4 ms·
IMO, the specifics of how to secure are less important than ensuring proper cost of not securing your systems. I think having rigid rules like PCI would be sign
by nathantotten 9y ago
IMO, the specifics of how to secure are less important than ensuring proper cost of not securing your systems. I think having rigid rules like PCI would be significant burden and not allow flexibility as technology and business changes.
On the other hand, simply ensuring that the financial penalties are in line with the damage done should be enough to solve the issue. You said yourself that boards won’t agree to spend money. If they saw a huge financial downside risk they would be more likely to invest in security.
- throwaway2016a 9y agoI agree. PCI is way too rigid. But you wouldn't want something like that for legislation anyway. I don't want Congress picking my security standards. But I think there should be some bar that companies can reach that protects them from the most serious penalties of any laws. That bar may even move depending on factors like revenue, number of users, and sensitivity of data. > On the other hand, simply ensuring that the financial penalties are in line with the damage done should be enough to solve the issue. You said yourself that boards won’t agree to spend money. If they saw a huge financial downside risk they would be more likely to invest in security. I completely agree. Not sure if it came off correctly but that was the point of my edit at the end.
- nathantotten 9y agoYeah, that makes sense. You’re right there needs to be a reward for achieving some measure of security.
- maxerickson 9y agoCompanies that want to protect themselves from breaches should avoid collecting and quickly discard sensitive data.
- throwaway2016a 9y agoAgreed completely. PCI and many data protection laws and industry frameworks already dictate that you should discard data as soon as you no longer need it and not collect sensitive data unless you legitimately need it. That can be part of the law.
- maxerickson 9y agoRight, but my point is that there isn't a deep need for a box checking exercise that gets a company out of liability, if they don't want liability they can just avoid creating it. Conveniently this is most onerous for stupid business models.
- AJ007 9y agoIt could also be a way to offload sensitive processing & storage to a third party; e.g. Stripe. I'm leaning much more toward John Young's (Cryptome) viewpoint of information security -- smoke and mirrors. Maybe nothing is secure and it is only a question of how interested the adversary is in creating a break and then what they decide to do with the information after. Robert Cringely has the most practical advice I've read -- keep secure communications off the internet.