Monday, January 25, 2010

NSK Inc. Hires New Marketing Intern



Name: Michael Lupacchino

Education: Emerson College

Position: Marketing Intern

Michael Lupacchino joined the NSK Inc Team as a Marketing Intern in January 2010. He graduated Cum Laude from Emerson College in December 2009 with a B.S. in Marketing Communications. A native of East Hartford, Connecticut, Michael’s interest in IT began when his mom purchased the family’s first computer (running Windows 95) in 1996.

A self taught technician, Michael slowly immersed himself in virus and spyware removal, registry cleaning, hardware and software instillations, audio and video editing, and wireless network set-up through the help of search engines, online forums, and owner’s manuals.

Previous to NSK Inc, Michael worked for the Emerson College IT Help Desk where he served as a Lab Assistant, Help Desk Technician, and Student Manager. A devout Windows® user, he became well versed in Mac® systems and software during his time at the Help Desk.

Michael was a member of EmComm, Emerson’s student run Integrated Marketing Communications Agency, as an account executive and as Director of Information Technology. He also worked as a freelance marketing consultant for Camp Stanleyfor the Performing Arts.

His other interests revolve around the performing arts. He restarted the Emerson Dance Company in 2007 and served as President until December 2009. He has directed and choreographed numerous showcases and has been involved with Emerson Stage. His most recent work will be shown in X-Dance 2010, debuting in February at Emerson College.

On working at NSK Inc, Michael is incredibly lucky to have found such a position. “To find an internship in both marketing and information technology seemed almost too good to be true.” He says that he is really enjoying his time with the company and is incredibly thankful for the opportunity.

Monday, January 18, 2010

NSK Inc. Hires New Sr. IT Associate

Name: Shane Martz

Education: Gibbs College

Years Active: 10

Originally from Wethersfield, CT, Shane Martz started his career in IT at the age of six when his father brought home a computer. He began working in the IT Industry professionally at eighteen. After spending time at Gibbs College, Shane became a full time employee in the IT Services sector.

Previous to NSK Inc., Shane worked for the IT Department of Skyhook Wireless, a Boston based company that specializes in wireless global positioning technology for mobile devices and smart phones.

Shane joined the NSK Inc. team in January 2010, as a Senior IT Associate. He is a Microsoft Certified Professional (MCP) and is working towards his MSCA (Microsoft Certified Systems Administrator). Shane is a cross-platform specialist, being well versed in Windows, Macintosh, and Linux systems.

On working at NSK Inc., Shane is thrilled to be here. He cites great business practices and high customer satisfaction as part of the NSK Inc. charm. According to Shane “There is nothing worse than being a provider with customers who don’t like you.” He states he really enjoys the fact that our clients like to work with us and is really excited about furthering his career at NSK Inc.

Thursday, January 14, 2010

Give in a Crisis.... But be wary who you are giving to



















There is an emerging humanitarian crisis in Haiti, currently the front page story on every major new website.

This is a quick security reminder due to the timeliness of the issue. The e-mail I received above is actually legitimate, but this is the same e-mail I would expect a scam-artist to use, just using the hyper-links and shortened URLs to point to illegitimate sites.

Quick security tip:

Be particularly wary of scam artists trying to profit from human nature. When catastrophy strikes, many people want to help and will often be too eager to send their money to bother checking where the money is actually going. Be wary of e-mails soliciting help and more wary still when the URLs are shortened. Don't be discouraged from donating, just make sure you go directly to the site to which you wish to give your time and money. If you want to donate through the Red Cross, go directly to www.redcross.org, or to the charity or benefit of your choosing.

Wednesday, November 25, 2009

Final Version of MGL 93H 201CMR 17.00 Filed

OCABR (Massachusetts Office of Consumer Affairs and Business Regulation) on October 29th, 2009 filed the "Final" version of the "Standards for the Protection of Personal Information" also know as MGL 93H 201 CMR 17.00 with the Secretary of State's office. The first issue was in September of 2008, and after more than a year of amendments to the original regulations this is the final step before the regulation takes effect on March 1, 2010. The final regulations include some further clarifications than the amendment that was released in August of this year, but are substantially similar.


The latest revisions were written in response to requests from companies and business leaders that were looking for further clarification of the regulation.


Following are the changes:


17.02 Definitions
Owns or licenses - adds the word "stores"
Service provider - adds the word "stores" and deletes the phrase provided, however that "Service provider" shall not include the U.S. Postal Service.

17.03 Duty to Protect and Standards for Protecting Personal information


Clarifies the language in section (2)(f)(2) relating to service provider contracts - A contract entered into with a third party service provider is deemed to be in compliance with this section until March 1, 2012, even if the contract does not include a requirement that the third party service provider maintain such appropriate safeguards, as long as the contract was entered into no later than March 1, 2010


"Definition of Owns or Licenses. A company owns or licenses personal information if it "receives, stores, maintains, processes, or otherwise has access to personal information in connection with the provision of goods or services or in connection with employment." The final regulations make clear for the first time that a company that "stores" the personal information of a Massachusetts resident is subject to the regulations' requirements, even if the company does not otherwise process or access such information.


Definition of Service Providers. A service provider is defined as "any person that receives, stores, maintains, processes, or otherwise is permitted access to personal information through its provision of services directly to a person that is subject to this regulation." The final regulations eliminate a previous carve-out that had stated, "‘service provider' shall not include the U.S. Postal Service." It is not clear that the OCABR intends this change to mean that a company using the U.S. Postal Service to transmit personal information must contractually require the U.S. Postal Service to implement and maintain appropriate security measures for such personal information, as it must do with other service providers. But the OCABR has stated that a company must assess the risks of using a common carrier, including the U.S. Postal Service, to transmit personal information and take steps to protect that personal information.


Amending Existing Contracts with Service Providers. The final regulations clarify prior language related to a grace period for amending existing contracts with service providers so that such contracts require the service providers to implement and maintain appropriate security measures for personal information. The regulations now make clear that a company has until March 1, 2012 to amend existing contracts with service providers to include personal information security provisions, as long as the existing contracts were entered into before March 1, 2010. As before, service-provider contracts that the company entered into after March 1, 2010, must include personal information security provisions." [1]


For a copy of the most up to date Regulation please click here.


MPICA - Massachusetts Personal Information Compliance Assessment


[1] David M. McIntosh, Lisa M. Ropple Christine Santariga - Ropes & Gray LLP Boston Office

Friday, October 16, 2009

Your Timeline for Compliance with MGL 93H 201CMR17.00

October 2009

Designate an Information Security Officer - You will need to designate at least 1 person at your place of business who will maintain the comprehensive information security program. Finding that person now will help get the rest of the items in line for when they need to be done. You can get a compliance checklist at: 201 CMR 17.00 Compliance Checklist

November
Start Assessing Your Information:

Identify the paper, electronic and other type records, including storage media, laptops and portable devices that contain personal information.**
Check all anti-virus and security patches on all computer systems and servers -- make sure they are up to date.**
a. Check that you have reasonably up-to-date versions of
system security agent software (including malware
protection)**
Identify what "personal information" moves around your business and out of your office including:**
a. healthcare/insurance information
b. benefits/401K information
c. Accounting/Tax information
d. Employment and Credit Applications
e. Checks and credit card information
Identify persons who need to see the "personal information" and those who do not.
Identify where encryption for personal information is needed.**
Identify what third-party service providers your business may use that have access to personal information.
Identify reasonably foreseeable internal and external risks to paper and electronic records containing personal information.**
Identify any systems that are connected to the internet and make sure the firewall protection for files containing personal information are up-to-date.**

December 2009

Purchase any hardware or software upgrades that are needed**
Get control of user IDS and other identifiers**
Come up with a reasonably secure method of assigning/selecting passwords for users**
Start developing your WISP (Written Information Security Program)
Make sure that your WISP is applicable to all records containing personal information about a resident of the Commonwealth of Massachusetts

Make sure that you include:

Administrative, technical and physical safeguards for Personal information protection
Any identified and reasonably foreseeable internal and external risks to paper and electronic records
Regular and ongoing employee training, and procedures for monitoring employee compliance
Disciplinary measures for violators
Policies and procedures for when and how records containing personal information should be kept, accessed or transported off your business premises
Processes for blocking terminated employees physical and electronic access to personal information, including deactivating their passwords and user names
Steps taken to verify third party service providers access
The length of time that you are storing records containing personal information.
Specifically the manner in which physical access to personal information records is to be restricted
Whether you are storing your records and data in locked facilities, storage areas or containers and the security measures taken to keep these areas secure
Actions and documenting that is taken in connection with any breach of security

January 2010

Install all hardware and software upgrades**
Test policies that have been written
Start Training Employees on new policies
Finalize WISP
December

Finish Training Employees
Send out WISP Policy to all Employees and get signatures from all that they understand and will comply

February 2010 and beyond

Continue monitoring your systems and procedures**
Continue providing training to new and existing employees
Update policies as required
Assure all computers and servers remain up-to-date with patches and anti-virus software**

** NSK Inc. can help you with any of these tasks, just let us know.

Thursday, August 13, 2009

What is AJAX? Does Microsoft do AJAX?

Ajax is “Asynchronous JavaScript and XML”. If you’ve ever used Microsoft Outlook Web (OWA), then you’ve used AJAX. Microsoft wrote OWA with hidden embedded web requests, so OWA could get and display new mail without refreshing the page all the time. Within a few years, everyone was doing this in several different ways. Microsoft was a pioneer, but AJAX is not Microsoft technology.

JavaScript (the modest little webpage scripting language) was one surprising ingredient. JavaScript was combined with something we got from Web Services: XML. That’s right-- Microsoft’s hidden browser function was combined with JavaScript and with some of the fast, light, network-ready data formats that we all learned from web services and SOAP, to create AJAX. Like magic, XML was being sent into web pages, “from behind”, to display data and reformat pages. The best part? It’s fast.

Atlas” was Microsoft’s first AJAX toolkit, released in 2007. When Microsoft renamed it to “AJAX toolkit 1.0”, many Microsoft developers were unhappy because they lost the cool name. But Microsoft knew what they were doing, because we’ve already been asked by clients why our AJAX is working, even though they never installed Microsoft AJAX on their
server!

Unfortunately, Microsoft AJAX toolkit is not yet a tool of common choice, and many Microsoft.NET programmers compare the AJAX toolkit to early versions of FrontPage(they assume it will get much better before being replaced with something else entirely). As of right now, Microsoft AJAX Toolkit doesn’t easily stand up to such libraries as Prototype, Dojo, Scriptaculous, and General Interface, in the same manner that Front Page (which has now been replaced by SharePoint Designer) didn’t survive well in the market against Adobe Dreamweaver.

Before MS AJAX arrived, these other toolkits were listing clients on their websites from Gucci to NASA to Apple to ESPN to Sony, and even Microsoft! Developers who use only Microsoft tools may say AJAX is slow, because Microsoft AJAX can be slow. AJAX tools are already far more sophisticated than Web Service tools ever became, and the simple truth is that good web programming now requires qualified, experienced pros.

How does NSK do AJAX?

NSK uses an in-house AJAX library, which was specifically designed to do three things. It performs as well or better than equivalent Windows-based applications. It is learned easily by developers, so work for our clients can be done quickly and inexpensively. And our framework is useable on many browsers (in addition to Internet Explorer), and is 100% compatible with all current major server and development technologies, including Microsoft.NET. We’ve seen development turn-around as short as eight months, on financial industry projects of considerable complexity.

Written by Keith Mitchell, Senior Developer at NSKinc

Web 2.0, AJAX, XML, Thin Clients, and You

"Web 2.0 and AJAX have already changed web programming and business application development to the same extent that managed care has already changed the healthcare industry, and boxing gloves have already changed boxing."


Most web programmers learn quickly how to use a submit button, which allows a user to wait for the next web page to come back to them and tell them the results of their action. Most accomplished web programmers have learned how to display a table of data, and to sort the data by waiting for the page to refresh. Most accomplished web programmers have also explained to clients many times, that they can’t type into a dropdown list; they can only choose one of the values in the list, because “that’s the way the web thing works”.

Now, web programming isn’t so simple. Forms can be updated and data can be sorted, faster than you can read the confirmation messages. No one has to wait for pages to reload any more. New descriptions can be added to a list, and stored into a database, simply by typing them into a dropdown box. A web form can enter and correct data faster than a user can type.

The admission requirements for the web programmer club are getting higher. Microsoft and Adobe are writing tools to make these tasks easy, but these tools are still in their infancy.


Written by Keith Mitchell, Senior Developer at NSKinc