Those who design and implement information infrastructures must account
for the current trends in the law to require "reasonable" security measures
to protect data considered by the owner to be confidential or deemed by
the government to be
confidential. As we say, ignorance of the law does not excuse non-compliance.
It costs a lot more to retrofit than to build in the necessary standards
and provide for flexibility today. An appropriate blend of good policies,
tested and enforced, and technical solutions designed to prevent and detect
issues, along with a reasonable response plan are necessary. This discussion
will focus on current legal trends; how we got here and where we likely
are going.
|