Defining "Reasonable Security" in 2017

No ratings

Presented at BSidesNola 2017 by

In 2016, a shared legal understanding of what reasonable security looks like continued to evolve, propelled by a number of forces, including new laws and regulations and new regulatory enforcement actions at the state and federal level. In the civil litigation arena, a number of prominent, long-running data breach cases continue to be litigated, and new ones have been filed. As a major development in data breach cases, courts have become more willing to acknowledge that consumers are harmed when their information is compromised. Related to these developments: increasingly, information security personnel are call on to fill various roles in litigation—as witnesses, whistleblowers, and defendants. The visibility of information security personnel will increase with the prevalence, interconnectedness, and invasiveness of new technology applications. All of these forces affect the current legal understanding of what reasonable security, or lack of it, looks like.