Laws - US Flashcards
(25 cards)
CCCA
Comprehensive Crime Control Act 1984
- First enactment of computer crimes law
- Federal computers that process “sensitive information”
- Took care not to step on state-boundaries, laws
CFAA
Computer Fraud and Abuse Act 1986
- First law to implement penalties for creators of viruses, worms, etc
- Extended CCCA to all “federal interest computers”
- Includes financial institution computers
- Any use that impedes federal, financial…
- 1994 - Amendments
- Outlawed malware
- Now covers “inter-state” computers, not just “federal interest”
- Imprisonment regardless of intent
- Legal authority for victims to pursue civil actions
CSA
Computer Security Act 1987
- Mandating baseline security requirements for all federal agencies
- Gave remit to NIST, NSA
- Requires periodic training for all people involved in managing, operating federal systems with sensitive information
CALEA
Communications Assistance for Law Enforcement Act 1994
- Amended ECPA
* Telcos must comply with wiretap court orders
EcPA
Economic and Protection of Proprietary Information Act 1996
- Part of EEA 1996
- Extends the defn of property to include proprietary economic information.
- Theft of information = espionage.
- Theft no longer restricted to physical assets.
EEA
Economic Espionage Act 1996
- Gives true teeth to intellectual property rights of trade secret owners
HIPAA
Health Insurance Portability and Accountability Act 1996
- HMOs = Health Maintenance Organisations
- PHI = Protected Health Information
- Strict security measures around health records, and disclosure of those.
HITECH
Health Information Technology for Economic and Clinical Health Act 2009
- Amemdment to HIPAA
- Federal mandating of data breach notification requirements to individuals affected.
- Extends obligations to BA = business associates
ECPA
Electronic Communications Privacy Act 1986
- Amended the Wiretap Statue of 1968
- Extends government restrictions on wire taps from telephone calls to include transmissions of electronic data by computer
- Added new provisions prohibiting access to stored electronic communications
USPA
Privacy Act 1974
- Establishes a Code of Fair Information Practice that governs the collection, maintenance, use, and dissemination of personally identifiable information about individuals that is maintained in systems of records by federal agencies.
- A system of records is a group of records under the control of an agency from which information is retrieved by the name of the individual or by some identifier assigned to the individual
GISRA
Government Information Security Reform Act 2000
- Amends PRA
- Places responsibility on individual agency leaders
- Continues to charge NIST and the NSA with security oversight for non-classified and classified data respectively
NIIPA
National Information Infrastructure Protection Act 1996
- Further amendments to CFAA
- Computers used in intl commerce
- Utilities - railroads, gas, power grids, telco etc
- Reckless acts = felony
COPPA
Children’s Online Privacy Protection Act 1998
- Demands on websites that cater to children or knowingly collect information from children
- Parental consent etc
NIIPA
National Information Infrastructure Protection Act 1996
- Part of EEA 1996
- Further amendments to CFAA
- Computers used in intl commerce
- Utilities - railroads, gas, power grids, telco etc
- Reckless acts = felony
GLBA
Gramm-Leach-Bliley Act 1999
- A “civil law”
- Financial institutions
- Relaxed rules on sharing information
- Introduced new rules to compensate
USA PATRIOT Act 2001
- Providing Appropriate Tools to Intercept and Obstruct Terrorism
- Amends CFAA
FISMA
Federal Information Security Management Act 2002
- Federal agencies must implement info security programme
- Extends to contractors also
- NIST responsible for guidelines
FERPA
Family Educational Rights and Privacy Act
- Gives parents
- Access to their child’s education records
- An opportunity to seek to have the records amended, and
- Some control over the disclosure of information from the records
ITADA
Identity Theft and Assumption Deterrence Act 1998
- Identity theft
- Makes the possession of any “means of identification” to “knowingly transfer, possess, or use without lawful authority” a federal crime
- …alongside unlawful possession of identification documents
FOIA
Freedom of Information Act 1966
- A federal freedom of information law
- Allows for the full or partial disclosure of previously unreleased information and documents controlled by the United States government
FOIA
Freedom of Information Act 1966
- A federal freedom of information law
- Allows for the full or partial disclosure of previously unreleased information and documents controlled by the United States government
UCITA
Uniform Computer Information Transactions Act 2000
- A model law (attempting to bring consistency across states)
- Allows a shrinkwrap license to override vendor’s liability for faults
- Only specifies a set of guidelines
- Has only been passed in two states, Virginia and Maryland
DMCA
Digital Millennium Copyright Act 2000
- Criminalises production and dissemination of technology, devices, or services intended to circumvent measures (commonly known as digital rights management or DRM)
- Implements the exemption from direct and indirect liability of Internet service providers and other intermediaries
- Does require that the ISP had nothing otherwise to do with the traffic (but has no geographical provisions)
- implements two 1996 treaties of the World Intellectual Property Organization (WIPO)
SOX
Sarbanes-Oxley 2002
- Financial reporting of publicly traded company boards, management and public accounting firms
- Reaction to Enron, Arhur Anderson, WorldCom scandals