Home > Is encryption required for compliance with all the current privacy and security laws and regulations?
FAQ:
EMAIL THIS LICENSING & REPRINTS

Is encryption required for compliance with all the current privacy and security laws and regulations?

04 Oct 2007 | Kevin Beaver

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

I'll give you the customary analyst/lawyer answer, it depends. Some of the regulations, like HIPAA and Graham Leach Bliley, require you to perform a risk analysis on your environment. So, you may or may not conclude that encryption is necessary based on your findings.

((Content component not found.)) Some of the state breach notification laws, like California's SB 1386, say that unencrypted personal information falls within the scope of notification. So, if a breach occurs, or is suspected to have occurred, and everything is encrypted, you may not have to report the incident to the information owners. But, if it's unencrypted, that's when you'll have to worry about it. It varies from state to state, so you've definitely got to do some research in this area. Even with SOX, it could be argued that financial controls may include storage encryption.

So, it all depends on the particular scenario, the size of the organization, whether or not you are a credit card merchant for PCI, etc. There needs to be someone in every organization that can look at these laws and say what's what and put you on the right track.

Check out the entire Storage Encryption FAQ guide.



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Secure data storage
Storage news in brief
Notes from SNW: Encryption shifts to disk drives
8 steps to better data security
Policy and technology: the belt and braces of data protection
Iron Mountain digitizes documents to bolster security
Disclosure becomes a fact of life in leaky Britain
nCipher grabs NeoScale for $1.9M
How to mitigate the performance penalties of data encryption software
Users: Storage security becoming a priority
EMC's Coviello: 'Security vendors do not sell fear'

Email archiving and compliance initiatives
Kazeon boosts data classification with e-discovery features
Clearwell makes its e-discovery search more transparent
Compliance, storage environments and Humpty Dumpty
ILM diary: Time to select the file archiving supplier
Data Domain and Mimosa add data compliance capability
Proofpoint buys email archiving SaaS provider Fortiva
National Library of Wales chooses optical disk media for digital archive
Symantec shops hail Enterprise Vault archiving software
Hull university turns to BridgeHead archiving software in tiered storage move
Pharma firm sets out on ILM journey to shrink backup windows, classify data

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Data Protection Act 1998  (SearchStorageUK.com)
Freedom of Information Act 2000  (SearchStorageUK.com)
Information Commissioner's Office (ICO)  (SearchStorageUK.com)
MiFID  (SearchStorageUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts