Skip to content
BOL Conferences
Thread Options
#341326 - 03/31/05 05:07 PM Response Programs for Unauth. Access
CalifDreamin Offline
Diamond Poster
CalifDreamin
Joined: Mar 2002
Posts: 2,300
Far from Calif
Curious to know others' opinions regarding encrypted data and the new guidance that was just issued. For example, if a laptop was taken, but all of the data contained on it was encrypted, would you still consider this as unauthorized access for purposes of this guidance? (assuming NPPI was contained on the laptop)
_________________________
The opinions expressed are mine and do not necessarily reflect those of my employer
_._._._._._.
A.S.A.P.
Always
Say
A
Prayer
<><

Return to Top
Security - PUBLIC
#341327 - 03/31/05 05:38 PM Re: Response Programs for Unauth. Access
Czargazer Offline
Gold Star
Czargazer
Joined: May 2003
Posts: 298
Pacific Northwest
From the final guidance:

"...the institution should conduct a reasonable investigation to promptly determine the likelihood that the information has been or will be misused. If the institution determines that misuse of its information about a customer has occurred or is reasonably possible, it should notify the affected customer as soon as possible."

It's a bit of a grey area. It's pretty much a matter of if the folks who currently have possession of the laptop are cabable of breaking the encryption, or otherwise find a way of stripping the data from the hard drive. I think contacting your regulator and asking them what their opinion is might be wise.
_________________________
Everyone has to make a living, mine just happens to involve thumbscrews.

Return to Top
#341328 - 04/22/05 09:26 PM Re: Response Programs for Unauth. Access
Anonymous
Unregistered

I agree with Czar. We see this kind of grey area all the time. At the same time, I know some banks don't like talking to their regulators because they fear such an inquiry could be used against them during an exam. I would say, call your regulator any way...it's better to have your answers now than worry about explanations later.

Return to Top

Moderator:  Andy_Z