The scenario provided described a situation in which an aircraft manufacturing company
located in California had reported that they had been the victim of a breach that had
compromised the data that they had stored on the network. This information had included the
contacts within the U.S. government, employee names, social security numbers, bank account
numbers as well as blueprints for current and future aircraft projects. It was found through an
investigation that the breech had come from the theft of an employee's remote access credentials
that had allowed for the information to be maliciously accessed. Throughout this paper, we will
discuss the laws that are related to this situation as well as what actions should be taken for the
compliance of these laws by the company to ensure that this type of issue does not happen again
in the future.
Since the aircraft manufacturing company is located within the United States there are
certain measures in place that protect any information containing the identity and financial
information of the people employed as well as the clients of the company. Due to the U.S
Governmental contracts and the laws that are implemented in the companies operating state of
California there are additional laws in place to ensure that this information is very well protected.
The main laws in place are the Federal Information Security Management Act (FISMA) and the
California Breach Notification Act.
The Federal Information Management Act states that "that federal agencies provide
information security, including those services provided by contractors or other sources. FISMA
assigns responsibilities to National Institute of Standards & Technology (NIST) to provide
standards and guidance to aid agencies in meeting the requirements of the law" (University of
Alabama Birmingham, n.d.). This act also ensures that there are risk assessments being done,
policies/procedures in place, training given to employees, testing of the procedures and a proper
incident response plan. Due to the company being a victim of a data breach it is their
responsibility to report the incident to the proper agencies. According to Grama & Spinello,
unauthorized access is a category 1 incident and it requires the incident to be reported within one
hour of being discovered by the company (Grama & Spinello, 2014)
With the location of the aircraft manufacturing company located in California, they must
also abide by the California Breach Notification Act. This is read as: "California law requires a
business or state agency to notify any California resident whose unencrypted personal
information, as defined, was acquired, or reasonably believed to have been acquired, by an
unauthorized person (State of California Department of Justice, 2019). It is because of this law
that the aircraft manufacturer is required to contact each of its employees to notify each of the
workers at the California location that there had been a breach and that their personal
information had been accessed. It also permits California residents affected the option of seeking
damages if the required precautions were not taken to prevent such a breach fro