Showing posts with label cmr 17 compliance. Show all posts
Showing posts with label cmr 17 compliance. Show all posts

Monday, April 12, 2010

NSK Inc Performs Compliance Assessment for Ziner & Murphy, PC

Boston-based IT consulting firm runs assessment of new Massachusetts law on data privacy compliance for CPA firm

Boston, MA, April 12, 2010 – NSK Inc, a leader in IT consulting for small to medium businesses, was contacted by Ziner & Murphy regarding their data storage needs. Ziner & Murphy, a Certified Public Accountant (CPA) firm in Stoneham, MA approached NSK about the new state regulations regarding data privacy. NSK Inc. was hired to perform a Massachusetts Personal Information Compliance Assessment (MPICA).

Changes in Massachusetts General Law (M.G.L.) Chapter 93H, with new regulations 201 CMR 17.00, now require companies that own, license, store, and/or maintain personal information about a resident of the Commonwealth of Massachusetts, to establish minimum standards in guarding the data in both paper and digital records. MPICA is designed to scan a company’s server and system components, locate where personal information is stored, and check to see if the current systems settings are in compliance with the new regulations.

According to David Murphy, the firm learned of the new regulations through the Massachusetts Society of CPAs, and subsequently contacted NSK Inc. “We had worked with NSK in the past, and knew that they are a very knowledgeable and professional firm.” NSK Inc, already prepared for the new regulations, dispatched a technician to perform the assessment for the CPA firm.

An NSK Inc technician installs the MPICA software on a company’s server as well as any desktops or laptops used by office personnel. The software locates where personal information is stored and analyzes whether or not the data is protected according to government standards. MPICA checks password strength and change frequency, current antivirus protection, firewall settings, e-mail and ftp settings, and if the client’s computer systems are updating new releases on a regular basis. NSK Inc can then offer solutions to fix any vulnerabilities found in the system.

Murphy says that being a CPA firm “Our relationship with our clients is based on trust.” Having the MPICA performed, and the system upgraded “We have enhanced this trust with our clients.”

For more information about MPICA, please visit http://www.nskinc.com/it/201CMR17_mpica.html.


About NSK Inc
NSK Inc is a leader in information technology consulting, with a focus on IT management for SMB companies Headquartered in Boston, MA with an additional office in Palo Alto, CA, the company offers a wide array of IT services for business driven information challenges. They provide service and support for small and medium-sized businesses and groups working within large organizations. NSK Inc also creates custom software products for investment banks, equity management organizations, and other specialized industry areas. For more information, please visit http://www.nskinc.com.

Press Contact
For more information, please contact:

Cathie Briggette
NSK Inc.
(p) +1 617 303-0480
(e) cathie@nskinc.com
(w) http://www.nskinc.com

Wednesday, November 25, 2009

Final Version of MGL 93H 201CMR 17.00 Filed

OCABR (Massachusetts Office of Consumer Affairs and Business Regulation) on October 29th, 2009 filed the "Final" version of the "Standards for the Protection of Personal Information" also know as MGL 93H 201 CMR 17.00 with the Secretary of State's office. The first issue was in September of 2008, and after more than a year of amendments to the original regulations this is the final step before the regulation takes effect on March 1, 2010. The final regulations include some further clarifications than the amendment that was released in August of this year, but are substantially similar.


The latest revisions were written in response to requests from companies and business leaders that were looking for further clarification of the regulation.


Following are the changes:


17.02 Definitions
Owns or licenses - adds the word "stores"
Service provider - adds the word "stores" and deletes the phrase provided, however that "Service provider" shall not include the U.S. Postal Service.

17.03 Duty to Protect and Standards for Protecting Personal information


Clarifies the language in section (2)(f)(2) relating to service provider contracts - A contract entered into with a third party service provider is deemed to be in compliance with this section until March 1, 2012, even if the contract does not include a requirement that the third party service provider maintain such appropriate safeguards, as long as the contract was entered into no later than March 1, 2010


"Definition of Owns or Licenses. A company owns or licenses personal information if it "receives, stores, maintains, processes, or otherwise has access to personal information in connection with the provision of goods or services or in connection with employment." The final regulations make clear for the first time that a company that "stores" the personal information of a Massachusetts resident is subject to the regulations' requirements, even if the company does not otherwise process or access such information.


Definition of Service Providers. A service provider is defined as "any person that receives, stores, maintains, processes, or otherwise is permitted access to personal information through its provision of services directly to a person that is subject to this regulation." The final regulations eliminate a previous carve-out that had stated, "‘service provider' shall not include the U.S. Postal Service." It is not clear that the OCABR intends this change to mean that a company using the U.S. Postal Service to transmit personal information must contractually require the U.S. Postal Service to implement and maintain appropriate security measures for such personal information, as it must do with other service providers. But the OCABR has stated that a company must assess the risks of using a common carrier, including the U.S. Postal Service, to transmit personal information and take steps to protect that personal information.


Amending Existing Contracts with Service Providers. The final regulations clarify prior language related to a grace period for amending existing contracts with service providers so that such contracts require the service providers to implement and maintain appropriate security measures for personal information. The regulations now make clear that a company has until March 1, 2012 to amend existing contracts with service providers to include personal information security provisions, as long as the existing contracts were entered into before March 1, 2010. As before, service-provider contracts that the company entered into after March 1, 2010, must include personal information security provisions." [1]


For a copy of the most up to date Regulation please click here.


MPICA - Massachusetts Personal Information Compliance Assessment


[1] David M. McIntosh, Lisa M. Ropple Christine Santariga - Ropes & Gray LLP Boston Office

Thursday, August 6, 2009

201 CMR 17 Compliance Timeline

Compliance for 201 CMR 17.00 is going to take a little time... We have written out a guideline for your timeline!

August

-Designate an Information Security Officer - You will need to designate at least 1 person at your place of business who will maintain the comprehensive information security program. Finding that person now will help get the rest of the items in line for when they need to be done.

September

Start Assessing Your Information:

-Identify the paper, electronic and other type records, including storage media, laptops and portable devices that contain personal information.**
-Check all anti-virus and security patches on all computer systems and servers -- make sure they are up to date.**

a. Check that you have reasonably up-to-date versions of
system security agent software (including malware
protection)**

-Identify what "personal information" moves around your business and out of your office including:**

a. healthcare/insurance information
b. benefits/401K information
c. Accounting/Tax information
d. Employment and Credit Applications
e. Checks and credit card information

-Identify persons who need to see the "personal information" and those who do not.
-Identify where encryption for personal information is needed.**
-Identify what third-party service providers your business may use that have access to personal information.
-Identify reasonably foreseeable internal and external risks to paper and electronic records containing personal information.**
-Identify any systems that are connected to the internet and make sure the firewall protection for files containing personal information are up-to-date.**

October

-Purchase any hardware or software upgrades that are needed**
-Get control of user IDS and other identifiers**
-Come up with a reasonably secure method of assigning/selecting passwords for users**
-Start developing your WISP (Written Information Security Program)
-Make sure that your WISP is applicable to all records containing personal information about a resident of the Commonwealth of Massachusetts

Make sure that you include:

-Administrative, technical and physical safeguards for Personal information protection
-Any identified and reasonably foreseeable internal and external risks to paper and electronic records
-Regular and ongoing employee training, and procedures for monitoring employee compliance
-Disciplinary measures for violators
-Policies and procedures for when and how records containing personal information should be kept, accessed or transported off your business premises
-Processes for blocking terminated employees physical and electronic access to personal information, including deactivating their passwords and user names
-Steps taken to verify third party service providers access
-The length of time that you are storing records containing personal information.
-Specifically the manner in which physical access to personal information records is to be restricted
-Whether you are storing your records and data in locked facilities, storage areas or containers and the security measures taken to keep these areas secure
-Actions and documenting that is taken in connection with any breach of security

November

-Install all hardware and software upgrades**
-Test policies that have been written
-Start Training Employees on new policies
-Finalize WISP

December

-Finish Training Employees
-Send out WISP Policy to all employees and get signatures from all that they understand and will comply

January 1, 2010 and beyond

-Continue monitoring your systems and procedures**
-Continue providing training to new and existing employees
-Update policies as required
-Assure all computers and servers remain up-to-date with patches and anti-virus software**

** NSK Inc can help you with any of these tasks, just let us know.

Written by Cathie Briggette