LogBlog

« Is your data protected if the company closes its doors? | Main | Are Network Sniffers for Database Audit Irrelevant? »

Legal Lessons From a Computer Fraud Case . . .

A recent ruling by a Federal court in Georgia in the Andritz, Inc. v. Southern Maint. Contractor, LLC case held that lost revenue caused by theft may not be recoverable under the Computer Fraud and Abuse Act. This means to me that if you can't stop an ex-employee from stealing information from your systems in the first place via proper de-provisioning and auditing tools, you may be out of luck in terms of recovering lost money caused by that theft.

The lawyers at Wilson Sonsini Goodrich and Rosati wrote an interesting alert about the ruling, which has also been quoted by other bloggers such as Tom Kemp's blog at Centrify.

The bottom line for the lawyers?

1) Make sure you have enforceable non-disclosure and  non-compete agreements with all employees who have access to  sensitive company information can strengthen claims.

2) More  practically, companies may want to consider how they monitor  and enable access to such information and ensure that access  is promptly terminated when the employee departs.

3) Finally, the  presence of or access to tools that enable analysis of user  activity, including log-file management, can help employers  evaluate whether or if any such unlawful access has occurred.

Posted March 04, 2009 in | Permalink


Post a comment

(If you haven’t left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won’t appear on the entry. Thanks for waiting.)

Visit loglogic.com

I ♥ Logs

Subscribe to this blog’s feed RSS

August 2010
Sun Mon Tue Wed Thu Fri Sat
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30 31        
Categories
Archives
Blogroll
Blogroll
Compliance
Good Reading
LogLogic
LogLogic Partners
Sites We Watch