On December 20, 2021, The National Institute of Standards and Technology (NIST) released its draft interagency report 8403 on “Blockchain for Access Control Systems”. As the report’s abstract states:
“Protecting system resources against unauthorized access is the primary objective of
Data Privacy & Security Observer
Legal Developments and Thought Leadership in Data Privacy and Cyber Security
The Data Privacy & Security Observer, published by Balch & Bingham LLP, focuses on legal developments and regulatory updates related to data privacy, cybersecurity, and information security. The blog covers state and federal privacy laws, including comprehensive state privacy statutes and regulations governing consumer data rights, consent, and data processing obligations. It also addresses cybersecurity threats, advisories, and mitigation strategies, particularly those affecting critical infrastructure and operational technology. Additionally, the blog discusses emerging issues such as artificial intelligence governance, automated decision-making technology regulations, and compliance challenges for businesses and organizations.
Latest from Data Privacy & Security Observer - Page 3
Financial Regulators Issue New Cyber Incident Reporting Rule for U.S. Banks and Service Providers
On November 18, 2021, the Federal Reserve, Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency (OCC) approved a new final rule regarding reporting of cyber incidents for U.S. banks and service providers.
Under the…
Senate Introduces Legislation Requiring 24-hour Ransomware Notification
A new bill introduced by the Senate (S. 2666), the “Sanction and Stop Ransomware Act of 2021”, would require a strict 24-hour limit for reporting ransomware payments for businesses with more than 50 employees. The bipartisan bill, put forward by…
California Privacy Protection Agency (CPPA) Invites Comments on Proposed Rulemaking
Background
Yesterday, on September 22, 2021, the California Privacy Protection Agency (“CPPA”) — the new privacy regulatory agency created by the California Privacy Rights Act of 2020 (“CPRA” or “CCPA 2.0”) — issued an invitation for public comment on…
SEC Issues Cybersecurity Sanctions Against Eight Firms
Background
On August 30, 2021, the Securities and Exchange Commission (SEC) sanctioned eight firms in three actions for cybersecurity failures in their policies and procedures that exposed the personal information of thousands of customers at each firm. These firms included:…
President Biden Issues Executive Order on Cybersecurity
On May 12, 2021, President Biden issued an executive order to strengthen U.S. cybersecurity defenses. The order comes in the wake of the ransomware attack on Colonial Pipeline and numerous other cybersecurity attacks against the U.S. government and private companies…
California Announces Board Appointments to New California Privacy Protection Agency (CPPA)
On March 17, 2021, Governor Gavin Newsome, Attorney General Xavier Becerra, Senate President pro tem Toni Atkins, and Assembly Speaker Anthony Rendon announced the members of the California Privacy Protection Agency (CPPA) the new administrative agency created by the California…
California Attorney General Issues Additional CCPA Regulations Advancing Consumer Protections
California Attorney General Issues Additional CCPA Regulations Advancing Consumer Protections
On March 15, 2021, the California Attorney General (“AG”) approved additional CCPA regulations to enhance consumer protections for opting out of the sale of information. These regulations come after the…
California’s CPRA (“CCPA 2.0”) Likely to Pass with Majority of Votes Counted
As the nation closely watches the election results coming in, the majority of votes counted in California suggest that the California Privacy Rights Act of 2020 (“CPRA”, or commonly known as “CCPA 2.0”), is on track to pass. Proposition 24…
NIST Publishes Technical Note on Predicting Botnet Attacks
On October 22, 2020, the National Institute of Standards and Technology (“NIST”) published NIST Technical Note (TN) 2111, “An Empirical Study on Flow-based Botnet Attacks Prediction”. The note, authored by Mitsuhiro Hatada and Matthew Scholl of NIST’s Information Technology Laboratory,…