Editor’s Note: “Cybersecurity regulation will take its place alongside environmental regulation, health and safety regulation and financial regulation as a major federal activity” as explained here. However, if cyber security “regulations affecting much of the economy are not cost-effective, the regulatory structure will not have lasting viability and will not boost industrial security irrespective of legal requirements” as explained here.
From: Information Management
The plan – issued last week by an agency of the Commerce Department – establishes a set of best practices for banks and other companies that support critical infrastructure to raise their cybersecurity game.
But several experts say the framework is ultimately likely to be cited in data breach litigation, other consumer claims and even by regulators as a baseline that all institutions must follow.
“It is by law voluntary. But it is going to mutate over time into a de facto or quasi mandatory standard,” said Paul Rosenzweig, founder of Red Branch Consulting and formerly deputy assistant secretary for policy in the Department of Homeland Security. “For one thing, regulators may adopt it and tort lawyers that sue banks may view it as a floor.”
Leave a Reply