Thursday, July 23, 2009

Massachusetts Businesses: Are you in Compliance?

DO NOT WAIT ANY LONGER. MARCH 1, 2010 WILL BE HERE BEFORE YOU KNOW IT!

Do you have all the information you need to become compliant with the new Massachusetts Regulation 201 CMR 17.00?

This regulation is inherent to Massachusetts General Law 93H (MGL 93H). This law was written to define the security breaches and regulations for safeguarding the personal information of any Commonwealth of Massachusetts resident. This regulation implements the provisions of the law and describes what you need to have in place in your company in order to be compliant.

Why was 93H Created? Why 201 CMR 17.00


The Department of Consumer Affairs and Business Regluations issued this law and these regulations in response to the following data breaches occurred: ·TJ Max (TJX ) January 17, 2007 -Affected about 100 million account numbers Hacked several different ways - through wireless connections and kiosks ·Hannaford Supermarkets - between Dec. 7, 2007 and Mar 10, 2008 -More than 4 million card numbers were exposed, and by the time Hannaford publicly announced the breach, on March 17, 2008, about 1,800 fraudulent charges had been made. ·Other Security Threats
-Malware, viruses In response, M.G.L. c 93H was enacted in November, 2007. Within the first 10 months after enactment of M.G.L. c 93H, the office of Consumer Affairs and Business Regulation received 318 notifications of security breaches.

  • 10 involved data that was encrypted
  • 69 involved data that was password protected
  • Total MA residents affected was 625,365

60% were due to stolen laptops or hard-drives and 40% were employee error or sloppy internal handling.
75% were in the financial services sector.

Massachusetts then took the lead in passing a new regulation -- 201 CMR 17.00 -- that required companies to implement a comprehensive data security plan that incuded encryption of all computer systems with personal information of a Massachusetts resident.

What Does This Mean to Your Business

It means that the Commonwealth of Massachusetts is setting minimum starndards for the protection of personal information, whether that information is stored in electronic or paper format. It means that if your company owns, licenses, stores or maintains personal information about a Massachusetts resident You MUST take steps to comply with this new regulation.

What is Personal Information

According to 201 CRM 17.00, personal information is defined as the First Name or First Initial, Last Name and any one or more of the following information:Social Security Number Credit Card or Debit Card Number State ID Card Bank or Financial Account Number Drivers Licence Number If you accept credit cards, you have the imprint of the card or the data from the magnetic strip.. This information falls in the above catagory. You MUST take steps to comply. If you are a business located in Massachusetts or you have employees who reside in Massachusetts and you have copies of driver's licences', employment applications, personnell files or payroll information on those employees You MUST take steps to comply.


What Do You Need To Do?

Establish and Maintain a security program to all who have access to personal information with the following Elements:

Computer System Security Requirements **

  1. Control of user IDs and passwords
  2. Secure method of assigning and selecting passwords
  3. Assign unique identifications plus passwords which are not default passwords
  4. Block access after multiple unsuccessful attempts to computers and servers holding the personal information
  5. Restrict access to inactive accounts
  6. Restrict access to files, to those that need acces to perform their job duties


Transmission of Personal Information**

  1. Encryption of all transmitted rocords and files containing personal information that travels across public networks
  2. Encryption of all wireless networks


Encryption of portable devices**

  1. Personal information stored on laptops and other portable devices must be encrypted

Staying Up-To-Date**

Make sure all computer and servers that hold personal information stay up to date on:

  1. Operating system patches
  2. Firewall software
  3. Antivirus software set to receive most current updates on a regular basis
  4. Antivirus software must include malware protection


Training and Monitoring

  1. Education and training of employees on the proper use of the computer security system and the importance of personal information security
  2. Reasonable monitoring of systems for unauthorized use or access to personal information


Written Information Security Program (WISP)

  1. Designate 1 or more persons to maintain the program
  2. Identify risks and evaluate safegaurds
  3. Develop security posicies for employees that work outside the office
  4. Impose disciplinary measures for program violations
  5. Prevent terminated employees from accessing personal information
  6. Make sure that third-party service providers have an information Security program that is compliant
  7. Limit the amount of personal information collected, the time it is retained and access to it
  8. Identify system used to store personal information
  9. Restrict physical access to records
  10. Regularly monitor the program once it is in place
  11. Review the scope of security measures at least annually or when there is a change in business practices
  12. Document responsive actions taken in a security breach incident

**There are many intricate requirements and rules involved with this law that have left many companies in Massachusetts with questions. NSK Inc. has formed a knowledgeable team to better assist with clarifying this law. If you have questions please fill out this form or contact:
Danielle Carroll at 617.303.0480

Tuesday, July 21, 2009

Outsourced IT vs. In-House IT

At some point during the growth of your business, you may start to wonder if a different system would work in your favor. Right now is a time during which you may especially feel the need to budget more carefully. There are different areas in which you can cut costs in your business, and you might be considering your IT department as an appropriate department in which to do so. Many firms are downsizing their IT staff and looking to outsource to save money. Before you decide on one definite solution, let’s outline the differences.

Outsourced IT:
When you outsource, you hire IT experts from an outside firm that typically tend to several different businesses. Depending on the IT firm, your relationship with your outsourced IT people can be very personal or impersonal. It is important to many businesses that they keep a close relationship with their outsourced IT specialists. This may mean that a single person or even two people are assigned to service your company so that there is a consistent knowledge of your IT history and problems. This is something you should probably consider as most important when evaluating your options. This way, during each new visit you don’t have to recap every IT problem you have had and what the status was during your last IT visit with a different person. Also, you get the convenience of having one person who has a broad spectrum of knowledge about all areas of IT.

In-House IT:
Many businesses have several IT professionals in-house. For example, one person may be used for IT management, the other for systems engineering, and another for general support. The problem many businesses run into with this is each person might not be fully utilized for the amount they are paid in salary. You may actually use only a portion of each person’s skills, and only when something goes wrong. Also, some businesses that have a single IT person in-house may not get that broad spectrum of knowledge because it is hard to come by someone who is trained in all areas. On the other hand, you may be content with having IT people at the desk next to you as opposed to picking up the phone or logging into an online helpdesk.

Outsourced IT/In-House Combination: Some businesses prefer having both an IT professional staffed in-house and an outside IT team. This gives some businesses the comfort of having someone constantly on-site while having outside experts who are highly-skilled in many areas a phone call away.

Written by Melissa Cocks

Tuesday, June 30, 2009

Data Loss Prevention and Data Backup


It is not a good day at work for you when you realize you have lost an important document that you worked on for hours, or when you realize your hard drive has been completely wiped out. The importance of data backup may seem a bit repetitive at this point, but it does take more effort to replace the data once it is gone than it takes to back it up.

First off, you should have a backup schedule. You should also think about how you’re going to implement it. Will you hire someone to do continuous backup for you? Maybe you’ll just use backup tapes. Backup tapes may seem like a perfectly fine idea to you, but you need to keep in mind that if a disaster strikes on site, no electronic device will save your data unless it is in a remote location.

Continuous backup is a process by which your data is constantly backed up by frequent ‘snapshots.’ Remote backup is a process by which your data is maintained off site without having to manually transport your data. Manual transportation has proven time and again to be an unsafe measure. You may want to consider continuous remote data backup for your company to ensure the best security of your information.

Other measures to take include keeping your computers in cool, dry, areas that are free of dust. Use a generator – if there’s ever a power outage, you want your computer to stay on so that data doesn’t disappear because you didn’t get the chance to save it. In addition, antivirus software is essential for keeping your computer’s system healthy and decreasing your risk of losing data.

Written by Melissa Cocks

Thursday, June 18, 2009

Preventing Computer Viruses

Far too many company and household computers become infected with viruses annually, and the affects of these infections can be devastating to the user. Since there are so many ways a virus can enter your computer’s system, it’s important that you know how to block off those entrances. Here are several ways to decrease the chances of your computer becoming infected:

-Don’t solely rely on anti-virus software, although you should have it installed. Be sure to update often to detect and protect your computer from the most recently created viruses.
(It also doesn't hurt to install a spyware, malware, and adware removal application)
-Read the headlines. Stay on top of the news to educate yourself about new viruses.
-Try not to open an e-mail attachment until you are sure it is safe. Make sure you know the person or why it may be sent to you.
-Once again, surf the web for news about viruses so you know common subject lines and file extensions relative to those viruses.
-Disable automatic attachment viewing in your e-mail settings.
-Set your Word and Excel settings so that Macros are disabled when a file is opened up for viewing.
- Use search engines that are well-known for generating results relevant to search terms. A site is probably safe if a lot of people have linked to it, but keep in mind that this isn’t always the case. This way, your chances of being directed to a site that hosts a virus is less likely.
-Make sure you set your security settings to ‘high’ in your web browser.
-Try to avoid downloading free applications from unverifiable websites.
-Configure your settings so that you can always view file extensions.

The following are examples of file extensions to be suspicious of when they show up in e-mail:

ADE, ADP, BAS, BAT, CHM, CMD, COM, CPL, CRT, DLL, EXE, HLP, HTA, INF, INS, ISP, JS, JSE, LNK, MDB, MDE, MSC, MSI, MSP, MST, OCX, PCD, PIF, POT, REG, SCR, SCT, SHB, SHS, SYS, URL, VB, VBE, VBS, WSC, WSF, WSH

It is easy to tell yourself you will regularly take these measures to maintain your computer security and implement virus protection, but it is also quite easy to forget. This is often how viruses end up finding their way into your computer.

Written by Melissa Cocks

Friday, May 29, 2009

The Importance of Having a Business Continuity Plan

What would happen if your data was lost or you lost internet for the day? If a hurricane hit and your information was gone, would you be able to continue performing your everyday business tasks? If not, how long would it take to recover your business? These questions are overwhelming, but important to ask yourself when it comes to threats to your business.

Whether you are the CEO or the CIO of your company, it is important to acknowledge the value of having an established business continuity plan. It is difficult to believe that something drastic enough to disrupt your everyday business activities could take place, but it is often when we assume things could never happen to us that they do.

Many U.S. companies encounter computer system failures annually. A lot of these failures last for over a day, which can significantly affect profit and customer relationship management (CRM). Also, it has been found that many businesses do not have a plan in place in case a disaster was to occur. That being said, there could be an even greater impact if disaster struck because many businesses depend on each other to operate efficiently and profitably. The potential domino effect that businesses would experience in the worst case scenario would be devastating.

On a lighter note, let’s just say that your email server was down for a day for whatever the reason may be. You might say, “But we could use the phone.” That is true, but consider how heavily businesses depend on databases, and rightfully so. Using them is easier and faster than going through a Rolodex of contacts, and they organize every piece of information regarding a single contact. You are going to want to make sure you have a plan in place and also seek help from IT professionals or an IT team in order to lessen the impact of disruption.

Assessing how vulnerable you are to being impacted by disaster or data loss is an important step in planning for business continuity. Here are a couple of questions that may make you think about how important a continuity plan is to your specific business:

-What activities are most important to your business?
-Can you survive without them or do you have an alternative?
-How much of your business’ productivity depends on computers/databases/internet?

Chances are that you feel concerned if you have not already established a plan, which isn’t surprising since most of America’s businesses rely on computers. Here are some steps you can take to make sure you are prepared in the case of disruption:

-Identify important roles in your company (who plays a crucial role in everyday business? If a certain person in your company was to no longer be there, would you have a backup?) Include solutions in your plan.

-Identify places for equipment rental and back-up supplies

-Implement off-site data backup or seek IT support/IT consulting

-Map out an alternate location (where would you move offices to temporarily if needed?)

-Have this plan set in stone

Additionally, you need to be sure every employee is informed of the plan, so it would be a good idea to conduct information sessions or send out newsletters regarding the business continuity plan.

Written by Melissa Cocks

Tuesday, May 26, 2009

NSK Offers MPICA for Compliance with MA Law


MPICA (Massachusetts Personal Information Compliance Assessment) is an IT support service that NSK Inc is offering to businesses that need to comply with the Massachusetts General Law Chapter 93H and its new regulations 201 CMR 17.00. The law requires that any companies who own, license, store, and/or maintain personal information about a Massachusetts resident make adjustments to further protect personal information. Both electronic and paper records will need to comply with the new law. The regulations go into effect on January 1, 2010. The law was originally supposed to go into effect on January 1, 2009, but then was pushed to May 1 and then January 1, 2010 due to the state of the economy, time restraints, and confusion about the law.

MPICA offers IT help to companies who are having difficulty making changes in their systems to adjust to this law. Identity theft and fraud are the major concerns at the core of the implementation of the 201 CMR 17.00, so it is important that the necessary changes are made within business IT systems. If a Massachusetts resident's information is leaked or captured, there could be serious consequences for the business that allowed the breach and for the individual whose information was leaked. Therefore, making changes to keep residents' information secure will be required to avoiding security breach and fines.

Companies will need a written security plan to safeguard their contacts' and/or employees personal information. It will need to be illustrative of policies that demonstrate technical, physical, and administrative protection for residents’ information. The plan needs to be written to meet industry standards. Companies will have to designate employees to oversee and manage security procedures in the workplace, as well as continuously monitor and address security hazards. Policies addressing employee access to and transportation of personal information will need to be developed, as well as disciplinary measures for employees who do not conform to the new regulations. Limiting the collection of data to the minimum that is needed for the purpose it will be used for is also part of the new regulations.

Since revisiting workplace data security procedures requires in-depth changes, this is a lengthy process. It takes months for businesses to make the necessary changes required by this law, so businesses might consider starting early at contacting an IT consulting firm and seeking its IT support.

Written by Melissa Cocks

Friday, May 8, 2009

The Need for IT Support

by Art Gib

When you use anything electronic, whether it's one computer or a cell phone at home, or whether you are a businessman with a whole network of computers, chances are at one point or another you will need technical support. It doesn't matter if you live in Boston or LA, the need for technical (IT) support will probably come up.

Basically, IT support is available to people and companies who need help solving a technical problem with their electronic device. The companies who offer IT support don't usually offer training, rather they work with the customer or client until the problem has been solved. The IT guy is well trained to handle your electronic malfunctions, which is a good thing because most of us have very limited knowledge of the inner working of electronics. We rely on them, but we don't fully understand them; the IT guy does.

Now, for the stay at home mom in Boston or California, or wherever, it might be necessary to call technical support a couple of times a year, but the businessman may need the help much more frequently. Most companies that offer technological products have a support system that comes with it. For example, if you go through Qwest for the internet, you can call Qwest support to get the answers to your problems. But for a businessman, calling Qwest isn't the solution. You need an IT support team because having the right amount of help in your IT department can save you time and money. It also frees up the time for your IT employees to work on ways to help your business.

A good IT support company in Boston will help you reduce the management costs of your IT department, will be able to help you use technology more efficiently, help you with data storage and recovery, and, of course, support the IT managers of your company. IT support doesn't only mean solving a problem on your computer. It also means freeing up the time of your regular employees by doing necessary infrastructure changes without them. For example, software needs to be updated frequently, and the updates can take time. A good IT support company will do the updates and installations of the software for you.

Don't sell yourself short by not having a good IT support center. Your employees can work more efficiently, making better use of their time, if they have a decent support network behind them. Your business will feel the benefits of a good network.

NSK Inc. offers IT support in Boston and San Francisco.

Art Gib is a freelance writer.