The goal here is not to Mandate levels of security, but rather to define levels of online security that businesses can apply for and receive certification. They can then publish these certifications to consumers so that consumers can make educated choices about what the companies they wish to do business in terms of keeping their data secure. This needs to be an agency and not a law because the types certifications will need to change rapidly to keep up with technology.



