BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

The US Government Wants to Secure Your Data. Well, Sort Of.

Posted September 14, 2011    Mike Puterbaugh

Earlier today, George Hulme reported on a recently-introduced piece of legislation, the Personal Data Protection and Breach Accountability Act of 2011 (or PDPBAA for short, which sounds like how my last is pronounced sometimes), geared toward protecting customer data from theft or loss. Senator Richard Blumenthal (D-CT) hopes that this new bill will “prevent and deter data breaches that put people at risk of identity theft and other serious harm both by helping protect consumers’ data before breaches occur”. That sounds good; I think we’d all like that. But as with any type of legislation, the devil is in the details.For example, the proposed bill is targeted towards customers with 10,000 customers or more. Are we customers of Twitter? I’m pretty sure I’m the product they’re selling, not their customer. What constitutes me being a “customer” of a company? I think I have flown once on Frontier Airlines, 3 years ago, but they undoubtedly have my information somewhere. Would that count?

“Data” is a pretty broad term as well.  Credit card numbers, social security numbers, birth dates, even Facebook photos?

(I’m sure there are most details in the bill that bear scrutiny, I was only able to make it through the first 30 pages.)

This isn’t the first, nor will it be the last time that regulations have been proposed to protect end users and their personal data. What I hope most typical consumers realize is, however, most of the companies that they trust with their personal information have extremely sophisticated security measures in place, including comprehensive vulnerability management programs to not only protect your data, but theirs as well.

At the end of the day, if the possibility of losing customers and their brand isn’t a strong enough call to action for your favorite companies to protect your data, then perhaps Senator Blumenthal’s bill and its penalties might be. But I doubt it.

You can check out Hulme’s solid reporting here, at CSO Online.

If you’re not following Hulme on Twitter, you should be, he provides great coverage on the security industry and is also known to share his stock picks from time time.  You can follow me on Twitter here.

Leave a Reply

Additional articles

Sudo_logo

Don’t Create a Different sudoers File for Each System

Posted May 20, 2015    Randy Franklin Smith

What if you have multiple Linux and/or Unix systems? Sudo management can become onerous and unwieldy if you try to manage a different sudoers file on each system. The good news is that sudo supports multiple systems.

password-safety

What Does Microsoft Local Administrator Password Solution Really Do?

Posted May 19, 2015    Morey Haber

LAPS is a feature that allows the randomization of local administrator accounts across the domain. Although it would seem that this capability overlaps with features in BeyondTrust’s PowerBroker Password Safe (PBPS), the reality is it is more suited for simple use cases such as changing the local Windows admin account and not much more.

Tags:
, ,
webinar_ondemand

On Demand Webinar: Securing Windows Server with Security Compliance Manager

Posted May 14, 2015    BeyondTrust Software

On Demand Webinar: Security Expert Russell Smith, explains how to use Microsoft’s free Security Compliance Manager (SCM) tool to create and deploy your own security baselines, including user and computer authentication settings.

Tags:
, ,