You are on page 1of 2

Federal Register / Vol. 71, No.

41 / Thursday, March 2, 2006 / Notices 10687

billion, for more than 119,000 small and these cards were unable to use them to sufficient effectiveness to provide
mid-size merchants. In the course of access credit and their own bank reasonable assurance that the security,
processing these credit and debit card accounts. confidentiality, and integrity of
purchases, CardSystems collected and The proposed order applies to consumers’ personal information has
stored personal information about personal information from or about been protected.
consumers, including card number and consumers that CardSystems and Pay By Parts III through VII of the proposed
expiration date and other information, Touch (as CardSystems’ successor) order are reporting and compliance
from magnetic stripes on the cards. Pay collect in connection with authorization provisions. Part III requires
By Touch acquired CardSystems’ assets processing. The proposed order contains CardSystems and Pay By Touch to
on December 9, 2005, at which time provisions designed to prevent them retain documents relating to their
CardSystems ceased doing business. Pay from engaging in the future in practices compliance with the order. Part IV
By Touch uses CardSystems’ former similar to those alleged in the requires dissemination of the order now
employees, equipment, and technology complaint. and in the future to persons with
to process transactions for the same Part I of the proposed order requires responsibilities relating to the subject
merchants CardSystems served. CardSystems and Pay By Touch to matter of the order. Part V requires them
The Commission’s proposed establish and maintain a comprehensive to notify the Commission of changes in
complaint alleges that CardSystems information security program in writing their corporate status. Part VI mandates
stored personal information on that is reasonably designed to protect that CardSystems and Pay By Touch
computers on its computer network and the security, confidentiality, and submit compliance reports to the FTC.
failed to employ reasonable and integrity of personal information they Part VII is a provision ‘‘sunsetting’’ the
appropriate security measures to protect collect from or about consumers. The order after twenty (20) years, with
the information. The complaint alleges security program must contain certain exceptions.
that this failure was an unfair practice administrative, technical, and physical This case is similar to the recent FTC
because it caused or was likely to cause safeguards appropriate to their size and cases against BJ’s Wholesale Club and
substantial consumer injury that was complexity, the nature and scope of DSW Inc., which also involved alleged
not reasonably avoidable and was not their activities, and the sensitivity of the failures to secure credit and debit card
outweighed by countervailing benefits personal information collected. information. As in those cases,
to consumers or competition. In Specifically, the order requires CardSystems faces potential liability in
particular, CardSystems engaged in a CardSystems and Pay By Touch to: the millions of dollars under bank
number of practices that, taken together, • Designate an employee or procedures and in private litigation for
failed to provide reasonable and employees to coordinate and be losses related to the breach.
appropriate security for personal accountable for the information security The purpose of this analysis is to
information stored on its computer program. facilitate public comment on the
network. Among other things, it: (1) • Identify material internal and proposed order. It is not intended to
Created unnecessary risks to the external risks to the security, constitute an official interpretation of
information by storing it; (2) did not confidentiality, and integrity of the proposed order or to modify its
adequately assess the vulnerability of its consumer information that could result terms in any way.
computer network to commonly known in unauthorized disclosure, misuse,
or reasonably foreseeable attacks, loss, alteration, destruction, or other By direction of the Commission, with
compromise of such information, and Commissioner Harbour recused.
including but not limited to ‘‘Structured
Query Language’’ injection attacks; (3) assess the sufficiency of any safeguards Donald S. Clark,
did not implement simple, low-cost, in place to control these risks. Secretary.
and readily available defenses to such • Design and implement reasonable [FR Doc. E6–2934 Filed 3–1–06; 8:45 am]
attacks; (4) failed to use strong safeguards to control the risks identified BILLING CODE 6750–01–P
passwords to prevent a hacker from through risk assessment, and regularly
gaining control over computers on its test or monitor the effectiveness of the
computer network and access to safeguards’ key controls, systems, and GENERAL SERVICES
personal information stored on the procedures. ADMINISTRATION
network; (5) did not use readily • Evaluate and adjust their
information security program in light of [OMB Control No. 3090–0228]
available security measures to limit
access between computers on its the results of testing and monitoring,
Office of Civil Rights; Information
network and between such computers any material changes to their operations
Collection; Nondiscrimination in
and the Internet; and (6) failed to or business arrangements, or any other
Federal Financial Assistance Programs
employ sufficient measures to detect circumstances that they know or have to
unauthorized access to personal reason to know may have a material AGENCY: Office of Civil Rights, GSA.
information or to conduct security impact on the effectiveness of their ACTION: Notice of request for comments
investigations. information security program. regarding a renewal to an existing OMB
The complaint further alleges that Part II of the proposed order requires clearance.
several million dollars in fraudulent that CardSystems and Pay By Touch
purchases were made using counterfeit obtain within 180 days, and on a SUMMARY: Under the provisions of the
copies of credit and debit cards that biennial basis thereafter, an assessment Paperwork Reduction Act of 1995 (44
contained the same personal and report from a qualified, objective, U.S.C. Chapter 35), the General Services
information CardSystems had collected independent third-party professional, Administration will be submitting to the
from the magnetic stripes of credit and certifying, among other things, that: (1) Office of Management and Budget
wwhite on PROD1PC61 with NOTICES

debit cards and then stored on its They have in place a security program (OMB) a request to review and approve
computer network. After discovering the that provides protections that meet or a renewal of a currently approved
fraudulent purchases, banks cancelled exceed the protections required by Part information collection requirement
and re-issued thousands of these credit I of the proposed order, and (2) their regarding nondiscrimination in Federal
and debit cards, and consumers holding security program is operating with financial assistance programs. The

VerDate Aug<31>2005 17:54 Mar 01, 2006 Jkt 208001 PO 00000 Frm 00054 Fmt 4703 Sfmt 4703 E:\FR\FM\02MRN1.SGM 02MRN1
10688 Federal Register / Vol. 71, No. 41 / Thursday, March 2, 2006 / Notices

clearance currently expires on June 30, program(s) and how the recipient is a renewed focus on commissioning
2006. This information is needed to addressing meaningful access for works of art that are an integral part of
facilitate nondiscrimination in GSA’s individuals that are Limited English the building’s architecture and adjacent
Federal Financial Assistance Programs, Proficient; whether there has been landscape was instituted. The program
consistent with Federal civil rights laws complaints or lawsuits filed against the continues to commission works of art
and regulations that apply to recipients recipient based on prohibited from living American artists. One-half of
of Federal financial assistance. discrimination and whether there has one percent of the estimated
Public comments are particularly been any findings; and whether the construction cost of new or substantially
invited on: Whether this collection of recipient’s facilities are accessible to renovated Federal buildings and U.S.
information is necessary and whether it qualified individuals with disabilities. courthouses is allocated for
will have practical utility; whether our commissioning works of art.
estimate of the public burden of this B. Annual Reporting Burden
Public comments are particularly
collection of information is accurate and Respondents: 500. invited on: Whether this collection of
based on valid assumptions and Responses Per Respondent: 1. information is necessary and whether it
methodology; and ways to enhance the Total Responses: 500. will have practical utility; whether our
quality, utility, and clarity of the Hours Per Response: 2. estimate of the public burden of this
information to be collected. Total Burden Hours: 1000. collection of information is accurate and
DATES: Submit comments on or before: Obtaining Copies of Proposals: based on valid assumptions and
May 1, 2006. Requesters may obtain a copy of the methodology; and ways to enhance the
FOR FURTHER INFORMATION CONTACT: information collection documents from quality, utility, and clarity of the
Evelyn Britton, Compliance Officer, the General Services Administration, information to be collected.
Office of Civil Rights, at telephone (202) Regulatory Secretariat (VIR), 1800 F DATES: Submit comments on or before:
501–4347 or via e-mail to Street, NW., Room 4035, Washington, May 1, 2006.
evelyn.britton@gsa.gov. DC 20405, telephone (202) 208–7312. FOR FURTHER INFORMATION CONTACT:
ADDRESSES: Submit comments regarding
Please cite OMB Control No. 3090–0228, Susan Harrison, Public Buildings
this burden estimate or any other aspect Nondiscrimination in Federal Financial Service, Office of the Chief Architect,
of this collection of information, Assistance Programs, in all Art-in-Architecture Program, Room
including suggestions for reducing this correspondence. 3341, 1800 F Street, NW., Washington,
burden to the Regulatory Secretariat Dated: February 23, 2006. DC 20405, at telephone (202) 501–1812
(VIR), General Services Administration, Michael W. Carleton, or via e-mail to susan.harrison@gsa.gov.
Room 4035, 1800 F Street, NW., Chief Information Officer. ADDRESSES: Submit comments regarding
Washington, DC 20405. Please cite OMB [FR Doc. E6–2932 Filed 3–1–06; 8:45 am] this burden estimate or any other aspect
Control No. 3090–0228, BILLING CODE 6820–34–S of this collection of information,
Nondiscrimination in Federal Financial including suggestions for reducing this
Assistance Programs, in all burden, to the Regulatory Secretariat
correspondence. GENERAL SERVICES (VIR), General Services Administration,
SUPPLEMENTARY INFORMATION: ADMINISTRATION Room 4035, 1800 F Street, NW.,
[OMB Control No. 3090–0274]
Washington, DC 20405. Please cite OMB
A. Purpose
Control No. 3090–0274, Art-in-
The General Services Administration Public Buildings Service; Information Architecture Program National Artist
(GSA) has mission responsibilities Collection; Art-in-Architecture Registry, in all correspondence.
related to monitoring and enforcing Program National Artist Registry SUPPLEMENTARY INFORMATION:
compliance with Federal civil rights
laws and regulations that apply to AGENCY: Public Buildings Service, GSA. A. Purpose
Federal Financial Assistance programs ACTION: Notice of request for comments The Art-in-Architecture Program
administered by GSA. Specifically, regarding a renewal to an existing OMB actively seeks to commission works
those laws provide that no person on clearance. from the full spectrum of American
the ground of race, color, national artists and strives to promote new media
origin, disability, sex or age shall be SUMMARY: Under the provisions of the and inventive solutions for public art.
excluded from participation in, be Paperwork Reduction Act of 1995 (44 The GSA Form 7437, Art-in-
denied the benefits of, or be otherwise U.S.C. Chapter 35), the General Services Architecture Program National Artist
subjected to discrimination under any Administration will be submitting to the Registry, will be used to collect
program in connection with which Office of Management and Budget information from artists across the
Federal financial assistance is extended (OMB) a request to review and approve country to participate and to be
under laws administered in whole or in a renewal of a currently approved considered for commissions.
part by GSA. These mission information collection requirement
responsibilities generate the regarding the Art-in-Architecture B. Annual Reporting Burden
requirement to request and obtain Program National Artist Registry form. Respondents: 360.
certain data from recipients of Federal The clearance currently expires on July Responses Per Respondent: 1.
surplus property for the purpose of 31, 2006. Hours Per Response: .25.
determining compliance, such as the The Art-in-Architecture Program is Total Burden Hours: 90.
number of individuals, based on race the result of a policy decision made in Obtaining Copies of Proposals:
and ethnic origin, of the recipient’s January 1963 by GSA Administrator Requesters may obtain a copy of the
wwhite on PROD1PC61 with NOTICES

eligible and actual serviced population; Bernard L. Boudin who had served on information collection documents from
race and national origin of those denied the Ad Hoc Committee on Federal the General Services Administration,
participation in the recipient’s Office Space in 1961–1962. Regulatory Secretariat (VIR), 1800 F
program(s); non-English languages The program has been modified over Street, NW., Room 4035, Washington,
encountered by the recipient’s the years, most recently in 1996 when DC 20405, telephone (202) 208–7312.

VerDate Aug<31>2005 17:54 Mar 01, 2006 Jkt 208001 PO 00000 Frm 00055 Fmt 4703 Sfmt 4703 E:\FR\FM\02MRN1.SGM 02MRN1

You might also like