IntroductionUncle Sam Wants You: How Your Company’s Information Security Can Affect U.S. National SecurityLegal Standards Relevant to Information SecuritySelected Federal LawsGramm-Leach-Bliley ActHealth Insurance Portability and Accountability ActSarbanes-OxleyFederal Information Security and Management ActFERPA and the TEACH ActElectronic Communications Privacy Act and Computer Fraud and Abuse ActState LawsUnauthorized AccessDeceptive Trade PracticesEnforcement ActionsThree Fatal FallaciesThe “Single Law” FallacyThe Private Entity FallacyThe “Pen Test Only” FallacyDo It Right or Bet the Company: Tools to Mitigate Legal LiabilityWe Did our Best; What is the Problem?The Basis for LiabilityNegligence and the “Standard of Care”What Can Be Done?Understand your Legal EnvironmentComprehensive and Ongoing Security Assessments, Evaluations, and ImplementationUse Contracts to Define Rights and Protect InformationUse Qualified Third-party ProfessionalsMaking Sure Your Standards-of-care Assessments Keep Up with Evolving LawPlan for the WorstInsuranceWhat to Cover in IEM ContractsWhat, Who, When, Where, How, and How MuchWhatDescription of the Security Evaluation and Business ModelDefinitions Used in the ContractDescription of the ProjectAssumptions, Representations, and WarrantiesBoundaries and LimitationsIdentification of DeliverablesWhoStatement of Parties to the Contractual AgreementAuthority of Signatories to the Contractual AgreementRoles and Responsibilities of Each Party to the Contractual AgreementNon-disclosure and Secrecy AgreementsAssessment PersonnelCrisis Management and Public CommunicationsIndemnification, Hold Harmless, and Duty to DefendOwnership and Control of InformationIntellectual Property ConcernsLicensesWhenActions or Events that Affect ScheduleWhereHowHow MuchFees and CostBilling MethodologyPayment Expectations and ScheduleRights and Procedures to Collect PaymentInsurance for Potential Damage During EvaluationMurphy’s Law (When Something Goes Wrong)Governing LawActs of God, Terror Attacks, and other Unforeseeable EvenWhen Agreement is Breached and RemediesLiquidated DamagesLimitation on LiabilitySurvival of ObligationsWaiver and SeverabilityAmendments to the ContractWhere the Rubber Meets the Road: The LOA as Liability ProtectionBeyond You and Your CustomerSoftware License AgreementsYour Customer’s CustomerThe First Thing We Do...? Why You Want Your Lawyers Involved From Start to FinishAttorney-client PrivilegeAdvice of Counsel DefenseEstablishment and Enforcement of Rigorous Assessment, Interview, and Report-writing StandardsCreating a Good Record for Future LitigationMaximizing Ability to Defend LitigationDealing with Regulators, Law Enforcement, Intelligence, and Homeland Security OfficialsThe Ethics of Information Security Evaluation