Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Legal Brief: Take Heed: FTC Enforcement in Guidance Case: Page 2 of 2

Another theme runs through the Guidance settlement: Information security requires a systematic approach. Some past FTC enforcement actions (Guess.com, for example) have focused on a single, catastrophic security failure, such as unencrypted PII. But the Guidance complaint sets forth a series of failures, outlined above, suggesting that the commission has increased its expectations for privacy-related data security programs. Specifically, it demands implementation of a broad spectrum of controls, including vulnerability-assessment procedures, encryption, database security, log aggregation and monitoring, and intrusion detection.

Here's the bottom line: The comprehensive nature of these regulatory demands should help drive the approach you take to securing the PII you maintain.

Click here for more information about the Guidance case.

Patrick R. Mueller Is completing his law degree and a master' degree in public affairs at the University Of Wisconsin-Madison, specializing in privacy and data security law and policy. He was previously a senior analyst for security consultancy Neohapsis. Write to him at [email protected].