Found this on IGN
If you follow American politics, then you know that the U.S. Congress
works in a series of committees and subcommittees that deal with the
pressing issues of the day. One such subcommittee -- the Subcommittee on
Commerce, Manufacturing and Trade (branched out from the House's
Committee on Energy and Commerce) -- recently released an inquiry into
the catastrophic breach of Sony's servers.
With the PlayStation Network now out of commission for two weeks and
counting, two members of the committee -- Congresswoman Mary Bono Mack
(R-CA) and Congressman G.K. Butterfield (D-NC) -- asked Sony a series of
questions on how something like this could happen, and what steps Sony
intends on taking to make things better with the millions of consumers
who were victimized by these events.
The PlayStation Blog posted a summary of Sony's response to the subcommittee, the long-form of which
spans eight pages.
Sony's blog-based summary began by stating their four key principles in dealing with the attack and the aftermath:
- 1. Act with care and caution.
- 2. Provide relevant information to the public when it has been verified.
- 3. Take responsibility for our obligations to our customers.
- 4. Work with law enforcement authoritiesSony also expounded upon six key elements of its response on the Blog, which included the following:
- Sony has been the victim of a very carefully planned, very professional, highly sophisticated criminal cyber attack.
- We discovered that the intruders had planted a file on one of our
Sony Online Entertainment servers named "Anonymous" with the words "We
are Legion."
- By April 25, forensic teams were able to confirm the scope of the
personal data they believed had been taken, and could not rule out
whether credit card information had been accessed. On April 26, we
notified customers of those facts.
- As of today, the major credit card companies have not reported any
fraudulent transactions that they believe are the direct result of this
cyber attack.
- Protecting individuals' personal data is the highest priority and
ensuring that the Internet can be made secure for commerce is also
essential. Worldwide, countries and businesses will have to come
together to ensure the safety of commerce over the Internet and find
ways to combat cybercrime and cyber terrorism.
- We are taking a number of steps to prevent future breaches,
including enhanced levels of data protection and encryption; enhanced
ability to detect software intrusions, unauthorized access and unusual
activity patterns; additional firewalls; establishment of a new data
center in an undisclosed location with increased security; and the
naming of a new Chief Information Security Officer.
web link to IGN