have had to pay millions of dollars to government agencies (often to the Federal Trade Commission or FTC). They are often set up with a special program of remediation and monitoring for an extended period of time [3]. These fines and remedial actions are intended to protect individuals from corporations who do not safeguard the security of their customers. Example cases will be described for each regulation. The intention is not to embarrass any particular organization, but rather to illustrate the issues. This chapter includes three sections: (1) U.S. security-oriented laws organizations must adhere to (e.g., HIPAA); (2) criminal laws that protect organizations (e.g., anti-hacking); and (3) an advanced section on the context of U.S. law.