Liability
A third legal issue relative to honeypots is downstream liability. If a honeypot is compromised and then used to attack other systems in another organization, could the honeypot operator be held liable in a suit brought by downstream victims? Although the harm was inflicted by the intruder rather than the operator, if the honeypot had been secure, then the intruder would not have been able to use it to inflict damage on others. Note that liability, if any, is a matter of state, not federal, law. That means you will need to work with legal counsel who know the law at least of the state(s) in which your organization is located and in which your deployed honeypots are located. The task of your legal counsel may be even more complicated ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access