While everyone can discuss security, regulation, and privacy, we first should understand this moving target called best practice and why we should care about it in great detail. The reason you should care is that it's three simple letters: FTC, or, more commonly known, the Federal Trade Commission. Upon clicking the FTC link, you can see the title "Protecting America's Consumers" right under it. What is a consumer, you might logically ask? It applies to everyone who purchases anything, interacts with anyone for the purpose of doing business or performing a service, and covers profit and non-profit entities. Thus, the FTC is the ultimate regulatory body in the United States and covers all aspects of business or engagement with anyone who could be, even remotely, viewed as a "customer," aka consumer. Most people think the FTC has to do with stocks or bonds; sorry to say, but that is the SEC. Hopefully, at this point, you will have in mind that the FTC applies to every business entity, profit or not, that performs actions, functions, activities, sells products, provides services, etc., within the USA.
So, can the FTC impose sanctions and so on for foreign companies? Sure can, they don't care where you are from if you are doing business in the US.
Given that the FTC is the USA's ultimate regulatory body, how many people know about the FTC's security and privacy framework? You can try all you want to find one; however, it simply doesn't exist. The FTC assumes that if you are running a company (doesn't matter if it's for profit or not), then you should know the regulations that apply to you and apply common sense as well as best practices. Unfortunately, best practices vary based on the available technology and the threats being faced. Thus, there are no actual guidelines to go by regarding best practice, but rather the collective opinion of supposed experts in their respective fields.
For example, best practice states that encryption should be used. OK, what kind of encryption? Should we use AES-128 or AES-256? While AES-128 is legal to use, is it safer than just going with AES-256 in the first place? The regulation may specify the use of "appropriate encryption" or a minimum level of encryption. This is where the FTC can swoop in, investigate, and possibly impose sanctions. These sanctions can also be quite punishing, and I'm specifically picking encryption as an example for this particular part.
So, let's say your company has suffered a breach and is using AES-128 per the regulatory standards it must comply with. Regardless of what the regulation states, the FTC can still come in and say, "you should have known better" and "should have applied AES-256 given that AES-256 was so easily readable and would have incurred no additional cost or effort to implement." This is a prime example of how the FTC can "gotcha!".
Has the FTC exercised its muscle before? You bet they have!
- Warning letter to "1 Party at a Time, Inc."
- Warning letter to "Living Senior, LLC."
- D-Link Agrees to make security enhancements to settle FTC litigation
- Tower Records Court order and news release
- Corporate Compliance Services
- Yellowstone Capital LLC
- Pointbreak Media, LLC
So what similarities do we have with the above examples? Only one...consumers. You see examples of commercial, financial, advertising, and other businesses, and these businesses can be of any size. The FTC's goal is to ensure that there is no anticompetitive, deceptive, or unfair business environment or practices. Additionally, the FTC can enforce as it sees fit, including issuing fines, issuing court orders, and pursuing law enforcement options. As it is, you can read through the links to see the various fines; however, not all companies made it...Tower Records is out of business.
What can you do to protect yourself and your company? Firstly, always do your best to protect your company. However, and likely the most important, is to be completely transparent with your customers/consumers and not commit to anything you can't do. A very easy way for a company to get on the FTC radar is to be accused of "deceptive trade practices" or, in other words, lead your clients down the path that your company is doing something when, in reality, it is not for the purpose of getting the business. For example, if there was contractual language that there must be at least annual vendor due diligence and risk assessment review, and that contract was signed under the pretense that the company was either going to, or already was, performing due diligence, then that would definitely be "deceptive trade practices" as it would relate to that one area. At this point, you, the reader, should be wondering whether your company is fully compliant with its contractual obligations.
You may also want to consider the minimum requirements per regulation and determine whether there is anything more you can do that doesn't add an extreme financial burden or effort. This could help you in other areas as well by showing your company went above and beyond regulatory requirements.
Another area to consider is contractual language regarding when and under what circumstances your clients may perform their own audits of your company. Ideally, you want to keep the audit as long as possible to ensure a successful audit, because an unsuccessful audit could lead to an FTC complaint.
Arrakis has built over several months numerous platforms that can help reduce risk. Read more here and those platforms are listed below.
- Compliance Chatbot - a free chatbot relating to compliance, cybersecurity, and privacy.
- Prosikon - A feature rich vendor due diligence platform to help increase visibility and provide more information for safer decisions. Read more here.
- PolicyForge - Build out your policies based on the regulatory environment you care about. Policy and Procedure Templates are included as well as control mapping. Read more here.
- Fortuna Risk Compass - Feature rich risk assessment platform that helps you visualize risk and cost better. Numerous graphical displays and ability to export risks to Prothesis. Read more here.
- Prothesis PoAM Builder - Build your PoAMs to prove you are mitigating risk and demonstrating maturity. Expands on Fortuna risks and demonstrates the "why" on the need for PoAMs. Read more here.
- Mutina SecurePath - Construct your SSPs to meet CMMC, or other frameworks, to provide assurance to external parties. SSPs are required for CMMC compliance. Read more here.
- CyberPrep Test Engine - A subscription based practice test platform covering 50+ certifications. Designed to be more difficult than the actual test to increase certification chances.
Regardless of the platforms, Arrakis suggests contracting professional consultation when seeking certification or compliance.