The Legal Standard for Information Security

Laws and regulations rarely specify what specific security measures a business should implement to satisfy its legal obligations.43 Most simply obligate the company to establish and maintain internal security procedures, controls, safeguards, or measures directed toward achieving the goals or objectives identified above, but often without any further direction or guidance. The standard for compliance, if one is stated, often requires simply that the security be “reasonable”45 or “appropriate.”46 Other expressions of the standard that appear in some regulations include “suitable,” “necessary,” and “adequate.” 44

A critical problem, then, is assessing how far a company is “legally” obligated to go. When are the security measures it implements sufficient, from a legal perspective, to comply with its obligations? For, example, does installing a firewall and using virus detection software satisfy a company’s legal obligations? Is it necessary for an organization to encrypt all of its electronic records? How does a business know when it is legally compliant? Is there a safe harbor? Since there is no such thing as perfect security

The FTC acknowledges that the mere fact that a breach of security occurs does not necessarily mean that there has been a violation of law.48 But it also notes that an organization can fail to meet its security obligations, even in the absence of a breach of

