1,720,971 research outputs found

    Computer Law & Security Report

    No full text
    In recent years, the payment card industry has dealt with the matter of consumer liability for unauthorized charges. However, risks to consumers from identity theft and related use of personal data present new challenges for cardholders and those who profit from their usage, including merchants, banks, and payment card companies. This article examines the varying and sometimes complementary roles that legal obligations and private ordering play in incentivizing security measures to protect consumers. It shows that, in the legal environment within the United States, which lacks comprehensive legal protections for consumer privacy and security, private ordering rooted in economic incentives within the payment card industry can also bring about enhanced security for consumers. The Payment Card Industry Data Security Standards ("PCI DSS") have emerged from private ordering, although threats of legal liability have also influenced their development and implementation. The article evaluates the basic framework of PCI DSS and raises issues for further development as the government, the legal system, and the industry copes with security threats in this environment.6540-5542

    DePaul Business & Commercial Law Journal

    No full text
    A private ordering regime has developed within the payment card industry to define appropriate security practices and to monitor compliance by network participants. Market demands for trustworthy systems upon which consumers and merchants could rely provide incentives for security, which the card brands supplement by privately designed fines and sanctions imposed through contract. Although private ordering has functioned sufficiently well to make payment cards a trusted payment method, the system is not completely secure, as data security breaches continue to occur. This is not surprising, as complete security is not a feasible goal. Nevertheless, some have questioned whether additional government regulation is necessary to protect consumers. This article explores the effects of legal intervention, including disclosure laws, on this private ordering system. It questions whether additional government intervention would enhance consumer welfare, particularly when consumers will likely bear the ultimate costs of such regulation. It recommends modifications in breach disclosure laws to eliminate individual notice requirements in favor of public notices, which may reduce costs and enhance consumer welfare. It challenges "bounty" enforcement regimes, such as FACTA, which offer little marginal benefit to consumers while substantially raising costs. It identifies practical and political problems presented by the different capacities of large and small firms to bear security costs, which are not easily solved under either private ordering or legislative approaches. Finally, it offers a set of policy issues as a possible agenda for consideration by policy makers and researchers in this domain.2213-2651

    ISACA Journal

    No full text
    How much of this virtual world will remain part of our lives after the pandemic has passed? Will the technological shift leave lasting changes in the habits and pract ices of business and society? For auditors, navigating through this future requires an examination of the changing risk environment and our ability to identify and mitigate these risk areas. We should examine these questions further.11-1

    Lydian Payments Journal

    No full text
    This article provides an update of recent legal and legislative developments and commentary on policy directions affecting data security within the payment card industry and related networks.31-45

    Information Security Journal: A Global Perspective

    No full text
    This study examines the impact of reported breaches in computer security using event study analysis. We use the event-study methodology to measure the magnitude of the effect of data security breach events on the behavior of stock markets. Our data come from security breaches spanning a ten-year period and involving various industries. The findings of the study suggest that there exist abnormal negative stock price returns following the announcement of a breach. Such abnormal negative returns persist over the next several years. Moreover, the source of data breach may moderate the price effect; the market tends to punish more heavily those compromises that could have been avoided with reasonable precautions by the breached company.6263-2731

    CFO Connect

    No full text
    17-1

    ISACA Journal

    No full text
    15-17

    ISACA Journal

    No full text
    8-10

    ISACA Journal

    No full text
    6-8
    corecore