IT-412 Cyberlaw and Ethics
Short Paper 4-1 Impact of Data Breach
Jason Popejoy
Southern New Hampshire University
The aircraft manufacturing company responsible for reporting the discovered breach is
based in California. As such, they are subject to the state's breach of notification laws.
According to California's Breach Notification Act, Businesses, that own, license, or
maintain the personal information of a local resident of the state, are required to notify
individuals whose data was compromised of the breach (California cyber--Security Law:
Data breach notification 2018). To follow this law, the aircraft manufacturing company
must provide written notice of the breach to each of its employees who reside in
California as soon as possible. They must also electronically submit a sample copy of the
security breach notification, excluding the personal information of its employees, to the
state of California Attorney General's office if more than 500 residents had to be notified
of the breach (State of California Department of Justice, 2019)
The company had contracts within the U.S. Government as well. Because of these
government contracts, the company must also adhere to data security guidelines set forth
by the Federal Information Security Act (FISMA). FISMA sets the guidelines and
security standards meant to protect government information and operations (Gillis, 2020)
The company must "report security incidents to the Cybersecurity and Infrastructure
Security Agency at the Department of Homeland Security" to comply with FISMA "-
including the attack vector used, impact category and other attributes" (Johnson, 2019).
The company should look at current security procedures, correcting
vulnerabilities that might be found, to prevent future breaches. A company-wide meeting
should also be conducted to refamiliarize employees with security rules and procedures.
Password requirements should be improved, and simple passwords should not be used to
grant system access. Lastly, multi-factor authentication processes should be in place for
any employees with remote access to the company's network, ensuring secure remote
connections.
References
Gillis, A. S. (2020, September 22). What is Fisma (Federal information security Management
Act)? Retrieved from https://searchsecurity.techtarget.com/definition/Federal-Information-
Security-Management-Act
Johnson, D. B. (2019, November 20). Updated FISMA guidance puts new REPORTING
mandates on agencies. Retrieved from https://fcw.com/articles/2019/11/20/fisma-updates-
johnson.aspx
Lewis Brisbois Bisgaard & Smith LLP (Ed.). (2021, January 1). California data breach
notification statute summary. Retrieved from
https://lewisbrisbois.com/privacy/US/California/data-breach
State of California Department of Justice. (2019, May 17). Data security breach reporting
Retrieved from https://oag.ca.gov/privacy/databreach/reporting