Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Big Brother is watching you shop
  • UK Alert: Stop the Pirate-Finder General!
  • New Copyright Alliance hopes to strengthen copyright law
  • Exploit-for-sale hacker pins bug on Vista's e-mail app
  • AACS hacked to expose Volume ID: WinDVD patch irrelevant - Engadget
  • FISA 101
  • The Year in First Amendment Rights: Internet Censorship

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Data privacy, security laws have far-reaching impact

Submitted by MacRonin on November 13, 2008 - 2:51pm
  • Companies
  • Databases
  • Editorial
  • Government
  • Hmmm
  • Infrastructure
  • Laws
  • Legal
  • Privacy
  • Proposed Laws
  • Remember
  • Security
  • Standards

Data privacy, security laws have far-reaching impact: Via IT World

nd data security regulations that will make it eke out California for the most wide ranging state privacy and security laws -- laws that are likely to impact the policies, practices, procedures, contracts and training used by companies nationwide. The Massachusetts Office of Consumer Affairs and Business Regulation determined that there was a significant need for set of comprehensive standards that ensure businesses are taking practical steps to safeguard personal information. While many of these practices are probably adopted by most companies in some way, shape or form --now a laundry list of minimum standards will be required. And, since it may be impractical for a company to treat information collected from Massachusetts residents differently than others--many companies across the country will need to look holistically at their data privacy and security programs across the country to make sure that they meet the requirements of Massachusetts standards.

Beginning on January 1, 2009, all businesses that collect personal data from or about Massachusetts residents will need to adopt a comprehensive written security program, conduct internal and external security reviews and complete employee training regarding their programs. While the efficacy of a security program will be determined based on the relative size of a company and the type and amount of data a company maintains, the standards clearly state that a security program needs to contain, at a minimum:

  • Designate one or more employees to maintain the security program.
  • Identify and assess the internal and external risks to the security, confidentiality, and/or integrity of any electronic, paper or other records containing personal information.
  • Evaluate current safeguards and means for detecting and preventing security system failures.
  • Implement and evaluate ongoing employee training (which must include temporary and contract employees).
  • Implement and evaluate employee compliance with policies and procedures.
  • Develop security policies that set forth whether and how employees should be allowed to keep, access, and transport records containing personal information outside of business premises.
  • Discipline employees for violating program rules.
  • Prevent terminated employees from accessing records containing personal information by immediately terminating access.
  • Take reasonable steps to verify that third-party service providers with access to personal information have the capacity to protect such personal information, including:
    • Selecting and retaining service providers that are capable of maintaining safeguards for personal information (i.e., conducting due diligence)
    • Contractually requiring service providers to maintain a security program that complies with the Standards
    • Limiting the amount of personal information collected to that reasonably necessary to accomplish the legitimate purpose for which it is collected; limiting the time such information is retained to that reasonably necessary to accomplish such purpose; and limiting access to those persons who are reasonably required to know such information in order to accomplish such purpose or to comply with legal requirements
  • Require an audit/inventory to identify paper, electronic and other records, computing systems, and storage media, including laptops and portable devices used to store personal information, to determine which records contain personal information, unless the security program provides for the handling of all records as if they all contained personal information.
  • Implement reasonable restrictions upon physical access to records containing personal information, including a written procedure that sets forth the manner in which physical access to such records is restricted; and storage of such records and data in locked facilities, storage areas, or containers.
  • Regularly monitor to ensure that the security program is operating in a manner reasonably calculated to prevent unauthorized access to or unauthorized use of personal information; and upgrade information safeguards as necessary to limit risks.

  • Review the scope of the security measures on at least an annual basis or whenever there is a material change in business practices that may reasonably implicate the security or integrity of records containing personal information.
  • Document incident responses involving a breach of security, and changes in business practices resulting from the incidents.

Read Original Article (Via IT World.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
  • How Privacy Vanishes Online
  • Undercover Feds on Social Networking Sites Raise Questions
  • FBI Uses Fake Facebook Profiles To Spy On Suspects
  • Lawrence Lessig: Citizens Unite
  • Case Report – BCCA says aerial surveillance by telphoto zoom lens not a search
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.