FTC Provides Data Security Guidance to Businesses Based on Lessons From Past Enforcement Actions

Robinson+Cole Data Privacy + Security Insider
Contact

On June 30th, the Federal Trade Commission (FTC) published a guide titled Start With Security: A Guide for Business, providing 10 lessons learned from the over 50 enforcement actions brought by the FTC against companies that failed to adequately protect consumer data. The lessons and advice offered by the FTC guide are certainly common-sense, but present a good refresher for businesses looking to adopt “best practices” for securing customer data and protect against system breaches.

  1. Start with security
  2. Control access to data sensibly
  3. Require secure passwords and authentication
  4. Store sensitive personal information securely and protect it during transmission
  5. Segment your network and monitor who’s trying to get in and out
  6. Secure remote access to your network
  7. Apply sound security practices when developing new products
  8. Make sure your service providers implement reasonable security measures
  9. Put procedures in place to keep your security current and address vulnerabilities that may arise
  10. Secure paper, physical media and devices

For each of the above 10 lessons, the FTC guide provides specific advice and examples of cases where business failed to adequately protect data, resulting in enforcement actions. From a business policy perspective, the key takeaway is for businesses to be aware of the risks associated with collecting, using and accessing customer data. Collect only the data about your customers you need, ensure that access to sensitive data is strictly limited to necessary individuals within your business and implement systems covering all phases of data’s life cycle.

The FTC guide can be accessed on the FTC’s website at the following link: https://www.ftc.gov/system/files/documents/plain-language/pdf0205-startwithsecurity.pdf

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide