Cyberlaw Topics: Internet and Information Security

This site discusses the legal and ethical environment of Internet and information security. Available resources include the following:

Security Legislation
Security Topics
Selected Cases
Selected Articles and Reports
Other Useful Links

 

Security Legislation
Computer Security Act of 1987
The purpose of this act is to provide for a computer standards program within the National Bureau of Standards, to provide for Government-wide computer security, and to provide for the training in security matters of persons who are involved in the management, operation, and use of Federal computer systems, and for other purposes.

Digital Signature and Electronic Authentication Law (SEAL) of 1998
To amend the Bank Protection Act of 1968 for purposes of facilitating the use of electronic authentication techniques by financial institutions, and for other purposes.

top of page

Security Topics
.A Consumer's Guide to E-Payments
Most consumers use credit or debit cards to pay for online purchases, but other payment methods, like "e-wallets," are becoming more common. The Federal Trade Commission (FTC) wants you to know about these new payment technologies and how to make your transactions as safe and secure as possible.

Cryptography Policy
Internet privacy coalition seeks to promote privacy and security on the Internet through widespread public availability of strong encryption and the relaxation of export controls on cryptography.

Digital Signature Laws and the Electronic Commerce Marketplace
This paper argues that certain enacted digital signature laws are premised upon false assumptions, and inappropriately enshrine a business model which would not evolve naturally in the marketplace. In attempting to solve an unsolvable liability allocation problem, such legislation harms consumers and the future evolution of electronic commerce.

ID Theft: When Bad Things Happen To Your Good Name
The Federal Trade Commission (FTC), working with other government agencies and organizations, has produced this booklet to help you guard against and recover from identity theft. Can you completely prevent identity theft from occurring? Probably not, especially if someone is determined to commit the crime. But you can minimize your risk by managing your personal information wisely and cautiously.

Improving the Security of Your Site by Breaking Into It
This paper takes an unusual approach to system security. Instead of merely saying that something is a problem, it will look through the eyes of a potential intruder, and show _why_ it is one. It will illustrate that even seemingly harmless network services can become valuable tools in the search for weak points of a system, even when these services are operating exactly as they are intended to. In an effort to shed some light on how more advanced intrusions occur, this paper outlines various mechanisms that crackers have actually used to obtain access to systems.

OECD Governments Launch Drive to Improve Security of Online Networks
By OECD. "OECD governments have drawn up new Guidelines for the Security of Information Systems and Networks in the wake of last year's September 11 attacks in the United States, in order to counter cyberterrorism, computer viruses, hacking and other threats."

W3C Security Resources
The World Wide Web Consortium (W3C) is a forum for information, commerce, communication, and collective understanding. Web security is a complex topic, encompassing computer system security, network security, authentication services, message validation, personal privacy issues, and cryptography. This page contains links to various topics in Web and Internet security, including the WWW Security FAQ.

top of page

Selected Cases
Hacking/cracking, viruses, and security
A list of archived cases from global cyberlaw.com for Information Technology and Privacy Law.

top of page

Selected Articles and Reports
List: Windows, Unix Still at Risk
"The federal government is going to get better at security," said Richard Clarke, special adviser to President Bush on cybersecurity. "We are going to walk the talk."

Senator Backs Off Backdoors
Sen. Judd Gregg has abruptly changed his mind and will no longer seek to insert backdoors into encryption products.

Security Management Gains Sophistication
Vendors unleash wave of products to let managers monitor system threats.

Was September the end of the virus calm?
September 2002 may be the calm month before the storm for worm activity.

top of page

Other Useful Links
CERT Coordination Center (CERT/CC)
The CERT Coordination Center (CERT/CC) is a center of Internet security expertise, located at the Software Engineering Institute, a federally funded research and development center operated by Carnegie Mellon University.

Computer Security Information
This page features general information about computer security. Information is organized by source and each section is organized by topic.

CNET Security Center
Contains information, downloadable files, and product reviews on the latest security technology.

CNET Virus Center
Contains information, downloadable files, and product reviews on the latest anti-virus technology.

Electronic Frontier Foundation (EFF)
Based in San Francisco, EFF is a donor-supported membership organization working to protect our fundamental rights regardless of technology; to educate the press, policymakers and the general public about civil liberties issues related to technology; and to act as a defender of those liberties.

PC Webopedia - Security Links
Contains definitions of security terminology and links to security topics.

searchSecurity.com
Contains the essential information needed to avoid security nightmares and breaches. Register FREE in order to receive management-level news, "Executive Security Briefing," exclusive product reviews, informative whitepapers, and much more.

top of page