12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9: Compliance and StorageBreach Disclosure Laws and StorageOne of the most common disclosures affecting the storage industryis the loss or theft of a backup tape. In many cases, a lost or stolentape media that is encrypted would not require disclosure; and inothers, a disclosure would still be required but it would be qualifiedwith the fact that the data was encrypted and does not pose anyrisks of exposing PII. This is quite significant from a public relationsperspective for an organization that has suffered such a breach.There have also been reported cases of disk subsystems being soldon the open market with actual data still residing on the disk drives.Similarly, there have been cases of disks installed in a customer'senvironment that still contained data, although they were allegedlyrefurbished by vendors.Health Insurance Portability and AccountabilityAct (HIPAA)HIPAA was enacted by the US Congress in 1996 to help maintain confidentialityof healthcare transactions or electronic protected healthinformation (EPHI). Title II of HIPAA, the Administrative Simplification(AS) provisions, requires the establishment of national standards forelectronic healthcare transactions and national identifiers for providers,health insurance plans, and employers. The AS provisions alsoaddress the security and privacy of health data.Offenses under HIPAA can have the following consequences:• A fine of not more than $50,000, imprisonment of not more than1 year, or both• If the offense is committed under false pretenses, a fine of notmore than $100,000, imprisonment of not more than 5 years, orboth• If the offense is committed with intent to sell, transfer, or use individuallyidentifiable health information for commercial advantage,personal gain, or malicious harm, a fine of not more than$250,000, imprisonment of not more than 10 years, or bothA major criticism of HIPAA has been that, in spite of providing welldefinedpenalties, it has not really been heavily enforced; althoughthere have been recent cases of healthcare institutions being auditedby the US Health and Human Services. To address this issue, the USGovernment enacted the Health Information Technology for Economicand Clinical Health (HITECH) Act in 2009. The HITECH Act now pro-160 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!