Showing posts with label security policies. Show all posts
Showing posts with label security policies. Show all posts

Thursday, March 4, 2010

NSK Inc Associate Getting CISSP Certified!

Ben. R Howard, a Senior IT Associate at NSK Inc recently took the CISSP Certification Exam and passed, placing him among roughly 64,000 other IT professionals in the world who have the certification.

The CISSP (Certified Information Systems Security Professional) is a highly prestigious certification that requires a massive amount of training and credentials in order to be considered to even take the exam.

CISSP candidates must have at least five years of experience in information security as well as experience with two of ten domains of security before they even apply. They then have to train and prepare for a sixty page exam that lasts for six-hours.

Those who pass receive the certification. A CISSP Certified Associate knows how to formally manage an all encompassing security program. The CISSP credential is a testament to the years of experience, knowledge, and competency of information systems, these personnel have achieved.

Howard hopes to broaden NSK’s ability to provide security services to its clients with his new certification. Having a CISSP Certified IT Associate, will only help NSK Inc move forward as a premier consulting firm in Boston.

Thursday, July 23, 2009

Massachusetts Businesses: Are you in Compliance?

DO NOT WAIT ANY LONGER. MARCH 1, 2010 WILL BE HERE BEFORE YOU KNOW IT!

Do you have all the information you need to become compliant with the new Massachusetts Regulation 201 CMR 17.00?

This regulation is inherent to Massachusetts General Law 93H (MGL 93H). This law was written to define the security breaches and regulations for safeguarding the personal information of any Commonwealth of Massachusetts resident. This regulation implements the provisions of the law and describes what you need to have in place in your company in order to be compliant.

Why was 93H Created? Why 201 CMR 17.00


The Department of Consumer Affairs and Business Regluations issued this law and these regulations in response to the following data breaches occurred: ·TJ Max (TJX ) January 17, 2007 -Affected about 100 million account numbers Hacked several different ways - through wireless connections and kiosks ·Hannaford Supermarkets - between Dec. 7, 2007 and Mar 10, 2008 -More than 4 million card numbers were exposed, and by the time Hannaford publicly announced the breach, on March 17, 2008, about 1,800 fraudulent charges had been made. ·Other Security Threats
-Malware, viruses In response, M.G.L. c 93H was enacted in November, 2007. Within the first 10 months after enactment of M.G.L. c 93H, the office of Consumer Affairs and Business Regulation received 318 notifications of security breaches.

  • 10 involved data that was encrypted
  • 69 involved data that was password protected
  • Total MA residents affected was 625,365

60% were due to stolen laptops or hard-drives and 40% were employee error or sloppy internal handling.
75% were in the financial services sector.

Massachusetts then took the lead in passing a new regulation -- 201 CMR 17.00 -- that required companies to implement a comprehensive data security plan that incuded encryption of all computer systems with personal information of a Massachusetts resident.

What Does This Mean to Your Business

It means that the Commonwealth of Massachusetts is setting minimum starndards for the protection of personal information, whether that information is stored in electronic or paper format. It means that if your company owns, licenses, stores or maintains personal information about a Massachusetts resident You MUST take steps to comply with this new regulation.

What is Personal Information

According to 201 CRM 17.00, personal information is defined as the First Name or First Initial, Last Name and any one or more of the following information:Social Security Number Credit Card or Debit Card Number State ID Card Bank or Financial Account Number Drivers Licence Number If you accept credit cards, you have the imprint of the card or the data from the magnetic strip.. This information falls in the above catagory. You MUST take steps to comply. If you are a business located in Massachusetts or you have employees who reside in Massachusetts and you have copies of driver's licences', employment applications, personnell files or payroll information on those employees You MUST take steps to comply.


What Do You Need To Do?

Establish and Maintain a security program to all who have access to personal information with the following Elements:

Computer System Security Requirements **

  1. Control of user IDs and passwords
  2. Secure method of assigning and selecting passwords
  3. Assign unique identifications plus passwords which are not default passwords
  4. Block access after multiple unsuccessful attempts to computers and servers holding the personal information
  5. Restrict access to inactive accounts
  6. Restrict access to files, to those that need acces to perform their job duties


Transmission of Personal Information**

  1. Encryption of all transmitted rocords and files containing personal information that travels across public networks
  2. Encryption of all wireless networks


Encryption of portable devices**

  1. Personal information stored on laptops and other portable devices must be encrypted

Staying Up-To-Date**

Make sure all computer and servers that hold personal information stay up to date on:

  1. Operating system patches
  2. Firewall software
  3. Antivirus software set to receive most current updates on a regular basis
  4. Antivirus software must include malware protection


Training and Monitoring

  1. Education and training of employees on the proper use of the computer security system and the importance of personal information security
  2. Reasonable monitoring of systems for unauthorized use or access to personal information


Written Information Security Program (WISP)

  1. Designate 1 or more persons to maintain the program
  2. Identify risks and evaluate safegaurds
  3. Develop security posicies for employees that work outside the office
  4. Impose disciplinary measures for program violations
  5. Prevent terminated employees from accessing personal information
  6. Make sure that third-party service providers have an information Security program that is compliant
  7. Limit the amount of personal information collected, the time it is retained and access to it
  8. Identify system used to store personal information
  9. Restrict physical access to records
  10. Regularly monitor the program once it is in place
  11. Review the scope of security measures at least annually or when there is a change in business practices
  12. Document responsive actions taken in a security breach incident

**There are many intricate requirements and rules involved with this law that have left many companies in Massachusetts with questions. NSK Inc. has formed a knowledgeable team to better assist with clarifying this law. If you have questions please fill out this form or contact:
Danielle Carroll at 617.303.0480

Tuesday, May 26, 2009

NSK Offers MPICA for Compliance with MA Law


MPICA (Massachusetts Personal Information Compliance Assessment) is an IT support service that NSK Inc is offering to businesses that need to comply with the Massachusetts General Law Chapter 93H and its new regulations 201 CMR 17.00. The law requires that any companies who own, license, store, and/or maintain personal information about a Massachusetts resident make adjustments to further protect personal information. Both electronic and paper records will need to comply with the new law. The regulations go into effect on January 1, 2010. The law was originally supposed to go into effect on January 1, 2009, but then was pushed to May 1 and then January 1, 2010 due to the state of the economy, time restraints, and confusion about the law.

MPICA offers IT help to companies who are having difficulty making changes in their systems to adjust to this law. Identity theft and fraud are the major concerns at the core of the implementation of the 201 CMR 17.00, so it is important that the necessary changes are made within business IT systems. If a Massachusetts resident's information is leaked or captured, there could be serious consequences for the business that allowed the breach and for the individual whose information was leaked. Therefore, making changes to keep residents' information secure will be required to avoiding security breach and fines.

Companies will need a written security plan to safeguard their contacts' and/or employees personal information. It will need to be illustrative of policies that demonstrate technical, physical, and administrative protection for residents’ information. The plan needs to be written to meet industry standards. Companies will have to designate employees to oversee and manage security procedures in the workplace, as well as continuously monitor and address security hazards. Policies addressing employee access to and transportation of personal information will need to be developed, as well as disciplinary measures for employees who do not conform to the new regulations. Limiting the collection of data to the minimum that is needed for the purpose it will be used for is also part of the new regulations.

Since revisiting workplace data security procedures requires in-depth changes, this is a lengthy process. It takes months for businesses to make the necessary changes required by this law, so businesses might consider starting early at contacting an IT consulting firm and seeking its IT support.

Written by Melissa Cocks