Showing posts with label Data Security. Show all posts
Showing posts with label Data Security. Show all posts

Wednesday, August 11, 2010

The Importance of Antivirus

Malware On The Rise

Reuters recently published an article claiming that malware has hit an all time high. They state that McAfee, the number two security software provider, found that malware reached a new record in the first half of 2010. Malware is software code that, when introduced into a system, can hack the computer, steal passwords and identities, and reap havoc on system performance.

McAfee says that 10 million new pieces of malicious code have been catalogued. What is most noteworthy of these findings is that Mac systems are becoming increasingly vulnerable to attacks. Apple users tout that Macs are virtually “insusceptible to viruses,” however as Macs continue to increase their market share, their vulnerability is also rising.


Android Antivirus

In similar news, the first Trojan has been reported on the Android Operating System for smartphones. The malware poses as a media player and once installed on the phone, sends text messages to premium text numbers inadvertently charging the user. Hackers are usually on the receiving end of the text messages, and thus profit from the rouge SMS messages.

According to the article, posted on Mashable.com, Kaspersky Labs is in the process of developing a mobile antivirus application for Android phones, due to be released next year.


The Bottom Line

You need to take precautions. Whether you are dealing with your personal computer or your organization’s infrastructure, steps need to be made to make sure your system(s) are secured.

Basic necessities include using a firewall, password protecting your WiFi, and having an up to date antivirus system installed (including Mac systems).

Additional steps, such as security assessments and security audits can be performed to make sure your organization isn’t vulnerable to outside attacks.

Most importantly, self monitoring is the key. Be sure to stay away from sketchy websites (including those not suitable for the workplace) and making sure you only download files from people or websites you know and trust.

Friday, July 23, 2010

Legal Advice For IT Professionals

Even though it may be your job to handle sensitive information, how you handle the data is just as important as how well it is secured.

One of the best ways to avoid any sort of legal snafu is to have a privacy policy in place. The policy needs to be all encompassing, meaning it covers EVERYTHING accessed on the company’s network (i.e. email, network drives, Twitter, Facebook, VPN connections from offsite, etc).

Privacy Policy

The policy should mandate guidelines of acceptable computer usage while using company resources (including all data).

Another step would be to conduct a Security Assessment and Security Audit.

  • A Security Assessment identifies vulnerabilities within an organization’s infrastructure and will then recommend solutions to secure the system.
  • A Security Audit installs an application on the network that is designed to identify, classify, secure, monitor and report on sensitive data. A manager is then notified every time the data is accessed so organization’s can track who is accessing sensitive data and when and where the access happens.

If you aren’t sure of your organization’s policy in regards to sensitive data, ask them. If they don’t have a policy in place – inquire about initiating one. This will help to safeguard yourself as well as the data you are in charge of.

Monday, April 12, 2010

NSK Inc Performs Compliance Assessment for Ziner & Murphy, PC

Boston-based IT consulting firm runs assessment of new Massachusetts law on data privacy compliance for CPA firm

Boston, MA, April 12, 2010 – NSK Inc, a leader in IT consulting for small to medium businesses, was contacted by Ziner & Murphy regarding their data storage needs. Ziner & Murphy, a Certified Public Accountant (CPA) firm in Stoneham, MA approached NSK about the new state regulations regarding data privacy. NSK Inc. was hired to perform a Massachusetts Personal Information Compliance Assessment (MPICA).

Changes in Massachusetts General Law (M.G.L.) Chapter 93H, with new regulations 201 CMR 17.00, now require companies that own, license, store, and/or maintain personal information about a resident of the Commonwealth of Massachusetts, to establish minimum standards in guarding the data in both paper and digital records. MPICA is designed to scan a company’s server and system components, locate where personal information is stored, and check to see if the current systems settings are in compliance with the new regulations.

According to David Murphy, the firm learned of the new regulations through the Massachusetts Society of CPAs, and subsequently contacted NSK Inc. “We had worked with NSK in the past, and knew that they are a very knowledgeable and professional firm.” NSK Inc, already prepared for the new regulations, dispatched a technician to perform the assessment for the CPA firm.

An NSK Inc technician installs the MPICA software on a company’s server as well as any desktops or laptops used by office personnel. The software locates where personal information is stored and analyzes whether or not the data is protected according to government standards. MPICA checks password strength and change frequency, current antivirus protection, firewall settings, e-mail and ftp settings, and if the client’s computer systems are updating new releases on a regular basis. NSK Inc can then offer solutions to fix any vulnerabilities found in the system.

Murphy says that being a CPA firm “Our relationship with our clients is based on trust.” Having the MPICA performed, and the system upgraded “We have enhanced this trust with our clients.”

For more information about MPICA, please visit http://www.nskinc.com/it/201CMR17_mpica.html.


About NSK Inc
NSK Inc is a leader in information technology consulting, with a focus on IT management for SMB companies Headquartered in Boston, MA with an additional office in Palo Alto, CA, the company offers a wide array of IT services for business driven information challenges. They provide service and support for small and medium-sized businesses and groups working within large organizations. NSK Inc also creates custom software products for investment banks, equity management organizations, and other specialized industry areas. For more information, please visit http://www.nskinc.com.

Press Contact
For more information, please contact:

Cathie Briggette
NSK Inc.
(p) +1 617 303-0480
(e) cathie@nskinc.com
(w) http://www.nskinc.com

Wednesday, March 17, 2010

NSK Inc IT Associate Receives CCENT Certification

For Immediate Release



NSK Inc IT Associate Receives CCENT Certification


Associate at Boston-based IT Consulting firm is now certified in small network implementation and management


Boston, MA, March 17, 2010 – One of NSK Inc’s IT Associates, Michael McGowan, recently announced that he has received the CCENT™ certification from Cisco®. CCENT, short for Cisco Certified Entry Networking Technician, validates skills in installing and managing small enterprise network systems, and is a stepping stone towards the Cisco Certified Network Associate (CCNA®) certification. McGowan’s new credentials demonstrate his knowledge and experience in data networks, IP addressing, wired and wireless networks, and network security in the small enterprise sector.


McGowan states “It took me about four months to prepare for the exam.” His efforts have paid off immensely. “Having a CCENT certification will help me provide better support with internet/networking, troubleshooting, and configurations for NSK and its clients.” Although time consuming, McGowan says, “The experience was totally worth it, as it is the largest industry-wide certification.” He will spend the next four months working towards his CCNA certification.


McGowan isn’t the only NSK member who is Cisco certified. Ben R. Howard, a Senior IT Associate, holds his CCNA certification. Howard says that “Having the CCNA Security certification ensures that NSK meets the standards set forth by Cisco to have an understanding not only of how to configure a range of Cisco products, but to recognize security issues and how to effectively configure and deploy the devices to address the issues.” NSK Inc is consistently expanding their knowledge base, and with two employees now Cisco certified the company can manage a multitude of network systems for their growing client base.


About Cisco Systems

Cisco, (NASDAQ: CSCO), the worldwide leader in networking that transforms how people connect, communicate and collaborate, this year celebrates 25 years of technology innovation, operational excellence and corporate social responsibility. Information about Cisco can be found at http://www.cisco.com. For ongoing news, please go to http://newsroom.cisco.com.


About NSK Inc

NSK Inc is a leader in information technology consulting, with a focus on IT management for SMB companies. Headquartered in Boston, MA with an additional office in Palo Alto, CA, the company offers a wide array of IT services for business driven information challenges. They provide service and support for small and medium-sized businesses and groups working within large organizations. NSK Inc also creates custom software products for investment banks, equity management organizations, and other specialized industry areas. For more information, please visit www.nskinc.com.


Press Contact


For more information, please contact:

Cathie Briggette

NSK Inc.

(p) +1 617 303-0480

(e) cathie@nskinc.com

Thursday, February 4, 2010

Quick Security Tip


Social Engineering:

I was with a client the other day in a secure room. The client left for lunch, locking me inside the secure room. The door to the secure room contains a glass window that allows any passerby to see inside. An outside vendor comes by and knocks on the door. This immediately brought to mind a common problem.

While this vendor was almost certainly legitimate, my only interaction with this client is with this secure room and the individual who locked me in. I have no idea who this vendor is, or, even if he is the clients legitimate electrician, if he has any business being in this secure room at this particular time. I routinely see UPS/FedEx/USPS hold open doors for people to allow them access into an area in which they have no business, but the delivery person has no idea and, true to the intent of social engineering, allows the person in.

In my case, I walked up to the door and advised the external vendor that I did not have the authority to allow him access to this area. He was furious and began yelling. This reminded me that social engineering is not just walking into a building looking as if you belong. Social engineering can include being quite unpleasant.

If a person exclaims loudly enough that he belongs, perhaps someone will be more apt to open the door. It’s odd to me how people innately understand the problem of social engineering when they’re at home, but quickly forget it at work.

To put this situation in the light of a personal situation, imagine you are visiting a friend at his home. He trusts you, so when he has to run a quick errand, he leaves you at his house and locks the door. Moments later, the cable guy shows up and demands entrance to install a new cable hookup. You would almost instinctively refuse entrance, and if he became loud and obnoxious, you may even call the police. Why would you act differently at work?

-Ben.

Ben Howard is a Sr. IT Consultant with NSK Inc

NSK Inc.
75 Kneeland St., Suite 201
Boston, MA 02111
617-303-0480

Thursday, January 14, 2010

Give in a Crisis.... But be wary who you are giving to



















There is an emerging humanitarian crisis in Haiti, currently the front page story on every major new website.

This is a quick security reminder due to the timeliness of the issue. The e-mail I received above is actually legitimate, but this is the same e-mail I would expect a scam-artist to use, just using the hyper-links and shortened URLs to point to illegitimate sites.

Quick security tip:

Be particularly wary of scam artists trying to profit from human nature. When catastrophy strikes, many people want to help and will often be too eager to send their money to bother checking where the money is actually going. Be wary of e-mails soliciting help and more wary still when the URLs are shortened. Don't be discouraged from donating, just make sure you go directly to the site to which you wish to give your time and money. If you want to donate through the Red Cross, go directly to www.redcross.org, or to the charity or benefit of your choosing.

Monday, July 27, 2009

Compliance for 201 CMR 17.00 is going to take a little time... We have written out a Guideline for your Timeline!

201 CMR 17.00: Standards for the Protection of Personal information of Residents of the Commonwealth of Massachusetts

"This regulation implements the provisions of M.G.L. c. 93H relative to the standards to be met by persons who own, license, store or maintain personal information about a resident of the Commonwealth of Massachusetts." (Purpose MGL c 93H)


August
Designate an Information Security Officer - You will need to designate at least 1 person at your place of business who will maintain the comprehensive information security program. Finding that person now, will help get the rest of the items in line for when they need to be done. You can get a compliance checklist at: 201 CMR 17.00 Compliance Checklist


September


Start Assessing Your Information:

  1. Identify the paper, electronic and other type records, including storage media, laptops and portable devices that contain personal information.**

  2. Check all anti-virus and security patches on all computer systems and servers -- make sure they are up to date.**
    a. Check that you have reasonably up-to-date versions of system security agent software (including malware protection)**

  3. Identify what "personal information" moves around your business and out of your office including:**

    a. healthcare/insurance information

    b. benefits/401K information

    c. Accounting/Tax information

    d. Employment and Credit Applications

    e. Checks and credit card information

  4. Identify persons who need to see the "personal information" and those who do not.

  5. Identify where encryption for personal information is needed.**

  6. Identify what third-party service providers your business may use that have access to personal information.

  7. Identify reasonably foreseeable internal and external risks to paper and electronic records containing personal information.**

  8. Identify any systems that are connected to the Internet and make sure the firewall protection for files containing personal information are up-to-date.**


October

Purchase any hardware or software upgrades that are needed**

  • Get control of user IDS and other identifiers**

  • Come up with a reasonably secure method of assigning/selecting passwords for users**

  • Start developing your WISP (Written Information Security Program) making sure that you include:

    a. Administrative, technical and physical safeguards for Personal information protection

    b. Make sure that your WISP is applicable to all records containing personal information
    about a resident of the Commonwealth of Massachusetts

    c. Any identified and reasonably foreseeable internal and external risks to paper and electronic records

    d. Regular and ongoing employee training, and procedures for monitoring employee compliance

    e. Disciplinary measures for violators

    f. Policies and procedures for when and how records containing personal information should be kept, accessed or transported off your business premises

    g. Processes for blocking terminated employees physical and electronic access to personal information, including deactivating their passwords and user names

    h. Steps taken to verify third party service providers access

    i. The length of time that you are storing records containing personal information.

    j. Specifically the manner in which physical access to personal information records is to be restricted

    k. Whether you are storing your records and data in locked facilities, storage areas or containers and the security measures taken to keep these areas secure

    l. Actions and documenting that is taken in connection with any breach of security

  • November


    1. Install all hardware and software upgrades**

    2. Test policies that have been written

    3. Start Training Employees on new policies

    4. Finalize WISP


    December


    1. Finish Training Employees
    2. Send out WISP Policy to all Employees and get signatures from all, verifying they understand and will comply

    January 1, 2010 and beyond




    1. Continue monitoring your systems and procedures**

    2. Continue providing training to new and existing employees

    3. Update policies as required

    4. Assure all computers and servers remain up-to-date with patches and anti-virus software**

    **There are many intricate requirements and rules involved with this law that have left many companies in Massachusetts with questions. NSK Inc. has formed a knowledgeable team to better assist with clarifying this law. If you have questions please fill out this form or contact:Danielle Carroll at 617.303.0480

    Thursday, July 23, 2009

    Massachusetts Businesses: Are you in Compliance?

    DO NOT WAIT ANY LONGER. MARCH 1, 2010 WILL BE HERE BEFORE YOU KNOW IT!

    Do you have all the information you need to become compliant with the new Massachusetts Regulation 201 CMR 17.00?

    This regulation is inherent to Massachusetts General Law 93H (MGL 93H). This law was written to define the security breaches and regulations for safeguarding the personal information of any Commonwealth of Massachusetts resident. This regulation implements the provisions of the law and describes what you need to have in place in your company in order to be compliant.

    Why was 93H Created? Why 201 CMR 17.00


    The Department of Consumer Affairs and Business Regluations issued this law and these regulations in response to the following data breaches occurred: ·TJ Max (TJX ) January 17, 2007 -Affected about 100 million account numbers Hacked several different ways - through wireless connections and kiosks ·Hannaford Supermarkets - between Dec. 7, 2007 and Mar 10, 2008 -More than 4 million card numbers were exposed, and by the time Hannaford publicly announced the breach, on March 17, 2008, about 1,800 fraudulent charges had been made. ·Other Security Threats
    -Malware, viruses In response, M.G.L. c 93H was enacted in November, 2007. Within the first 10 months after enactment of M.G.L. c 93H, the office of Consumer Affairs and Business Regulation received 318 notifications of security breaches.

    • 10 involved data that was encrypted
    • 69 involved data that was password protected
    • Total MA residents affected was 625,365

    60% were due to stolen laptops or hard-drives and 40% were employee error or sloppy internal handling.
    75% were in the financial services sector.

    Massachusetts then took the lead in passing a new regulation -- 201 CMR 17.00 -- that required companies to implement a comprehensive data security plan that incuded encryption of all computer systems with personal information of a Massachusetts resident.

    What Does This Mean to Your Business

    It means that the Commonwealth of Massachusetts is setting minimum starndards for the protection of personal information, whether that information is stored in electronic or paper format. It means that if your company owns, licenses, stores or maintains personal information about a Massachusetts resident You MUST take steps to comply with this new regulation.

    What is Personal Information

    According to 201 CRM 17.00, personal information is defined as the First Name or First Initial, Last Name and any one or more of the following information:Social Security Number Credit Card or Debit Card Number State ID Card Bank or Financial Account Number Drivers Licence Number If you accept credit cards, you have the imprint of the card or the data from the magnetic strip.. This information falls in the above catagory. You MUST take steps to comply. If you are a business located in Massachusetts or you have employees who reside in Massachusetts and you have copies of driver's licences', employment applications, personnell files or payroll information on those employees You MUST take steps to comply.


    What Do You Need To Do?

    Establish and Maintain a security program to all who have access to personal information with the following Elements:

    Computer System Security Requirements **

    1. Control of user IDs and passwords
    2. Secure method of assigning and selecting passwords
    3. Assign unique identifications plus passwords which are not default passwords
    4. Block access after multiple unsuccessful attempts to computers and servers holding the personal information
    5. Restrict access to inactive accounts
    6. Restrict access to files, to those that need acces to perform their job duties


    Transmission of Personal Information**

    1. Encryption of all transmitted rocords and files containing personal information that travels across public networks
    2. Encryption of all wireless networks


    Encryption of portable devices**

    1. Personal information stored on laptops and other portable devices must be encrypted

    Staying Up-To-Date**

    Make sure all computer and servers that hold personal information stay up to date on:

    1. Operating system patches
    2. Firewall software
    3. Antivirus software set to receive most current updates on a regular basis
    4. Antivirus software must include malware protection


    Training and Monitoring

    1. Education and training of employees on the proper use of the computer security system and the importance of personal information security
    2. Reasonable monitoring of systems for unauthorized use or access to personal information


    Written Information Security Program (WISP)

    1. Designate 1 or more persons to maintain the program
    2. Identify risks and evaluate safegaurds
    3. Develop security posicies for employees that work outside the office
    4. Impose disciplinary measures for program violations
    5. Prevent terminated employees from accessing personal information
    6. Make sure that third-party service providers have an information Security program that is compliant
    7. Limit the amount of personal information collected, the time it is retained and access to it
    8. Identify system used to store personal information
    9. Restrict physical access to records
    10. Regularly monitor the program once it is in place
    11. Review the scope of security measures at least annually or when there is a change in business practices
    12. Document responsive actions taken in a security breach incident

    **There are many intricate requirements and rules involved with this law that have left many companies in Massachusetts with questions. NSK Inc. has formed a knowledgeable team to better assist with clarifying this law. If you have questions please fill out this form or contact:
    Danielle Carroll at 617.303.0480

    Tuesday, June 30, 2009

    Data Loss Prevention and Data Backup


    It is not a good day at work for you when you realize you have lost an important document that you worked on for hours, or when you realize your hard drive has been completely wiped out. The importance of data backup may seem a bit repetitive at this point, but it does take more effort to replace the data once it is gone than it takes to back it up.

    First off, you should have a backup schedule. You should also think about how you’re going to implement it. Will you hire someone to do continuous backup for you? Maybe you’ll just use backup tapes. Backup tapes may seem like a perfectly fine idea to you, but you need to keep in mind that if a disaster strikes on site, no electronic device will save your data unless it is in a remote location.

    Continuous backup is a process by which your data is constantly backed up by frequent ‘snapshots.’ Remote backup is a process by which your data is maintained off site without having to manually transport your data. Manual transportation has proven time and again to be an unsafe measure. You may want to consider continuous remote data backup for your company to ensure the best security of your information.

    Other measures to take include keeping your computers in cool, dry, areas that are free of dust. Use a generator – if there’s ever a power outage, you want your computer to stay on so that data doesn’t disappear because you didn’t get the chance to save it. In addition, antivirus software is essential for keeping your computer’s system healthy and decreasing your risk of losing data.

    Written by Melissa Cocks

    Thursday, June 18, 2009

    Preventing Computer Viruses

    Far too many company and household computers become infected with viruses annually, and the affects of these infections can be devastating to the user. Since there are so many ways a virus can enter your computer’s system, it’s important that you know how to block off those entrances. Here are several ways to decrease the chances of your computer becoming infected:

    -Don’t solely rely on anti-virus software, although you should have it installed. Be sure to update often to detect and protect your computer from the most recently created viruses.
    (It also doesn't hurt to install a spyware, malware, and adware removal application)
    -Read the headlines. Stay on top of the news to educate yourself about new viruses.
    -Try not to open an e-mail attachment until you are sure it is safe. Make sure you know the person or why it may be sent to you.
    -Once again, surf the web for news about viruses so you know common subject lines and file extensions relative to those viruses.
    -Disable automatic attachment viewing in your e-mail settings.
    -Set your Word and Excel settings so that Macros are disabled when a file is opened up for viewing.
    - Use search engines that are well-known for generating results relevant to search terms. A site is probably safe if a lot of people have linked to it, but keep in mind that this isn’t always the case. This way, your chances of being directed to a site that hosts a virus is less likely.
    -Make sure you set your security settings to ‘high’ in your web browser.
    -Try to avoid downloading free applications from unverifiable websites.
    -Configure your settings so that you can always view file extensions.

    The following are examples of file extensions to be suspicious of when they show up in e-mail:

    ADE, ADP, BAS, BAT, CHM, CMD, COM, CPL, CRT, DLL, EXE, HLP, HTA, INF, INS, ISP, JS, JSE, LNK, MDB, MDE, MSC, MSI, MSP, MST, OCX, PCD, PIF, POT, REG, SCR, SCT, SHB, SHS, SYS, URL, VB, VBE, VBS, WSC, WSF, WSH

    It is easy to tell yourself you will regularly take these measures to maintain your computer security and implement virus protection, but it is also quite easy to forget. This is often how viruses end up finding their way into your computer.

    Written by Melissa Cocks

    Tuesday, May 26, 2009

    NSK Offers MPICA for Compliance with MA Law


    MPICA (Massachusetts Personal Information Compliance Assessment) is an IT support service that NSK Inc is offering to businesses that need to comply with the Massachusetts General Law Chapter 93H and its new regulations 201 CMR 17.00. The law requires that any companies who own, license, store, and/or maintain personal information about a Massachusetts resident make adjustments to further protect personal information. Both electronic and paper records will need to comply with the new law. The regulations go into effect on January 1, 2010. The law was originally supposed to go into effect on January 1, 2009, but then was pushed to May 1 and then January 1, 2010 due to the state of the economy, time restraints, and confusion about the law.

    MPICA offers IT help to companies who are having difficulty making changes in their systems to adjust to this law. Identity theft and fraud are the major concerns at the core of the implementation of the 201 CMR 17.00, so it is important that the necessary changes are made within business IT systems. If a Massachusetts resident's information is leaked or captured, there could be serious consequences for the business that allowed the breach and for the individual whose information was leaked. Therefore, making changes to keep residents' information secure will be required to avoiding security breach and fines.

    Companies will need a written security plan to safeguard their contacts' and/or employees personal information. It will need to be illustrative of policies that demonstrate technical, physical, and administrative protection for residents’ information. The plan needs to be written to meet industry standards. Companies will have to designate employees to oversee and manage security procedures in the workplace, as well as continuously monitor and address security hazards. Policies addressing employee access to and transportation of personal information will need to be developed, as well as disciplinary measures for employees who do not conform to the new regulations. Limiting the collection of data to the minimum that is needed for the purpose it will be used for is also part of the new regulations.

    Since revisiting workplace data security procedures requires in-depth changes, this is a lengthy process. It takes months for businesses to make the necessary changes required by this law, so businesses might consider starting early at contacting an IT consulting firm and seeking its IT support.

    Written by Melissa Cocks

    Friday, January 16, 2009

    Massachusetts Consumer Protection Law

    ARE YOU IN COMPLIANCE?

    Does your company store and/or maintain personal information about a resident of Massachusetts? Do you have client databases, direct deposit records, payroll files, 401K information, employee records files or a QuickBooks company database? If so you need to be aware of this new regulation.

    The new Massachusetts General Law (M.G.L.) Chapter 93H requires that companies that own, license, store or maintain personal information about a resident of the Commonwealth of Massachusetts establish minimum standards in safeguarding the personal information contained in both paper and electronic records. This new law’s further purpose is to:

    Ensure security and confidentiality of information consistent with industry standards;
    Protect against anticipated threats or hazards to the security or integrity of information;
    Protect against unauthorized access to or use of such information


    NSK Inc., along with Burns & Levinson are hosting a Free Seminar at the Omni Parker House Hotel, 50 School St., Boston, MA on February 24th, 2009, explaining:

    The law and how it relates to you and your company.
    The implications of the law
    How to assess your information technology environment and make it comply with the new regulations.

    There will be three (3) 1 hour sessions during the day. For more information and to sign up please call us at 617-303-0480 X 224 and we will sign you up.

    Monday, January 5, 2009

    New Data Security Law - Massachusetts – Personal Information Compliance Assessment

    75 Kneeland Street, Suite 201, Boston, MA 02211
    Tel: 617.303.0480
    Fax: 617.303.0481

    Are you aware of the new Massachusetts General Law (M.G.L.) Chapter 93H?
    (201 CMR 17.00: M.G.L. c. 93H)
    201 CMR 17.00: Standards for the Protection of Personal information of Residents of the Commonwealth.
    This regulation implements the provisions of M.G.L. c. 93H relative to the standards to be met by persons who own, license, store or maintain personal information about a resident of the
    Commonwealth of Massachusetts. This regulation establishes minimum standards to be met in
    connection with the safeguarding of personal information contained in both paper and electronic records. Further purposes are to (i) ensure the security and confidentiality of such information in a manner consistent with industry standards, (ii) protect against anticipated threats or hazards to the security or integrity of such information, and (iii) protect against unauthorized access to or use of such information


    We have a new program that will handle your company's Personal Information that is covered under the electronic records of this new law.

    The New Program is Called:
    M-PICA (Massachusetts - Personal Information Compliance Assessment)

    Every person that owns, licenses, stores or maintains personal information about a resident of the Commonwealth and electronically stores or transmits such information shall include in its written, comprehensive information security program the establishment and maintenance of a security system covering its computers, including any wireless system, that, at a minimum, shall have the following elements:

    Secure user authentication protocols including:
    1. Control of user IDs and other identifiers;

    2. A reasonably secure method of assigning and selecting passwords, or use of unique identifier technologies, such as biometrics or token devices;

    3. Control of data security passwords to ensure that such passwords are kept in a location and/or format that does not compromise the security of the data they protect;

    4. Restricting access to active users and active user accounts only;

    5. Blocking access to user identification after multiple unsuccessful attempts to gain access or the limitation placed on access for the particular system;

    Secure access control measures that:
    1. Restrict access to records and files containing personal information to those who need such information to perform their job duties;
    2. Assign unique identifications plus passwords, which are not vendor supplied default passwords, to each person with computer access, that are reasonably designed to maintain the integrity of the security of the access controls;
    3. To the extent technically feasible, encryption of all transmitted records and files containing personal information that will travel across public networks, and encryption of all data to be transmitted wirelessly.

    4. Reasonable monitoring of systems, for unauthorized use of or access to personal information;

    5. Encryption of all personal information stored on laptops or other portable devices;

    6. For files containing personal information on a system that is connected to the Internet, there must be reasonably up-to-date firewall protection and operating system security patches, reasonably designed to maintain the integrity of the personal information.

    7. Reasonably up-to-date versions of system security agent software which must include malware protection and reasonably up-to-date patches and virus definitions, or a version of such software that can still be supported with up-to-date patches and virus definitions, and is set to receive the most current security updates on a regular basis.

    8. Education and training of employees on the proper use of the computer security system and the importance of personal information security.


    17.05: Effective Date
    These regulations shall take effect on May 1, 2009.