Lawsuit regarding information security

Lawsuit Could Redefine Liabilities of Security Service Providers

Wednesday, June 03, 2009 10:23 AM/EST

Information security managers and executives have long been held accountable for security incidences and breaches, but what about the people who certify or provide the security? In other words, should auditors and managed security service providers be held accountable for breaches that happen after they’ve signed off on security measures?

That is the question before the courts in the case of the 2005 breach of CardSystems, a credit card payment processor that suffered a theft of more than 40 million credit card numbers, according to a Wired.com report. CardSystems has been certified as compliant with Cardholder Information Security Program (CISP), the precursor to the Payment Card Industry Data Security Standard (PCI DSS). But an incident response analysis discovered that CardSystems wasn’t in compliance with the security standards at the time of the breach.

According to the Wired report, a lawsuit brought by Merrick Bank is moving forward against Savvis, the managed service provider that certified CardSystems as CISP compliant. The lawsuit alleges that Savvis was negligent in certifying CardSystems as secure and bears responsibility. Savvis is a partner of such vendors as Cisco, Microsoft and Hewlett-Packard.

To read the entire article, posted by Larry Walsh on June 3, 2009 10:23 AM, follow the link (below).

http://blogs.channelinsider.com/secure_channel/content/data_security/breach_lawsuit_could_reset_security_liabilities_to_service_providers.html

Comments are closed.

Free Newsletter Sign Up Below
* = required field
CBC Video – GEEP
Green Living Tips
Use both sides of paper
If you have a printer with a double sided print option, use it. You will save half of the amount of paper you would have normally used.
Add this to your site
Tag Cloud
Content Protected Using Blog Protector By: PcDrome.