• Shuffle
    Toggle On
    Toggle Off
  • Alphabetize
    Toggle On
    Toggle Off
  • Front First
    Toggle On
    Toggle Off
  • Both Sides
    Toggle On
    Toggle Off
  • Read
    Toggle On
    Toggle Off
Reading...
Front

Card Range To Study

through

image

Play button

image

Play button

image

Progress

1/16

Click to flip

Use LEFT and RIGHT arrow keys to navigate between flashcards;

Use UP and DOWN arrow keys to flip the card;

H to show hint;

A reads text to speech;

16 Cards in this Set

  • Front
  • Back

Goals of the Act

Reduce spam and unsolicited pornography by prohibiting senders of unsolicited commercial email messages from disguising the source and content of their messages.


Give consumers the choice to cease receiving a sender’s unsolicited commercial email messages.

Affirmative Consent

The recipient expressly consented to receive the message, AND


If the message is from a party other than the party to which the recipient communicated consent, the recipient was given clear and conspicuous notice at the time that the consent was communicated that the recipient’s email could be transferred to such other party for the purpose of initiating commercial email messages.

Commercial Email Messages

Email with the PRIMARY purpose of which is to advertise or promote for a commercial purpose, a commercial product/service.


Not considered a commercial email solely because the message includes a reference to a commercial entity that serves to identify the sender or reference/link a website operated for commercial purpose.

Dictionary Attacks

Obtaining email addresses by using an automated means that generates possible email addresses by combining names, letters, or numbers into numerous permutations.

Harvesting

Obtaining email addresses using an automated means from a website, where such service/person at the time the address was obtained had provided a notice stating they the operator of the website would not give, sell, or otherwise transfer email addresses.

Header Information

The source, destination, and routing information attached to the beginning of an email, including the originating domain name and originating email address.

Hijacking

Use of automated means to register for multiple email accounts or online user accounts from which to transmit, or enable another to transmit, a commercial email message that is unlawful.

Initiate

To originate, transmit, or to procure the origination or transmission of such message but shall not include actions that constitute routine conveyance. More than one person may be considered to have initiated the same message.

Primary Purpose

Will be deemed to be commercial if it contains only the commercial advertisement or promotion of a commercial product/service (commercial content)


Will be deemed to be commercial if it contains both commercial and “transactional/relationship” content IF


-a recipient reasonably interpreting the subject line would likely conclude it to contain commercial content OR


-the email message’s “transactional/relationship” content doesn’t appear in whole or substantial part at the beginning of the body of the message.


Will be deemed commercial if it contains both commercial content as well as content that is not transactional/relationship content if a recipient reasonably interpreting either:


-the subject line would likely conclude that the message contains commercial content OR


-the body of the message would likely conclude that the primary purpose is commercial.


Will be deemed to be transactional/relationship (non-commercial) if it contains only “transactional/relationship” content.

Protected Computer

Exclusively for the use of a financial institution or the US government OR which is used in interstate or foreign commerce or communication.

Recipient

An authorized user of the email address to which the message was sent/delivered.

Sender

A person who initiates an email and whose product, service, or website is advertised or promoted by the message.

Sexually Oriented Material

Any material that depicts sexually explicit conduct unless the depiction constitutes a small and insignificant part of the whole.

Transactional or Relationship Email

Email with the primary purpose of facilitating, completing, or confirming a commercial transaction that the recipient had previously agreed to enter into; to provide warranty, product recall, or safety or security information; or subscription, membership, account, loan, or other information relating to an ongoing purchase or use.

General Requirements

Prohibits:


-the use of false/misleading transmission information


-the use of deceptive subject headings


-address harvesting and dictionary attacks


-hijacking


-any person from knowingly relaying or retransmitting a commercial email that is unlawful


-a person from promoting, or allowing the promotion of, that person's trade/business, or goods, products, property, or services in an unlawful commercial email.




Requires:


-a functioning email return address or other internet-based response mechanism


-commercial email be discontinued within 10 BUSINESS DAYS after receipt of opt-out from recipient


-clear and conspicuous identification that the message is an advertisement/solicitation; clear and conspicuous notice of the opportunity to decline to receive further commercial email; and a valid physical postal address of the sender


-warning labels (in the subject line and within the message body) on the commercial email messages containing sexually oriented material.

Examination Objectives

Assess the quality of the bank's CMS related to CAN-SPAM


Can monitoring/audit be relied upon for compliance with CAN-SPAM?


Determine the bank's compliance with CAN-SPAM


If violations of law are identified, or if controls in place are deficient, initiate effective corrective actions