Recommendation
Congress should require companies to publish security policies to promote transparency with consumers.
Details
Most companies publish privacy policies, which create a transparent and accountable mechanism for regulators to ensure companies are adhering to their stated policies. But no such practice exists for information security practices, which has resulted in vague standards, regulation by buzzword, and information asymmetry in markets. By publishing security policies, companies would be motivated to describe the types of security measures they have in place rather than just make claims of taking “reasonable security measures.” This is a concrete step that policymakers can take to improve security practices in the private sector.
Keep reading:
▪ Daniel Castro, “How Congress Can Fix ‘Internet of Things’ Security,” The Hill, October 28, 2016, http://thehill.com/blogs/pundits-blog/technology/303302-how-congress-can-fix-internet-of-things-security.