In February, the California Attorney General issued the “California Data Breach Report.” That report contained several recommendations, the most controversial of which related to the Center for Internet Security’s Critical Security Controls (the “CCS”). The report stated that “failure to implement all the Controls that apply to an organization’s environment constitutes a lack of reasonable security.” A failure to have “reasonable security” obviously has large legal ramifications for all companies employing or doing business with California residents, so presumably all such businesses will need to comply with the CCS-mandated controls or risk an enforcement action by the California Attorney General.
The problem is that the level of detail and sophistication required to implement all the CCS action items is beyond the reach of many small (and medium-sized) businesses. For example, here’s a subcontrol of one of the 20 controls from the CCS: “Deploy a SIEM (Security Information and Event Management) or log analytic tools for log aggregation and consolidation from multiple machines and for log correlation and analysis. Using the SIEM tool, system administrators and security personnel should devise profiles of common events from given systems so that they can tune detection to focus on unusual activity, avoid false positives, more rapidly identify anomalies, and prevent overwhelming analysts with insignificant alerts.”
How many small businesses know what this means? And if they do not know, and therefore are unable to comply, are they all lacking “reasonable security”?