Case Study:
Conduct research on the Internet or select 1 of the 2 examples in your text in Chapter 4, page 117 on a credit card breach. Write a 3 to 4 page paper (Not including title and reference page) in which describe the details of the event. Tell us what could done to prevent the event from happening, list the laws that were broken and if the event violated any of the acts or laws that you read about in chapters 3 & 4. You paper should be in APA format and contain 3 to 4 different sources. Make sure you cite all sources.
Writing Requirements
No PlagiarismAPA Format
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Legal Issues in
Information Security
Lesson 4
Security and Privacy of
Consumer Financial Information
Page 2Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Learning Objective
Describe legal compliance laws addressing
how
financial institutions
protect the
security and privacy of consumer financial
information.
Page 3Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Key Concepts
Financial institutions and the protection of
information they collect
Financial regulatory laws and government
regulatory bodies
The Gramm-Leach-Bliley Act and financial
institutions
The Federal Trade Commission Red Flags
Rule
Payment Card Industry Standards
Page 4Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Business Challenges Facing
Financial Institutions
Bear cost of consumer identity theft
Company names and logos used in
phishing scams
Targets of hackers
Must follow regulations designed to protect
security and privacy of data they collect and
use; rules place compliance burden on
financial institutions
Page 5Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Types of Financial Institutions
Savings and loan associations
Finance companies
Insurance companies
Investment companies
Page 6Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Consumer Financial Information
Name
Social
Security
number
Driver’s
license
number
Address/
telephone
number
Work history
Page 7Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Who Regulates Financial
Institutions?
Page 8Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Federal Financial Institutions
Examination Council (FFIEC)
Establish principles and standards for
examination of federal financial institutions
Develop uniform reporting system
Conduct training for federal bank examiners
Make recommendations regarding bank
supervision matters
Encourage adoption of uniform principles and
standards by federal and state banks
Page 9Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
The Gramm-Leach Bliley Act
(GLBA)
The Financial Modernization Act of 1999
Protects personal financial information held
by financial institutions
Page 10Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Impacts of
GLBA
Allows banks, securities, and insurance
companies to merge
Financial activities include borrowing,
lending, providing credit counseling, debt
collection, and other activities
Protects nonpublic personal information
(NPI)
Page 11Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Nonpublic Personal Information
(NPI)
Social Security numbers
Financial account numbers
Credit card numbers
Date of birth
Name, address, and phone numbers when
collected with financial data
Details of any transactions or the fact that an
individual is a customer of a financial institution
Page 12Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
GLBA―Principal Parts
GLBA
Privacy
Rule
Safeguards
Rule
Pretexting
Page 13Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
GLBA Privacy Rule
Financial institutions may not share NPI with
nonaffiliated third parties unless institution gives
notice to consumer
The notice must tell consumers about types of
data the institution collects and how it uses that
information
• Called a notice of privacy practices
Consumers have chance to opt out of some data
sharing
Page 14Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
GLBA Safeguard Rule
Each agency must establish standards
that:
• Protect the security and confidentiality of
customer information
• Protect against threats to the security or
integrity of customer information
• Protect against unauthorized access to or
use of customer information that could
result in harm to a customer
Page 15Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
GLBA Pretexting Rule
Pretexting
• Trying to gain access to customer information without
proper authority; also known as social engineering
Illegal to make false, fictitious, or fraudulent
statements to a financial institution or its
customers to get customer information
Illegal to use forged, counterfeit, lost, or stolen
documents to do the same thing
Designed to stop identity theft
Page 16Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
The Federal Trade Commission
Red Flags Rule
Fair and Accurate Credit Transaction Act of
2003 (FACTA)
Identify Theft Red Flags Rule
Page 17Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Red Flag Categories
Suspicious
Documents
Suspicious
Personal
Identifying
Information
Unusual
Account Activity
Notice of Identity
Theft
Credit Reporting
Agency Alerts
Page 18Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Payment Card Industry (PCI)
Data Security Standards (DSS)
Safeguards and protects credit card data
All merchants accepting credit cards must
follow PCI DSS standards
Single approach makes it easier for
merchants to accept all cards
Page 19Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
PCI DSS Controls and Rules
Build and maintain a secure network
Protect cardholder data
Maintain a vulnerability management
program
Implement strong access control measures
Regularly monitor and test networks
Maintain an information security policy
Page 20Legal Issues in Information Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Summary
Financial institutions and the protection of
information they collect
Financial regulatory laws and government
regulatory bodies
Gramm-Leach-Bliley Act
Federal Trade Commission Red Flag Rules
Nonpublic personal information (PII)
We provide professional writing services to help you score straight A’s by submitting custom written assignments that mirror your guidelines.
Get result-oriented writing and never worry about grades anymore. We follow the highest quality standards to make sure that you get perfect assignments.
Our writers have experience in dealing with papers of every educational level. You can surely rely on the expertise of our qualified professionals.
Your deadline is our threshold for success and we take it very seriously. We make sure you receive your papers before your predefined time.
Someone from our customer support team is always here to respond to your questions. So, hit us up if you have got any ambiguity or concern.
Sit back and relax while we help you out with writing your papers. We have an ultimate policy for keeping your personal and order-related details a secret.
We assure you that your document will be thoroughly checked for plagiarism and grammatical errors as we use highly authentic and licit sources.
Still reluctant about placing an order? Our 100% Moneyback Guarantee backs you up on rare occasions where you aren’t satisfied with the writing.
You don’t have to wait for an update for hours; you can track the progress of your order any time you want. We share the status after each step.
Although you can leverage our expertise for any writing task, we have a knack for creating flawless papers for the following document types.
Although you can leverage our expertise for any writing task, we have a knack for creating flawless papers for the following document types.
From brainstorming your paper's outline to perfecting its grammar, we perform every step carefully to make your paper worthy of A grade.
Hire your preferred writer anytime. Simply specify if you want your preferred expert to write your paper and we’ll make that happen.
Get an elaborate and authentic grammar check report with your work to have the grammar goodness sealed in your document.
You can purchase this feature if you want our writers to sum up your paper in the form of a concise and well-articulated summary.
You don’t have to worry about plagiarism anymore. Get a plagiarism report to certify the uniqueness of your work.
Join us for the best experience while seeking writing assistance in your college life. A good grade is all you need to boost up your academic excellence and we are all about it.
We create perfect papers according to the guidelines.
We seamlessly edit out errors from your papers.
We thoroughly read your final draft to identify errors.
Work with ultimate peace of mind because we ensure that your academic work is our responsibility and your grades are a top concern for us!
Dedication. Quality. Commitment. Punctuality
Here is what we have achieved so far. These numbers are evidence that we go the extra mile to make your college journey successful.
We have the most intuitive and minimalistic process so that you can easily place an order. Just follow a few steps to unlock success.
We understand your guidelines first before delivering any writing service. You can discuss your writing needs and we will have them evaluated by our dedicated team.
We write your papers in a standardized way. We complete your work in such a way that it turns out to be a perfect description of your guidelines.
We promise you excellent grades and academic excellence that you always longed for. Our writers stay in touch with you via email.