Skip Links

Network World

  • Social Web 
  • Email 
  • Close

WEIS 2008: Do data-breach-disclosure laws reduce identity theft?

Research attempts to answer the question
Security Strategies Alert By M. E. Kabay , Network World , 07/29/2008
Sign up for this newsletter now!

Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.

  • Share/Email
  • Comment
  • Print

At the 2008 Workshop on the Economics of Information Security (WEIS 2008) at Dartmouth College last month (see also my overview in this column), there were many fascinating research papers presented by distinguished scholars. In this short series, I will summarize some of the most striking findings of several researchers whose work I particularly enjoyed (I must quickly add that my not discussing particular articles should in no way be construed as criticism).

Sasha Romanosky, a doctoral student, presented a paper he co-authored with Prof. Rahul Telang and Prof. Alessandro Acquisti. The three researchers are from the Heinz School of Public Policy and Management, at Carnegie Mellon University. Their paper is “Do Data Breach Disclosure Laws Reduce Identity Theft?" Carnegie Mellon’s CyLab summarized their work and pointed to a June 5 article about it by Robert McMillan.

The key points of the researchers’ methods and findings were:

• The question: do data-breach-disclosure laws reduce the frequency of identity theft?
• The researchers used the Freedom of Information Act to request identity theft data from the FTC over the years 2002 to 2006.
• Their statistical model allowed them to control for many economic and demographic factors.
• In this preliminary paper, they found a negative but not statistically significant relationship between implementation of data-breach-disclosure laws and the rate of identity theft.
• The absence of measurable relationship may indicate an absence in reality (what statisticians call the parametric values) or may indicate problems in the sampling (size or quality of the dataset). However, see the next comment immediately below.

The researchers have since augmented their analysis and data to include 2007 identity thefts and find negative and statistically significant but marginal effect of disclosure laws on identity theft rates (a reduction of 1.2 reported thefts per 100,000 population or about 2% of the crime rate). Sasha Romanosky commented:

“It’s not clear whether that’s a large enough effect to justify the laws. Nor is it clear what is the net social effect (costs relative to benefits). There are likely other benefits of these disclosure laws, and we are studying only one possible outcome. We also recognize that to be most effective, the responsibility lies with both firms and consumers to take appropriate action to prevent identity theft.”

M. E. Kabay, PhD, CISSP-ISSMP, is Program Director of the Master of Science in Information Assurance program at Norwich University.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (2)
Login
Forgot your account info?

View from another angleBy Mike.D. on July 29, 2008, 12:22 pmMich, perhaps we are just looking at this result from the wrong angle. Assume the number of attacks like this have gone up. I can't prove this and haven't done any...

Reply | Read entire comment

Could the researches be looking for the wrong benefitBy Anonymous on July 29, 2008, 10:19 amI thought the reason for the law was so the victim whose data was comprimised could take action to check there credit reports, or place resrtictions on allowing...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed