Making and Enforcing 1
Running Head: Making and Enforcing Security Legislations and Standards
TUI UNIVERSITY
Module 3 – Case
Course #: ITM517
Information Security Overview for Managers and Policy Makers
Making and Enforcing 2
Introduction
Information security is the protection of information from a wide range of threats in
order to ensure business continuity, minimize business risk, and maximize return on
investments and business opportunities (ISO, 2010). Organizations and government often try
to achieve information security by establishing information security legislations and
standards. Making these legislations and standards however, is very challenging and often
times they do not achieve their objectives. This paper begins with an overview of some of the
major legislations and standards in information security, flowered by a discussion on whether
or not they are serving their purposes and then it discusses how the legislations may be
enforced and concludes with a discussion on how to establish security rules and regulations.
Major Legislations and Standards in Information Security: There are two
possibilities for defining the term “computer crime”: (1) the use of a computer by a criminal
to conduct illegal activity or (2) a computer as the target of illegal activity (Robinson, 2003).
In an attempt to address these two facets of computer crime, congress has instituted Federal
legislation regulating criminal activity involving information technology, including: The
Computer Fraud and Abuse Act; The Digital Millennium Copyright Act; The Electronic
Communications Protection Act; The Anticybersquatting Consumer Protection Act; The
CAN-SPAM Act, and The Communications Decency Act (Veitch, 2006). This paper will
describe three from the list.
The Digital Millennium Copyright Act (DMCA) amended several pre-existing sections of
Copyright Law. IT criminalizes the circumvention of any technology that controls access to a
copyrighted work (Robinson, 2003). Circumvention is defined as any attempt to descramble,
decrypt, avoid or impair a technological measure without authority—individual authority may be
Making and Enforcing 3
granted for reverse engineering for interoperability, encryption research, or security testing
(Veitch, 2006).
The Electronic Communications Protection Act of 1986 (ECPA) amended the previously
existing Wiretap Act, Sections 2510-22 of Title 18 of the United States Code, and created the
Stored Communications Act, Sections 2701-12 of Title 18 of the United States Code. The
essential purpose of the ECPA is to prohibit unauthorized or unjustified interception, disclosure,
or use of any communication, including electronic communication (Robinson, 2003).
In December 2003, U.S. President George W. Bush signed into law the Controlling the
Assault of Non-Solicited Pornography and Marketing Act of 2003 (S.877), more commonly referred
to as the CAN-SPAM Act of 2003 (Griam, 2003). The intent of this Act is to set specifications for
how email advertisers can legally distribute unsolicited commercial email (UCE) messages and
specifically commercial email messages containing pornographic text and images (Griam, 2003).
Along with the security legislations, there are also standards that are put in place with the aim
of attaining information security. These standards, BS7799, BS ISO/IEC17799: 2000 and its latest
version ISO/IEC 17799:2005 in particular, have been praised as being the keystone in any
successful information security management activities (Siponen, 2006). These standards establish
guidelines and general principles for initiating, implementing, maintaining, and improving
information security management in an organization (ISO, 2010).
Are these Legislations and Standards Serving their Purposes? The aim of these
legislations and standards is to achieve information security. But are they doing that? After the
CAN-SPAM Act was signed into law, a study was done to assess the compliance level. Based on
the study the level of compliance with the Act was low. The results of this study clearly indicates
that compliance with the CAN-SPAM Act six months after its enactment was very low with only
14.3% of email messages meeting even the minimum standards of compliance listed in this study
Making and Enforcing 4
(Grimes, 2003). Two years after the enactment of CAN-SPAM the overall compliance rate was down
even further to only 5.7% (Grimes, 2003).
As for the ISO standards they focus on ensuring that certain information security processes or
activities exist, while they are unconcerned about and fail to give advice on how these security
processes can be accomplished in practice (Siponen, 2006). Information security management
standards are primarily concerned with ensuring the existence of processes rather than the content of
these processes. These standards do not pay attention to an organization’s content problem, rather
they are more concerned with ensuring certain information security activities exist in organizations
and are less interested in how well they are done (Siponen, 2006). Also these processes, guidelines,
and the principles provided by the standards are abstract and simplified, and do not provide advice on
how the desired results are to be achieved in practice (Siponen, 2006). In other words these
standards by themselves will not achieve information security. However, organizations should
use them as a guideline in addressing their unique security content problem.
How should these legislations and standards be enforced? Enforcing these legislations
and standards are by no means an easy task. This interconnected computing age and the boom of
wireless computing makes it difficult to track the offenders, and not because something is printed
in law as illegal means that people will avoid doing it. Legislation for example, will not stop a
hacker from breaking the ECPA. Therefore an organization should not rest assure that the
legislations are in place and believe that is enough. Based on the CAN-SPAM survey it is clear
that government has its hands full in trying to enforce these legislations. This therefore means
that organizations should take it a step further if they are to obtain effective information security.
Organizations should first educate its staff about these legislations and put polices and
procedures in place that will avoid its employees, customers and other stakeholders from
breaking them. A marketing department for example may endorse a non-spam policy. On the
Making and Enforcing 5
other hand organizations should report any evidence of an offender who is disregarding the
legislations. If an organization for example reports an incident of the CFAA and the intruder is
arrested, this will alert other prospective intruders to be skeptic of trying to launch an attack on
such organization.
Enforcing the standards as outlined by the ISO is also not a clear cut task. Organizations
however, should try to observe such standards by breaking them down into daily operational
security activities. The BS ISO/IEC17799: 2000 suggests that, employees should follow security
producers correctly, and the standard implies that producing an introduction to information security
awareness programs (education and training activities) is the way to ensure this ( Siponen, 2006).
However, the standard does not suggest how users should be trained or motivated to follow
information security procedures, this is the duty of the organization since all organizations are
unique.
Establishing Security Rules and Regulations: It would be easy if an organization could
simply use the legislations and standards as a guideline in establishing information security rules
and regulations. However it is not that simple when you consider the political complexity (the
people, power struggles, hidden agendas and related nonsense that make up the average
business) that exists in many organizations. Establishing rules and regulations is clearly a
political task. Without compromising the security of an organization, law makers should be
sensitive to the organization’s political landscape when making security rules and regulations. In
information security decision making, law makers she ensure to include all the people with clout
in the organization to assist in establishing these laws. When such individuals are involve in
establishing these laws they will feel the need to be more involve in their enforcement. With
such potent individuals helping to enforce the laws their implementation has a greater chance of
succeeding.
Making and Enforcing 6
Conclusion
Several legislations and standards have been put in place with the aim of improving
information security—some by private organizations and others by the Federal government.
These legislations and standards however, are often challenging to enforce, hence they do not
achieve their objectives. Criminalizing an activity is simply not enough. Not because something
is signed into law as illegal means that individuals will refrain from doing it. Action must be
taken against offenders and be publicized as an example to prevent others from doing it.
Standards such as BS ISO/IEC17799: 2000 should be used as a guideline to develop and implement
organizations’ unique security model. In order to effectively develop and implement information
security rules and standards in an organization, one has to apply positive organizational politics.
Making and Enforcing 7
Reference
Grimes, G. (2007) Compliance with the CAN-SPAM Act of 2003. Communications of the
ACM, Vol. 50 Issue 2, p56-62. Retrieved February 16, 2010 from TUI library.
19, 2008 from TUI library.
ISO. (2010). ISO/IEC 17799:2005 Information technology - Security techniques - Code of
practice for information security management. Retrieved February 16, 2010 from
[Link]
widely_used_standards_other/information_security.htm
Robinson, S. (2003). U.S. Information Security Law, Part 3. Retrieved February 15, 2010, from
[Link]
Robinson, S. (2003). U.S. Information Security Law, Part Four. Retrieved February 15, 2010,
from [Link]
Robinson, S. (2003) U.S. Information Security Law, Part 2. Retrieved February 15, 2010, from
[Link]
Siponen, M. (2006). Information security standards focus on the existence of process, not its
content. Communications of the ACM, Vol. 49 Issue 8, pp. 97-100. Retrieved February
Veitch, C. (2006). INFORMATION SECURITY LAW:Federal Legislation and Recent Legal
Cases. New Mexico Institute of Mining and Technology Socorro, New Mexico.
Retrieved February 15, 2010 form
[Link]