|
There are no current standards among the 50 States. Some states, such as Oregon and Massachusetts, have modern Information Security laws that protect state residents from poor security practices of businesses. Other states have minimal attempts at protecting their residents from the negligent practices of its businesses.
While a state may not be responsible, businesses still must comply with Federal and industry requirements. One aspect of most state and Federal laws deals with “encryption exemptions” which allow a business or organization to waive notification requirements if Personally Identifiable Information (PII) was encrypted at the time of a breach. This can serve as a “get out of jail free” card for businesses, but only if they follow encryption procedures at the time of the breach.
|