My Answers to HWcase5, Q1
Nov. 2nd, 2022 10:01 pmQ1. As a “case” to discuss for this unit, use a law related to security, privacy, etc. Suggestions: HIPAA, FERPA, Computer Security Act, Sarbanes-Oxley, Gramm-Leach-Bliley, COPPA, Payment Card Industry Data Security Standard (PCI DSS), US Patriot Act, Section 508 of the Americans with Disabilities Act, or some other law.
A link or other citation to the case you are using, or if it is from personal experience, point that out.
A list of 8 or more important facts about the case. These could help you tell your group members or anyone or remind yourself what the case is all about.
A list of questions (5 or more) to think about or discuss about the case.
Answer:
The source of my case is http://alisondb.legislature.state.al.us/alison/CodeOfAlabama/1975/8-38-3.htm.
Eight important facts are:
This is a data security law implemented by the state of Alabama.
The law states that there should be implementation and maintenance of security measures to protect private identity information.
This law applies to state, county or municipality, and third-party agents.
The law forces organizations to designate an employee or employee to protect the information in case of a data breach.
Organizations must identify possible internal and external risks.
The effectiveness of the safeguard must be assessed.
The security measure must be practicable.
“The amount of sensitive personally identifying information and the type of activities for which the sensitive personally identifying information is accessed, acquired, maintained, stored, utilized, or communicated by, or on behalf of, the covered entity.”
Five questions to ask about the case are:
Do you believe that this is an adequate law to enforce data security?
How accountable do you think the state is holding itself and other entities with this law?
Do you notice anything interesting about the law?
If you could, how would you modify this law?
Is this law within your expectation of how a state would enforce data security?
Three additional standard questions:
What does virtue ethics say about this case?
What does utilitarianism say about this case?
What does deontology say about this case?