extent of a company’s “legal” obligation to implement information security. In other words, what is the legal standard against which compliance with an obligation to provide reasonable security is measured?

There are many standards that seek to define the scope of information security requirements from a “technical” perspective.50 But a review of newer statutes, regulations, and cases51 indicates that a “legal” standard is also beginning to emerge – a legal standard that helps to clarify the scope and extent of a company’s obligation to implement information security. Under that standard, which is described in detail below, the duty to provide information security (e.g., the duty to provide “reasonable” security) requires both (1) implementation of an ongoing process and (2) addressing certain categories of security measures.

The developing legal standard involves a relatively sophisticated approach to c o m p l i a n c e , a n d r e c o g n i z e s w h a t s e c u r i t y c o n s u l t a n t s h a v e b e e n s a y i n g f o r s o m e t i m e :

“security is a process, not a product.”52

Thus, it does not literally dictate what security

measures are required to achieve “reasonable security.” Instead, it sets out requirements for a fact-specific process leading to the development of what is often referred to as a

“comprehensive information security program,”53 process is required to achieve legal compliance.

and makes clear that following that

This “process oriented” legal standard for corporate information security was first set forth in a series of financial industry security regulations required under the Gramm- Leach-Bliley Act (GLBA) titled Guidelines Establishing Standards for Safeguarding Consumer Information. They were issued by the Federal Reserve, the OCC, FDIC, and

