5 ms·
I can definitely see more standards and certifications coming to pass, which then later distill down to one or two primary certifications that everybody aspires
by mildweed 10y ago
I can definitely see more standards and certifications coming to pass, which then later distill down to one or two primary certifications that everybody aspires to get. Currently there are multiple privacy/security standards (PCI, HIPPA, FERPA, etc). We'll probably have to get more opinions from more sensitive-data industries, and then for them all to find the common ground.
But how would we incentivize businesses properly to be [WHATEVER] compliant, and pay for the regular security scans? Social proof / public shame hasn't worked yet, despite MANY high profile examples. We may have to impose some sort of carrot/stick combo that says: "If your infrastructure consists of N# of networked devices, you must meet these standards. If you fail to, and get caught in a data breach (like what happens with PCI), fines that could put you out of business get levied. Additionally, if you show proof of your security certification every year, you get a tax break."
- ryanmarsh 10y agoRegulatory enforcement. Even though PCI DSS is enforced by a private regulatory body, it still carries weight. HIPAA has HHS which does investigate and lead to corrective action. Both of these bodies scare the crap out of a lot of companies. I've worked in both sectors (banking/credit, healthcare) and the fear is palpable. If the CFPB had the ability to enforce regulatory requirements for handling of PII you bet your ass companies would fall in line. Nobody wants trouble with the feds.
- schoen 10y agoThese regulations have done a lot of good, but there's sometimes the way in which they seem to devolve into checklists (not to stigmatize checklists, which are valuable tools!), often without corresponding understanding and capability. I've seen that particularly in the way that PCI rules led people to get certificates and turn on HTTPS, without knowing what a certificate, private key, public key, TLS, or HTTPS were or what they were for. While I prefer that to the alternative of no HTTPS at all -- which is probably what we would have seen without the rules! -- it's still a bit disappointing and concerning that for so many organizations it only got to the "have to satisfy PCI rules by doing this weird arbitrary thing" stage.