Explore top 10 tips to secure your open-source projects now. Read More
×Legal experts have warned organizations in certain highly regulated industries that they could be fined twice under new EU security laws with huge maximum penalties.. The GDPR has received most press since it was introduced at the end of May, but for operators of essential services (OES) and digital service providers (DSPs), there’s also a second piece of legislation to consider: the EU directive on the Security of Networks and Information Systems (NIS Directive), introduced a few weeks previously. The link for this article located at InfoSecurity is no longer available. . The GDPR has received most press since it was introduced at the end of May, but for operators of ess. legal, experts, warned, organizations, certain, highly, regulated, industries. . LinuxSecurity.com Team
A new study on "US and European Corporate Privacy Practices" was released two days ago, and as I constantly monitor the topic knowing EU's stricter information sharing and privacy violations laws comparing to the U.S, thought you might find this useful. To sum up the findings: "European companies are much more likely to have privacy practices that restrict or limit the sharing of customer or employees' sensitive personal information and are also more likely to provide employees with choice or consent on how information is used or shared," said David Bender, head of White & Case's Global Privacy practice." still at the "sharing sensitive information is bad" promotional stage, I feel the research reasonable points out the lack of a systematic technical approach, bureaucracy can also be an issue, but with so many CERTs in Europe there's potential for lots of developments I think. Established in 2004, ENISA is the current body overseeing and guiding the Community towards data protection practices -- slowly, but steadily gaining grounds. . "But the research also revealed that US companies are engaging in more security and control-oriented compliance activities than their European counterparts. As a result, US corporations scored higher in five of the eight areas of corporate privacy practice." - structured implementation on a technical level, that is people auditing networks and being accountable in case of not doing so, and privacy policies by default. The link for this article located at Dancho Danchev is no longer available. . Explore the distinctions in corporate privacy protocols between the US and Europe highlighted by a recent analysis.. Corporate Privacy Practices, European Data Protection, US Compliance, Privacy Comparisons, Security Regulations. . LinuxSecurity.com Team
A House committee this week unanimously approved a data security law that would establish federal standards for protecting personal information and would supersede state laws. The Data Accountability and Trust Act, (HR 4127), is one of a spate of bills introduced last year in the wake of publicity about the theft or loss of data that could lead to identity theft. The incidents came to light as a result of state laws requiring consumer notification of security breaches and spurred a consumer demand for tighter regulation. . Data brokers and other companies subject to multiple state laws also have called for a single federal law. The DATA Act is one of the first bills to move out of committee. It was approved Wednesday by a 41 to 0 vote in the House Energy and Commerce Committee. The bill would require the Federal Trade Commission to establish security requirements for interstate businesses holding personal information in an electronic form. Requirements include creating security policies, naming a point person for information security and the use of state-of-the-art security practices. The link for this article located at Government Computer News is no longer available. . A congressional panel has approved legislation to establish national guidelines for data protection, tackling concerns related to consumer safety.. Data Security Bill, Consumer Rights, Information Protection, Federal Legislation. . Brittany Day
The Bush administration has admitted that its plan to combat the threat of cyber terrorism through industry self-regulation is flawed, and companies may be encouraging more restrictive security regulations by declining to work with the Federal Government. Richard Clarke, the . . . . The Bush administration has admitted that its plan to combat the threat of cyber terrorism through industry self-regulation is flawed, and companies may be encouraging more restrictive security regulations by declining to work with the Federal Government. Richard Clarke, the administration's national co-ordinator for security, infrastructure protection and counter-terrorism, warned US corporations this week that self-regulation is not working, and that the US Government could consider regulatory action if companies fail to protect themselves adequately from the threat of cyber terrorism. The link for this article located at vnunet is no longer available. . The Biden administration's acknowledgment uncovers gaps in addressing cyber threats via corporate self-governance.. Cybersecurity Policy, Industry Self-Regulation, Government Response. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.