Find White Papers
Home
About Us
List Your Papers
    
> Cenzic > Cenzic Software: Identity Theft Laws And Application Security

Cenzic Software: Identity Theft Laws And Application Security

White Paper Published By: Cenzic

The Cenzic Hailstorm® solution helps companies comply with AB 1950, allowing companies to use automated processes to manage their security. Hailstorm is a key tool for preventing breaches.



Tags : 
identity theft, application security, password management, security management, compliance, california sb 1386, senate bill 1386, ab 1950

Cenzic
Published:  Nov 29, 2006
Type:  White Paper
Length:  20 pages

California Identity Theft Laws
And Application Security
AB 1950, SB 1386, and BeyondTable of Contents
Executive Summary........................................................................................................................3
Rising Public Anxiety About Identity Theft.........................................................................................4
The California Legislature Steps In...................................................................................................5
(a) SB 1386: Security Breach Notification...........................................................................6
(b) AB 1950: Protection of Personal Information..................................................................8
Identity Theft Laws Beyond California...............................................................................................10
The Application Security Link in the Compliance Chain......................................................................10®The Cenzic Hailstorm Solution for Assisting in Identity Theft Law Compliance ...................................11
California Identity Theft Law Compliance Chart.................................................................................13
Appendix SB 1386 and AB 1950: Selected Sections from the California Civil Code ............................16
Cenzic developed this white paper with the assistance of Infoliance, Inc. (www.infoliance.com)
Nothing in this white paper is intended as legal advice. Please consult competent legal counsel if you have legal questions.Executive Summary
An April 2002 security breach at California's Stephen P. Teale Data Center triggered public outrage. It eventually led to California's security breach notification law called SB 1386. SB 1386 calls for notification of California residents following some kinds of security breaches. On January 1, 2005, California legislation called AB 1950 went into effect. It requires businesses to protectcertain "personal information." A steady wave of security breaches involving the theft or loss of personal information in 2005 underscores the vulnerability of personal information to hackers seeking identity theft targets. It is likely that incident response costs, legal fees, and the losses from tarnished reputations imposed enormous costs on the organizations falling prey to these security breaches.
AB 1950 addresses companies owning or licensing certain personal information about California residents. These companies must implement reasonable security procedures and practices to prevent the unauthorized access, destruction, use, modification, or disclosure of that personal information. SB 1386 requires businesses and state agencies to notify California residences of breaches in the security of certain "personal information" in computerized records. Other states have enacted legislation similar to SB 1386. Federal legislation is pending in Congress.
Application security and automated tools to assess application security vulnerabilities protect computerized information accessible through web-enabled applications. Accordingly, application security tools are crucial for preventing unauthorized access, destruction, use, modification, or disclosure of personal information available through web applications, as required by AB 1950. ®The Cenzic Hailstorm solution helps companies comply with AB 1950, because companies can use automated processes to asses risk, check for vulnerabilities, test code and controls during software development for the purpose of preventing unauthorized access, destruction, use, modification, or disclosure of personal information. Also, companies that successfully prevent security breaches have no breaches to report under SB 1386 or similar laws. And the Hailstorm solution is a key tool to preventing breaches from occurring.WHITE PAPER
I. Rising Public Anxiety About Identity Theft
On April 5, 2002, hackers exploited vulnerabilities in a server holding a database of personnel information on California's 265,000 state employees. The victims included then-Governor Grey Davis and 120 state legislators. The security breach at California's Stephen P. Teale Data Center in Rancho Cordova compromised names, Social Security numbers, and payroll information. Public outrage soon followed the May 24, 2002 public ... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search