Showing posts with label security policy. Show all posts
Showing posts with label security policy. Show all posts

Friday, July 23, 2010

Legal Advice For IT Professionals

Even though it may be your job to handle sensitive information, how you handle the data is just as important as how well it is secured.

One of the best ways to avoid any sort of legal snafu is to have a privacy policy in place. The policy needs to be all encompassing, meaning it covers EVERYTHING accessed on the company’s network (i.e. email, network drives, Twitter, Facebook, VPN connections from offsite, etc).

Privacy Policy

The policy should mandate guidelines of acceptable computer usage while using company resources (including all data).

Another step would be to conduct a Security Assessment and Security Audit.

  • A Security Assessment identifies vulnerabilities within an organization’s infrastructure and will then recommend solutions to secure the system.
  • A Security Audit installs an application on the network that is designed to identify, classify, secure, monitor and report on sensitive data. A manager is then notified every time the data is accessed so organization’s can track who is accessing sensitive data and when and where the access happens.

If you aren’t sure of your organization’s policy in regards to sensitive data, ask them. If they don’t have a policy in place – inquire about initiating one. This will help to safeguard yourself as well as the data you are in charge of.

Thursday, March 4, 2010

NSK Inc Associate Getting CISSP Certified!

Ben. R Howard, a Senior IT Associate at NSK Inc recently took the CISSP Certification Exam and passed, placing him among roughly 64,000 other IT professionals in the world who have the certification.

The CISSP (Certified Information Systems Security Professional) is a highly prestigious certification that requires a massive amount of training and credentials in order to be considered to even take the exam.

CISSP candidates must have at least five years of experience in information security as well as experience with two of ten domains of security before they even apply. They then have to train and prepare for a sixty page exam that lasts for six-hours.

Those who pass receive the certification. A CISSP Certified Associate knows how to formally manage an all encompassing security program. The CISSP credential is a testament to the years of experience, knowledge, and competency of information systems, these personnel have achieved.

Howard hopes to broaden NSK’s ability to provide security services to its clients with his new certification. Having a CISSP Certified IT Associate, will only help NSK Inc move forward as a premier consulting firm in Boston.

Monday, July 27, 2009

Compliance for 201 CMR 17.00 is going to take a little time... We have written out a Guideline for your Timeline!

201 CMR 17.00: Standards for the Protection of Personal information of Residents of the Commonwealth of Massachusetts

"This regulation implements the provisions of M.G.L. c. 93H relative to the standards to be met by persons who own, license, store or maintain personal information about a resident of the Commonwealth of Massachusetts." (Purpose MGL c 93H)


August
Designate an Information Security Officer - You will need to designate at least 1 person at your place of business who will maintain the comprehensive information security program. Finding that person now, will help get the rest of the items in line for when they need to be done. You can get a compliance checklist at: 201 CMR 17.00 Compliance Checklist


September


Start Assessing Your Information:

  1. Identify the paper, electronic and other type records, including storage media, laptops and portable devices that contain personal information.**

  2. Check all anti-virus and security patches on all computer systems and servers -- make sure they are up to date.**
    a. Check that you have reasonably up-to-date versions of system security agent software (including malware protection)**

  3. Identify what "personal information" moves around your business and out of your office including:**

    a. healthcare/insurance information

    b. benefits/401K information

    c. Accounting/Tax information

    d. Employment and Credit Applications

    e. Checks and credit card information

  4. Identify persons who need to see the "personal information" and those who do not.

  5. Identify where encryption for personal information is needed.**

  6. Identify what third-party service providers your business may use that have access to personal information.

  7. Identify reasonably foreseeable internal and external risks to paper and electronic records containing personal information.**

  8. Identify any systems that are connected to the Internet and make sure the firewall protection for files containing personal information are up-to-date.**


October

Purchase any hardware or software upgrades that are needed**

  • Get control of user IDS and other identifiers**

  • Come up with a reasonably secure method of assigning/selecting passwords for users**

  • Start developing your WISP (Written Information Security Program) making sure that you include:

    a. Administrative, technical and physical safeguards for Personal information protection

    b. Make sure that your WISP is applicable to all records containing personal information
    about a resident of the Commonwealth of Massachusetts

    c. Any identified and reasonably foreseeable internal and external risks to paper and electronic records

    d. Regular and ongoing employee training, and procedures for monitoring employee compliance

    e. Disciplinary measures for violators

    f. Policies and procedures for when and how records containing personal information should be kept, accessed or transported off your business premises

    g. Processes for blocking terminated employees physical and electronic access to personal information, including deactivating their passwords and user names

    h. Steps taken to verify third party service providers access

    i. The length of time that you are storing records containing personal information.

    j. Specifically the manner in which physical access to personal information records is to be restricted

    k. Whether you are storing your records and data in locked facilities, storage areas or containers and the security measures taken to keep these areas secure

    l. Actions and documenting that is taken in connection with any breach of security

  • November


    1. Install all hardware and software upgrades**

    2. Test policies that have been written

    3. Start Training Employees on new policies

    4. Finalize WISP


    December


    1. Finish Training Employees
    2. Send out WISP Policy to all Employees and get signatures from all, verifying they understand and will comply

    January 1, 2010 and beyond




    1. Continue monitoring your systems and procedures**

    2. Continue providing training to new and existing employees

    3. Update policies as required

    4. Assure all computers and servers remain up-to-date with patches and anti-virus software**

    **There are many intricate requirements and rules involved with this law that have left many companies in Massachusetts with questions. NSK Inc. has formed a knowledgeable team to better assist with clarifying this law. If you have questions please fill out this form or contact:Danielle Carroll at 617.303.0480

    Tuesday, May 26, 2009

    NSK Offers MPICA for Compliance with MA Law


    MPICA (Massachusetts Personal Information Compliance Assessment) is an IT support service that NSK Inc is offering to businesses that need to comply with the Massachusetts General Law Chapter 93H and its new regulations 201 CMR 17.00. The law requires that any companies who own, license, store, and/or maintain personal information about a Massachusetts resident make adjustments to further protect personal information. Both electronic and paper records will need to comply with the new law. The regulations go into effect on January 1, 2010. The law was originally supposed to go into effect on January 1, 2009, but then was pushed to May 1 and then January 1, 2010 due to the state of the economy, time restraints, and confusion about the law.

    MPICA offers IT help to companies who are having difficulty making changes in their systems to adjust to this law. Identity theft and fraud are the major concerns at the core of the implementation of the 201 CMR 17.00, so it is important that the necessary changes are made within business IT systems. If a Massachusetts resident's information is leaked or captured, there could be serious consequences for the business that allowed the breach and for the individual whose information was leaked. Therefore, making changes to keep residents' information secure will be required to avoiding security breach and fines.

    Companies will need a written security plan to safeguard their contacts' and/or employees personal information. It will need to be illustrative of policies that demonstrate technical, physical, and administrative protection for residents’ information. The plan needs to be written to meet industry standards. Companies will have to designate employees to oversee and manage security procedures in the workplace, as well as continuously monitor and address security hazards. Policies addressing employee access to and transportation of personal information will need to be developed, as well as disciplinary measures for employees who do not conform to the new regulations. Limiting the collection of data to the minimum that is needed for the purpose it will be used for is also part of the new regulations.

    Since revisiting workplace data security procedures requires in-depth changes, this is a lengthy process. It takes months for businesses to make the necessary changes required by this law, so businesses might consider starting early at contacting an IT consulting firm and seeking its IT support.

    Written by Melissa Cocks