California Attorney General Defines Minimum Requirements for 'Reasonable Cybersecurity'

Locke Lord LLP
Contact

California has now weighed in on the definition of “reasonable” security and minimum security requirements for all businesses through the California Attorney General’s 2016 Data Breach Report.

The Report references the legal obligation to secure information, and adopts the views that “Security is a process,” that “Information security laws and regulations generally require a risk management approach,” and that “This means organizations must develop, implement, monitor, and regularly update a comprehensive information security program.”

More importantly, the Report adopts the Critical Security Controls for Effective Cyber Defense released by the Center for Internet Security (formerly known as the SANS Top 20) as the “minimum standard of care for personal information.” According to the Report, “The 20 controls in the Center for Internet Security’s Critical Security Controls define a minimum level of information security that all organizations that collect or maintain personal information should meet. The failure to implement all the Controls that apply to an organization’s environment constitutes a lack of reasonable security.” (Emphasis added.)

Presumably this view will guide their enforcement actions going forward and likely warrants the careful attention of entities seeking to maintain strong information security practices.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Locke Lord LLP | Attorney Advertising

Written by:

Locke Lord LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Locke Lord LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide