• Home
  • Southern New Hampshire University
  • Cyberlaw and Ethics IT412
  • Impact of Data Breach in Cyberlaw and Ethics

Impact of Data Breach in Cyberlaw and Ethics

IT-412 Cyberlaw and Ethics Short Paper 4-1 Impact of Data Breach Jason Popejoy Southern New Hampshire University The aircraft manufacturing company responsible for reporting the discovered breach is based in California. As such, they are subject to the state's breach of notification laws. According to California's Breach Notification Act, Businesses, that own, license, or maintain the personal information of a local resident of the state, are required to notify individuals whose data was compromised of the breach (California cyber--Security Law: Data breach notification 2018). To follow this law, the aircraft manufacturing company must provide written notice of the breach to each of its employees who reside in California as soon as possible. They must also electronically submit a sample copy of the security breach notification, excluding the personal information of its employees, to the state of California Attorney General's office if more than 500 residents had to be notified of the breach (State of California Department of Justice, 2019) The company had contracts within the U.S. Government as well. Because of these government contracts, the company must also adhere to data security guidelines set forth by the Federal Information Security Act (FISMA). FISMA sets the guidelines and security standards meant to protect government information and operations (Gillis, 2020) The company must "report security incidents to the Cybersecurity and Infrastructure Security Agency at the Department of Homeland Security" to comply with FISMA "- including the attack vector used, impact category and other attributes" (Johnson, 2019). The company should look at current security procedures, correcting vulnerabilities that might be found, to prevent future breaches. A company-wide meeting should also be conducted to refamiliarize employees with security rules and procedures. Password requirements should be improved, and simple passwords should not be used to grant system access. Lastly, multi-factor authentication processes should be in place for any employees with remote access to the company's network, ensuring secure remote connections. References Gillis, A. S. (2020, September 22). What is Fisma (Federal information security Management Act)? Retrieved from https://searchsecurity.techtarget.com/definition/Federal-Information- Security-Management-Act Johnson, D. B. (2019, November 20). Updated FISMA guidance puts new REPORTING mandates on agencies. Retrieved from https://fcw.com/articles/2019/11/20/fisma-updates- johnson.aspx Lewis Brisbois Bisgaard & Smith LLP (Ed.). (2021, January 1). California data breach notification statute summary. Retrieved from https://lewisbrisbois.com/privacy/US/California/data-breach State of California Department of Justice. (2019, May 17). Data security breach reporting Retrieved from https://oag.ca.gov/privacy/databreach/reporting