Sunteți pe pagina 1din 3

Federal Register / Vol. 73, No.

16 / Thursday, January 24, 2008 / Notices 4231

natural progesterone. According to the corporate structure and changes in requesting that any comment filed in
Commission’s complaint, the employment that might affect paper form be sent by courier or
respondents represented that Eternal compliance obligations under the order; overnight service, if possible, because
Woman Progesterone Cream and Pro- and to file compliance reports with the U.S. postal mail in the Washington area
Gest Body Cream: (1) were effective in Commission. Part IX provides that the and at the Commission is subject to
preventing, treating, or curing order will terminate after twenty (20) delay due to heightened security
osteoporosis; (2) were effective in years under certain circumstances. precautions. Comments that do not
preventing or reducing the risk of The purpose of this analysis is to contain any nonpublic information may
estrogen-inducted endometrial (uterine) facilitate public comment on the instead be filed in electronic form as
cancer; and (3) did not increase the proposed order. It is not intended to part of or as an attachment to email
user’s risk of developing breast cancer constitute an official interpretation of messages directed to the following email
and/or were effective in preventing or the agreement and proposed order or to box: consentagreement@ftc.gov.
reducing the user’s risk of developing modify in any way their terms. The FTC Act and other laws the
breast cancer. The complaint alleged By direction of the Commission. Commission administers permit the
that the respondents failed to have collection of public comments to
Donald S. Clark
substantiation for these claims. The consider and use in this proceeding as
proposed consent order contains Secretary appropriate. All timely and responsive
provisions designed to prevent the [FR Doc. E8–1169 Filed 1–23–08: 8:45 am] public comments, whether filed in
respondents from engaging in similar [BILLING CODE 6750–01–S] paper or electronic form, will be
acts and practices in the future. considered by the Commission, and will
Part I of the proposed order requires be available to the public on the FTC
the respondents to have competent and FEDERAL TRADE COMMISSION website, to the extent practicable, at
reliable scientific evidence [File No. 072 3046] www.ftc.gov. As a matter of discretion,
substantiating claims that any the FTC makes every effort to remove
progesterone product or any other Life is good, Inc., and Life is good home contact information for
dietary supplement, food, drug, device Retail, Inc.; Analysis of Proposed individuals from the public comments it
or health-related service or program is Consent Order to Aid Public Comment receives before placing those comments
effective in preventing, treating, or on the FTC website. More information,
curing osteoporosis, in preventing or AGENCY: Federal Trade Commission. including routine uses permitted by the
reducing the risk of estrogen-induced ACTION: Proposed Consent Agreement. Privacy Act, may be found in the FTC’s
endometrial cancer or breast cancer, or SUMMARY: The consent agreement in this
privacy policy, at http://www.ftc.gov/
in the mitigation, treatment, prevention, matter settles alleged violations of ftc/privacy.htm.
or cure of any disease, illness, or health federal law prohibiting unfair or FOR FURTHER INFORMATION CONTACT:
condition; that it does not increase the deceptive acts or practices or unfair Jessica Rich, FTC Bureau of Consumer
user’s risk of developing breast cancer, methods of competition. The attached Protection, 600 Pennsylvania Avenue,
is safe for human use, or has no side NW., Washington, D.C. 20580, (202)
Analysis to Aid Public Comment
effects; or about its health benefits, 326-2252.
describes both the allegations in the
performance, efficacy, safety, or side SUPPLEMENTARY INFORMATION: Pursuant
draft complaint and the terms of the
effects. to section 6(f) of the Federal Trade
Part II of the proposed order prevents consent order—embodied in the consent
agreement—that would settle these Commission Act, 38 Stat. 721, 15 U.S.C.
the respondents from misrepresenting 46(f), and § 2.34 of the Commission
the existence, contents, validity, results, allegations.
Rules of Practice, 16 CFR 2.34, notice is
conclusions, or interpretations of any DATES: Comments must be received on
hereby given that the above-captioned
test, study, or research. or before February 19, 2008. consent agreement containing a consent
Part III of the proposed order provides ADDRESSES: Interested parties are order to cease and desist, having been
that the order does not prohibit the invited to submit written comments. filed with and accepted, subject to final
respondents from making Comments should refer to ‘‘Life is good, approval, by the Commission, has been
representations for any drug that are File No. 072 3046,’’ to facilitate the placed on the public record for a period
permitted in labeling for the drug under organization of comments. A comment of thirty (30) days. The following
any tentative final or final Food and filed in paper form should include this Analysis to Aid Public Comment
Drug Administration (‘‘FDA’’) standard reference both in the text and on the describes the terms of the consent
or under any new drug application envelope, and should be mailed or agreement, and the allegations in the
approved by the FDA; representations delivered to the following address: complaint. An electronic copy of the
for any medical device that are Federal Trade Commission/Office of the full text of the consent agreement
permitted in labeling under any new Secretary, Room 135-H, 600 package can be obtained from the FTC
medical device application approved by Pennsylvania Avenue, NW., Home Page (for January 17, 2008), on
the FDA; and representations for any Washington, D.C. 20580. Comments the World Wide Web, at http://
product that are specifically permitted containing confidential material must be www.ftc.gov/os/2008/01/index.htm. A
in labeling for that product by filed in paper form, must be clearly paper copy can be obtained from the
regulations issued by the FDA under the labeled ‘‘Confidential,’’ and must FTC Public Reference Room, Room 130-
Nutrition Labeling and Education Act of comply with Commission Rule 4.9(c). H, 600 Pennsylvania Avenue, NW.,
1990. 16 CFR 4.9(c) (2005).1 The FTC is Washington, D.C. 20580, either in
Parts IV through VIII require the person or by calling (202) 326-2222.
respondents to keep copies of relevant 1 The comment must be accompanied by an
Public comments are invited, and may
jlentini on PROD1PC65 with NOTICES

advertisements and materials explicit request for confidential treatment, be filed with the Commission in either
substantiating claims made in the including the factual and legal basis for the request,
and must identify the specific portions of the paper or electronic form. All comments
advertisements; to provide copies of the comment to be withheld from the public record.
order to certain of their personnel; to The request will be granted or denied by the applicable law and the public interest. See
notify the Commission of changes in Commission’s General Counsel, consistent with Commission Rule 4.9(c), 16 CFR 4.9(c).

VerDate Aug<31>2005 20:35 Jan 23, 2008 Jkt 214001 PO 00000 Frm 00060 Fmt 4703 Sfmt 4703 E:\FR\FM\24JAN1.SGM 24JAN1
4232 Federal Register / Vol. 73, No. 16 / Thursday, January 24, 2008 / Notices

should be filed as prescribed in the related types of attacks; (4) failed to use 4. Develop and use reasonable steps to
ADDRESSES section above, and must be readily available security measures to retain service providers capable of
received on or before the date specified monitor and control connections from appropriately safeguarding personal
in the DATES section. the network to the internet; and (5) information they receive from
failed to employ sufficient measures to respondents, require service providers
Analysis of Agreement Containing
Consent Order to Aid Public Comment detect unauthorized access to credit by contract to implement and maintain
card information. appropriate safeguards, and monitor
The Federal Trade Commission has The complaint further alleges that their safeguarding of personal
accepted, subject to final approval, a between June and August 2006, a hacker
consent agreement from Life is good, information.
exploited Life is good’s failures by using
Inc. and Life is good Retail, Inc. SQL injection attacks on Life is good’s 5. Evaluate and adjust its information
(collectively, ‘‘Life is good’’). website and web application and security program in light of the results
The proposed consent order has been exporting to the hacker’s browser of the testing and monitoring, any
placed on the public record for thirty consumer information for thousands of material changes to its operations or
(30) days for receipt of comments by customers, including credit card business arrangements, or any other
interested persons. Comments received numbers, expiration dates, and security circumstances that it knows or has
during this period will become part of codes. reason to know may have a material
the public record. After thirty (30) days, impact on the effectiveness of their
The proposed order applies to
the Commission will again review the information security program.
personal information Life is good
agreement and the comments received,
collects from or about consumers. It Part III of the proposed order requires
and will decide whether it should
contains provisions designed to prevent that Life is good obtain, covering the
withdraw from the agreement and take
Life is good from engaging in the future first 180 days after the order is served,
appropriate action or make final the
in practices similar to those alleged in and on a biennial basis thereafter for
agreement’s proposed order.
Life is good designs and distributes the complaint. twenty (20) years, an assessment and
retail apparel and accessories and Part I of the proposed order prohibits report from a qualified, objective,
operates a retail website at Life is good, in connection with the independent third-party professional,
www.lifeisgood.com. In selling its collection of personally identifiable certifying, among other things, that (1)
products, Life is good routinely has information from or about consumers, in it has in place a security program that
collected sensitive information from or affecting commerce, from provides protections that meet or exceed
consumers, including name, address, e- misrepresenting the extent to which it the protections required by Part II of the
mail address, phone number, credit card maintains and protects the privacy,
proposed order; and (2) its security
number, credit card expiration date, and confidentiality, or integrity of such
program is operating with sufficient
credit card security code (hereinafter information.
effectiveness to provide reasonable
‘‘consumer information’’). Life is good Part II of the proposed order requires
assurance that the security,
has collected this consumer information Life is good to establish and maintain a
comprehensive information security confidentiality, and integrity of
through its website and telephone consumers’ personal information is
orders and stored it on a network program in writing that is reasonably
designed to protect the security, protected.
computer accessible through the
website. This matter concerns alleged confidentiality, and integrity of personal Parts IV through VII of the proposed
false or misleading representations Life information collected from or about order are reporting and compliance
is good made about the security it consumers. The security program must provisions. Part IV requires Life is good
provided for this information. contain administrative, technical, and to retain documents relating to their
The Commission’s proposed physical safeguards appropriate to Life compliance with the order. For most
complaint alleges that Life is good is good’s size and complexity, the records, the order required that the
represented that it implemented nature and scope of its activities, and documents be retained for a five-year
reasonable and appropriate security the sensitivity of the personal period. For the third-party assessments
measures to protect the privacy and information collected from or about and supporting documents, Life is good
confidentiality of sensitive consumer consumers. Specifically, the order must retain the documents for a period
information. The complaint alleges this requires Life is good to: of three years after the date that each
representation was false because Life is 1. Designate an employee or assessment is prepared. Part V requires
good engaged in a number of practices employees to coordinate and be dissemination of the order now and in
that, taken together, failed to provide accountable for the information security the future to persons with
reasonable and appropriate security for program. responsibilities relating to the subject
the sensitive consumer information 2. Identify material internal and matter of the order. Part VI ensures
stored on its computer network. In external risks to the security, notification to the FTC of changes in
particular, Life is good: (1) created confidentiality, and integrity of personal corporate status. Part VII mandates that
unnecessary risks to credit card information that could result in the Life is good submit an initial
information by storing it indefinitely in unauthorized disclosure, misuse, loss,
compliance report to the FTC, and make
clear, readable text on its network alteration, destruction, or other
available to the FTC subsequent reports.
without a business need, and by storing compromise of such information, and
Part VIII is a provision ‘‘sunsetting’’ the
credit card security codes; (2) failed to assess the sufficiency of any safeguards
order after twenty (20) years, with
assess adequately the vulnerability of its in place to control these risks.
web application and corporate computer 3. Design and implement reasonable certain exceptions.
jlentini on PROD1PC65 with NOTICES

network to certain commonly known or safeguards to control the risks identified The purpose of the analysis is to aid
reasonably foreseeable attacks, such through risk assessment, and regularly public comment on the proposed order.
SQL injection attacks; (3) failed to test or monitor the effectiveness of the It is not intended to constitute an
implement simple, free or low-cost, and safeguards’ key controls, systems, and official interpretation of the proposed
readily available defenses to SQL and procedures. order or to modify its terms in any way.

VerDate Aug<31>2005 20:35 Jan 23, 2008 Jkt 214001 PO 00000 Frm 00061 Fmt 4703 Sfmt 4703 E:\FR\FM\24JAN1.SGM 24JAN1
Federal Register / Vol. 73, No. 16 / Thursday, January 24, 2008 / Notices 4233

By direction of the Commission. burden to the Regulatory Secretariat DEPARTMENT OF HEALTH AND
(VIR), General Services Administration, HUMAN SERVICES
Donald S. Clark
Room 4035, 1800 F Street, NW.,
Secretary Administration for Children and
Washington, DC 20405. Please cite OMB
[FR Doc. E8–1168 Filed 1–23–08: 8:45 am] Families
Control No. 3090–0197, GSAR Provision
[BILLING CODE 6750–01–S]
552.237–70, Qualifications of Offerors,
Submission for OMB Review;
in all correspondence.
Comment Request
GENERAL SERVICES SUPPLEMENTARY INFORMATION:
ADMINISTRATION Title: Application Requirements for
A. Purpose the Low Income Home Energy
[OMB Control No. 3090–0197] Assistance Program (LIHEAP)
The General Services Administration Residential Energy Assistance Challenge
General Services Administration (GSA) has various mission Program (REACH) Model Plan.
Acquisition Regulation;Information responsibilities related to the OMB No.: New Collection.
Collection; GSAR Provision 552.237– acquisition and provision of service Description: States, including the
70, Qualifications of Offerors contracts. These mission responsibilities District of Columbia, Tribes, Tribal
AGENCY: Office of the Chief Acquisition generate requirements that are realized organizations and Territories applying
Officer, GSA. through the solicitation and award of for LIHEAP REACH funds must submit
ACTION: Notice of request for comments contracts for building services. an annual application prior to receiving
regarding a renewal to an existing OMB Individual solicitations and resulting Federal funds. The Human Services
clearance. contracts may impose unique Amendments of 1994 (Pub. L. 103–252)
information collection and reporting amended the LIHEAP statute to add
SUMMARY: Under the provisions of the requirements on contractors not Section 2607B, which established the
Paperwork Reduction Act of 1995 (44 required by regulation, but necessary to REACH Program. REACH was funded
U.S.C. Chapter 35), the General Services evaluate particular program for the first time in FY 1996 and is
Administration will be submitting to the accomplishments and measure success intended to: (1) Minimize health and
Office of Management and Budget in meeting program objectives. safety risks that result from high energy
(OMB) a request to review and approve burdens on low-income Americans; (2)
a renewal of a currently approved B. Annual Reporting Burden reduce home energy vulnerability and
information collection requirement prevent homelessness as a result of the
regarding the qualifications of offerors. Respondents: 6794
inability to pay energy bills; (3) increase
The clearance currently expires on April Responses Per Respondent: 1 the efficiency of energy usage by low-
30, 2008. Hours Per Response: 1 income families, helping them achieve
Public comments are particularly energy self-sufficiency; and (4) target
invited on: Whether this collection of Total Burden Hours: 6794
energy assistance to individuals who are
information is necessary and whether it OBTAINING COPIES OF most in need.
will have practical utility; whether our PROPOSALS: Requesters may obtain a The REACH Model Plan clarifies the
estimate of the public burden of this copy of the information collection information being requested and
collection of information is accurate, documents from the General Services ensures the submission of all the
and based on valid assumptions and Administration, Regulatory Secretariat information required by statute. The
methodology; ways to enhance the (VIR), 1800 F Street, NW., Room 4035, form facilitates our response to
quality, utility, and clarity of the Washington, DC 20405, telephone (202) numerous queries each year concerning
information to be collected. 501–4755. Please cite OMB Control No. the information that should be included
DATES: Submit comments on or before: 3090–0197, GSAR Provision 552.237– in the REACH application. Submission
March 24, 2008. 70, Qualifications of Offerors, in all of a REACH application and use of the
FOR FURTHER INFORMATION CONTACT: Mr. correspondence. REACH Model Plan is voluntary.
Michael Jackson, Contract Policy Grantees have the option to use another
Dated: January 15, 2008.
Division, GSA, (202) 208–4949. format.
Al Matera,
ADDRESSES: Submit comments regarding Respondents: State Governments,
this burden estimate or any other aspect Director, Office of Acquisition Policy. Tribal governments, Insular Areas, the
of this collection of information, [FR Doc. E8–1144 Filed 1–23–08; 8:45 am] District of Columbia, and the
including suggestions for reducing this BILLING CODE 6820–61–S Commonwealth of Puerto Rico.

ANNUAL BURDEN ESTIMATES


Number of Average
Number of Total burden
Instrument responses per burden hours
respondents hours
respondent per response

REACH Model Plan ......................................................................................... 51 1 72 3,672

Estimated Total Annual Burden Administration, Office of Information information collection. E-mail address:
jlentini on PROD1PC65 with NOTICES

Hours: 3,672. Services, 370 L’Enfant Promenade, SW., infocollection@acf.hhs.gov.


Additional Information: Copies of the Washington, DC 20447, Attn: ACF OMB Comment: OMB is required to
proposed collection may be obtained by Reports Clearance Officer. All requests make a decision concerning the
writing to the Administration for should be identified by the title of the collection of information between 30
Children and Families, Office of and 60 days after publication of this

VerDate Aug<31>2005 20:35 Jan 23, 2008 Jkt 214001 PO 00000 Frm 00062 Fmt 4703 Sfmt 4703 E:\FR\FM\24JAN1.SGM 24JAN1

S-ar putea să vă placă și