September 28, 2007 6:11 AM PDT

CA exec urges Asia to strengthen data-breach laws

Governments in Asia need stronger data-breach laws to ensure businesses improve the security of their customer data, according to a senior executive at IT management specialist CA.

Jerry Cox, CA's director of security sales for the Asia-Pacific region, including Japan, said in an interview that "strong laws would force a company to disclose security breaches often involving the loss of customer data."

This, Cox explained, would protect the people whose data was compromised. Strong data-breach laws will also ensure companies take data security more seriously, especially if there are penalties in the form of monetary fines, or risks of reputation damage due to public disclosure.

According to Cox, Japan and Korea are ahead of most parts of Southern Asia in establishing such laws.

"In Japan, companies pay for security breaches in the form of an 'apology fine,' sometimes per user-account affected, which can amount to millions of dollars," he said, adding, however, that data security in most of Southern Asia is not yet at the level of that deployed in Japan.

Cox said California's strict data-breach law is an example of legislation "driving good security practices." California's law--SB 1386--requires businesses to disclose data-security breaches to residents if their unencrypted personal information is compromised. Other states in the U.S. have since introduced similar laws, and the U.K. is moving in that direction.

Data-breach penalties in Asia are often disproportionately mild compared to the severity and consequences of the breach, Cox said. "In Singapore, spammers can be fined. But you've got half the population online, so it's a bigger crime than it seems, and the penalties should be more severe."

Cox added: "In the United States, the penalty for spamming is jail."

One long-term measure to protect data, Cox suggested, would be to educate people about sound security practices and require them to apply them diligently.

Cox also highlighted the importance of establishing a good security foundation before implementing "higher level" security measures such as identity management.

Explaining what constitutes a foundation of "sound" network security, Cox said that putting up firewalls and antivirus protection, as well as building policies around user permissions, should be established before implementing ID management.

Companies that do not have a good foundation for network security risk the failure of automated security processes such as ID management. Compared to their western counterparts, more companies in Asia are taking this riskier path, Cox warned, noting that a wide range of security technologies are nonetheless readily available in the region.

"While the United States went with the evolution of security tools, companies in Asia have a lot to choose from, even if their organizations are not ready," said Cox. Unlike many Asian companies, those in the U.S. "grew" their security installations and practices by applying more-sophisticated tools as they became available, he said.

He added that enterprise security policies may not be as developed in Asia, and estimates companies in this region to be "five to seven" years behind their U.S. counterparts, despite having access to the latest technology.

Victoria Ho of ZDNet Asia reported from Singapore.

See more CNET content tagged:
Asia, data security, identity management, Computer Associates International Inc., penalty

Add a Comment (Log in or register) 1 comment
He can urge all he wants...
by wbenton October 3, 2007 7:47 AM PDT
But getting such implemented in foreign countries whom don't have as stringent laws as we do is next to impossible! (* CHUCKLE *)

Keep wishing is all I can say... (* LOL *)

Walt
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Samsung contemplating SanDisk acquisition

    South Korean consumer electronics giant is considering a buyout of the chipmaker to reduce its NAND flash memory costs, according to PaidContent.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • The Open Road

    Analysts as a lagging indicator of success

    Gartner, Forrester, and other analyst firms tend to be great predictors of the past, probably because that's where they get their money.

  • Beyond Binary

    Memo: Windows chief on new ads

    Windows business unit head Bill Veghte send a memo to troops late Thursday promising that the debut Seinfeld/Bill Gates ad was just an "icebreaker."

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Digital Media

    Week in review: Google's Chrome shines

    Web giant makes long-awaited foray into browser market, while the mobile market warms up. Also: Tech goes to Republican National Convention.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Politics and Law

    Google and 'Vanity Fair' party with the GOP

    Google and Vanity Fair hosted one of the most talked-about parties at the Republican convention.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • Crave

    Motorola U9 reviewed

    CNET puts the Motorola U9 through its paces.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.