Showing posts with label data security policy. Show all posts
Showing posts with label data security policy. Show all posts

Wednesday, November 25, 2009

Final Version of MGL 93H 201CMR 17.00 Filed

OCABR (Massachusetts Office of Consumer Affairs and Business Regulation) on October 29th, 2009 filed the "Final" version of the "Standards for the Protection of Personal Information" also know as MGL 93H 201 CMR 17.00 with the Secretary of State's office. The first issue was in September of 2008, and after more than a year of amendments to the original regulations this is the final step before the regulation takes effect on March 1, 2010. The final regulations include some further clarifications than the amendment that was released in August of this year, but are substantially similar.


The latest revisions were written in response to requests from companies and business leaders that were looking for further clarification of the regulation.


Following are the changes:


17.02 Definitions
Owns or licenses - adds the word "stores"
Service provider - adds the word "stores" and deletes the phrase provided, however that "Service provider" shall not include the U.S. Postal Service.

17.03 Duty to Protect and Standards for Protecting Personal information


Clarifies the language in section (2)(f)(2) relating to service provider contracts - A contract entered into with a third party service provider is deemed to be in compliance with this section until March 1, 2012, even if the contract does not include a requirement that the third party service provider maintain such appropriate safeguards, as long as the contract was entered into no later than March 1, 2010


"Definition of Owns or Licenses. A company owns or licenses personal information if it "receives, stores, maintains, processes, or otherwise has access to personal information in connection with the provision of goods or services or in connection with employment." The final regulations make clear for the first time that a company that "stores" the personal information of a Massachusetts resident is subject to the regulations' requirements, even if the company does not otherwise process or access such information.


Definition of Service Providers. A service provider is defined as "any person that receives, stores, maintains, processes, or otherwise is permitted access to personal information through its provision of services directly to a person that is subject to this regulation." The final regulations eliminate a previous carve-out that had stated, "‘service provider' shall not include the U.S. Postal Service." It is not clear that the OCABR intends this change to mean that a company using the U.S. Postal Service to transmit personal information must contractually require the U.S. Postal Service to implement and maintain appropriate security measures for such personal information, as it must do with other service providers. But the OCABR has stated that a company must assess the risks of using a common carrier, including the U.S. Postal Service, to transmit personal information and take steps to protect that personal information.


Amending Existing Contracts with Service Providers. The final regulations clarify prior language related to a grace period for amending existing contracts with service providers so that such contracts require the service providers to implement and maintain appropriate security measures for personal information. The regulations now make clear that a company has until March 1, 2012 to amend existing contracts with service providers to include personal information security provisions, as long as the existing contracts were entered into before March 1, 2010. As before, service-provider contracts that the company entered into after March 1, 2010, must include personal information security provisions." [1]


For a copy of the most up to date Regulation please click here.


MPICA - Massachusetts Personal Information Compliance Assessment


[1] David M. McIntosh, Lisa M. Ropple Christine Santariga - Ropes & Gray LLP Boston Office

Monday, July 27, 2009

Compliance for 201 CMR 17.00 is going to take a little time... We have written out a Guideline for your Timeline!

201 CMR 17.00: Standards for the Protection of Personal information of Residents of the Commonwealth of Massachusetts

"This regulation implements the provisions of M.G.L. c. 93H relative to the standards to be met by persons who own, license, store or maintain personal information about a resident of the Commonwealth of Massachusetts." (Purpose MGL c 93H)


August
Designate an Information Security Officer - You will need to designate at least 1 person at your place of business who will maintain the comprehensive information security program. Finding that person now, will help get the rest of the items in line for when they need to be done. You can get a compliance checklist at: 201 CMR 17.00 Compliance Checklist


September


Start Assessing Your Information:

  1. Identify the paper, electronic and other type records, including storage media, laptops and portable devices that contain personal information.**

  2. Check all anti-virus and security patches on all computer systems and servers -- make sure they are up to date.**
    a. Check that you have reasonably up-to-date versions of system security agent software (including malware protection)**

  3. Identify what "personal information" moves around your business and out of your office including:**

    a. healthcare/insurance information

    b. benefits/401K information

    c. Accounting/Tax information

    d. Employment and Credit Applications

    e. Checks and credit card information

  4. Identify persons who need to see the "personal information" and those who do not.

  5. Identify where encryption for personal information is needed.**

  6. Identify what third-party service providers your business may use that have access to personal information.

  7. Identify reasonably foreseeable internal and external risks to paper and electronic records containing personal information.**

  8. Identify any systems that are connected to the Internet and make sure the firewall protection for files containing personal information are up-to-date.**


October

Purchase any hardware or software upgrades that are needed**

  • Get control of user IDS and other identifiers**

  • Come up with a reasonably secure method of assigning/selecting passwords for users**

  • Start developing your WISP (Written Information Security Program) making sure that you include:

    a. Administrative, technical and physical safeguards for Personal information protection

    b. Make sure that your WISP is applicable to all records containing personal information
    about a resident of the Commonwealth of Massachusetts

    c. Any identified and reasonably foreseeable internal and external risks to paper and electronic records

    d. Regular and ongoing employee training, and procedures for monitoring employee compliance

    e. Disciplinary measures for violators

    f. Policies and procedures for when and how records containing personal information should be kept, accessed or transported off your business premises

    g. Processes for blocking terminated employees physical and electronic access to personal information, including deactivating their passwords and user names

    h. Steps taken to verify third party service providers access

    i. The length of time that you are storing records containing personal information.

    j. Specifically the manner in which physical access to personal information records is to be restricted

    k. Whether you are storing your records and data in locked facilities, storage areas or containers and the security measures taken to keep these areas secure

    l. Actions and documenting that is taken in connection with any breach of security

  • November


    1. Install all hardware and software upgrades**

    2. Test policies that have been written

    3. Start Training Employees on new policies

    4. Finalize WISP


    December


    1. Finish Training Employees
    2. Send out WISP Policy to all Employees and get signatures from all, verifying they understand and will comply

    January 1, 2010 and beyond




    1. Continue monitoring your systems and procedures**

    2. Continue providing training to new and existing employees

    3. Update policies as required

    4. Assure all computers and servers remain up-to-date with patches and anti-virus software**

    **There are many intricate requirements and rules involved with this law that have left many companies in Massachusetts with questions. NSK Inc. has formed a knowledgeable team to better assist with clarifying this law. If you have questions please fill out this form or contact:Danielle Carroll at 617.303.0480

    Thursday, July 23, 2009

    Massachusetts Businesses: Are you in Compliance?

    DO NOT WAIT ANY LONGER. MARCH 1, 2010 WILL BE HERE BEFORE YOU KNOW IT!

    Do you have all the information you need to become compliant with the new Massachusetts Regulation 201 CMR 17.00?

    This regulation is inherent to Massachusetts General Law 93H (MGL 93H). This law was written to define the security breaches and regulations for safeguarding the personal information of any Commonwealth of Massachusetts resident. This regulation implements the provisions of the law and describes what you need to have in place in your company in order to be compliant.

    Why was 93H Created? Why 201 CMR 17.00


    The Department of Consumer Affairs and Business Regluations issued this law and these regulations in response to the following data breaches occurred: ·TJ Max (TJX ) January 17, 2007 -Affected about 100 million account numbers Hacked several different ways - through wireless connections and kiosks ·Hannaford Supermarkets - between Dec. 7, 2007 and Mar 10, 2008 -More than 4 million card numbers were exposed, and by the time Hannaford publicly announced the breach, on March 17, 2008, about 1,800 fraudulent charges had been made. ·Other Security Threats
    -Malware, viruses In response, M.G.L. c 93H was enacted in November, 2007. Within the first 10 months after enactment of M.G.L. c 93H, the office of Consumer Affairs and Business Regulation received 318 notifications of security breaches.

    • 10 involved data that was encrypted
    • 69 involved data that was password protected
    • Total MA residents affected was 625,365

    60% were due to stolen laptops or hard-drives and 40% were employee error or sloppy internal handling.
    75% were in the financial services sector.

    Massachusetts then took the lead in passing a new regulation -- 201 CMR 17.00 -- that required companies to implement a comprehensive data security plan that incuded encryption of all computer systems with personal information of a Massachusetts resident.

    What Does This Mean to Your Business

    It means that the Commonwealth of Massachusetts is setting minimum starndards for the protection of personal information, whether that information is stored in electronic or paper format. It means that if your company owns, licenses, stores or maintains personal information about a Massachusetts resident You MUST take steps to comply with this new regulation.

    What is Personal Information

    According to 201 CRM 17.00, personal information is defined as the First Name or First Initial, Last Name and any one or more of the following information:Social Security Number Credit Card or Debit Card Number State ID Card Bank or Financial Account Number Drivers Licence Number If you accept credit cards, you have the imprint of the card or the data from the magnetic strip.. This information falls in the above catagory. You MUST take steps to comply. If you are a business located in Massachusetts or you have employees who reside in Massachusetts and you have copies of driver's licences', employment applications, personnell files or payroll information on those employees You MUST take steps to comply.


    What Do You Need To Do?

    Establish and Maintain a security program to all who have access to personal information with the following Elements:

    Computer System Security Requirements **

    1. Control of user IDs and passwords
    2. Secure method of assigning and selecting passwords
    3. Assign unique identifications plus passwords which are not default passwords
    4. Block access after multiple unsuccessful attempts to computers and servers holding the personal information
    5. Restrict access to inactive accounts
    6. Restrict access to files, to those that need acces to perform their job duties


    Transmission of Personal Information**

    1. Encryption of all transmitted rocords and files containing personal information that travels across public networks
    2. Encryption of all wireless networks


    Encryption of portable devices**

    1. Personal information stored on laptops and other portable devices must be encrypted

    Staying Up-To-Date**

    Make sure all computer and servers that hold personal information stay up to date on:

    1. Operating system patches
    2. Firewall software
    3. Antivirus software set to receive most current updates on a regular basis
    4. Antivirus software must include malware protection


    Training and Monitoring

    1. Education and training of employees on the proper use of the computer security system and the importance of personal information security
    2. Reasonable monitoring of systems for unauthorized use or access to personal information


    Written Information Security Program (WISP)

    1. Designate 1 or more persons to maintain the program
    2. Identify risks and evaluate safegaurds
    3. Develop security posicies for employees that work outside the office
    4. Impose disciplinary measures for program violations
    5. Prevent terminated employees from accessing personal information
    6. Make sure that third-party service providers have an information Security program that is compliant
    7. Limit the amount of personal information collected, the time it is retained and access to it
    8. Identify system used to store personal information
    9. Restrict physical access to records
    10. Regularly monitor the program once it is in place
    11. Review the scope of security measures at least annually or when there is a change in business practices
    12. Document responsive actions taken in a security breach incident

    **There are many intricate requirements and rules involved with this law that have left many companies in Massachusetts with questions. NSK Inc. has formed a knowledgeable team to better assist with clarifying this law. If you have questions please fill out this form or contact:
    Danielle Carroll at 617.303.0480

    Tuesday, May 26, 2009

    NSK Offers MPICA for Compliance with MA Law


    MPICA (Massachusetts Personal Information Compliance Assessment) is an IT support service that NSK Inc is offering to businesses that need to comply with the Massachusetts General Law Chapter 93H and its new regulations 201 CMR 17.00. The law requires that any companies who own, license, store, and/or maintain personal information about a Massachusetts resident make adjustments to further protect personal information. Both electronic and paper records will need to comply with the new law. The regulations go into effect on January 1, 2010. The law was originally supposed to go into effect on January 1, 2009, but then was pushed to May 1 and then January 1, 2010 due to the state of the economy, time restraints, and confusion about the law.

    MPICA offers IT help to companies who are having difficulty making changes in their systems to adjust to this law. Identity theft and fraud are the major concerns at the core of the implementation of the 201 CMR 17.00, so it is important that the necessary changes are made within business IT systems. If a Massachusetts resident's information is leaked or captured, there could be serious consequences for the business that allowed the breach and for the individual whose information was leaked. Therefore, making changes to keep residents' information secure will be required to avoiding security breach and fines.

    Companies will need a written security plan to safeguard their contacts' and/or employees personal information. It will need to be illustrative of policies that demonstrate technical, physical, and administrative protection for residents’ information. The plan needs to be written to meet industry standards. Companies will have to designate employees to oversee and manage security procedures in the workplace, as well as continuously monitor and address security hazards. Policies addressing employee access to and transportation of personal information will need to be developed, as well as disciplinary measures for employees who do not conform to the new regulations. Limiting the collection of data to the minimum that is needed for the purpose it will be used for is also part of the new regulations.

    Since revisiting workplace data security procedures requires in-depth changes, this is a lengthy process. It takes months for businesses to make the necessary changes required by this law, so businesses might consider starting early at contacting an IT consulting firm and seeking its IT support.

    Written by Melissa Cocks