About Us  | Contact Us

Archive for the ‘Security’ Category

Shopper Uncovers Security Compliance: 201 CMR 17.00 Already Having an Effect on Businesses

I was semi-impressed yesterday when I visited a global retail chain, signed up for a new credit card and they handed me back the application form for me to destroy.  Retail stores that manage payment card information must abide by strict rules governed by PCI — the Payment Card Industry standard developed to protect card [...]

Leave a Comment

Connecticut Attorney General Sues Health Net Over Security Breach

I mentioned in my blog in late November that the cost to Health Net over loss of an unencrypted hard drive containing 450,000 patient records (revised down from 1.5m) would be much greater than the cost of securely controlling and protecting their information assets. Health Net will begin the process of emptying their wallets in [...]

Leave a Comment

H.R. 2221: Data Accountability and Trust Act

The national Data Accountability and Trust Act, H.R. 2221 passed within the House of Representatives earlier this month (Dec. 8th, 2009).  The Bill — as with 201 CMR 17.00, the Massachusetts Protection for Personal Information — seeks to protect consumer personal information and requires notification to individuals in the event of a breach, albeit from [...]

Leave a Comment

SSL and TLS no longer safe?

 A huge chink in the armor of end-to-end encryption took a big hit last week when the US-CERT reported that a man-in-the-middle exploit code against SSL and TLS is publicly available.   The exploit allows a malicious attacker to insert themselves into an SSL or TLS conversation during a client or server initiated renegotiation of their [...]

Leave a Comment

What I Learned From Getting Hacked

In CPP’s June Podcast, we discussed a security breach that occurred a few years ago and the steps my team took to detect, respond and remediate the incident.  Here are the five things I learned from that breach.
1).  Planning your response to a disaster or security incident is just as important as the safeguards you [...]

Leave a Comment

201 CMR 17.00 – The 5 Things You Need to Do Right Now

As many of you are aware, the new Massachusetts Standards for the Protection of Personal information (201 CMR 17.00) will hit the books on January 1, 2010.  The law establishes protection standards to be met by persons who own, license, store or maintain personal information about a resident of the Commonwealth of Massachusetts in both [...]

Comments (1)

Third-Parties — Mass. Standards for the Protection of Personal Privacy

Important update.  The amended or revised 201 CMR 17.00 has softened the requirement for third-parties you do business with and that have access to personal data.  The original regulation slated for a May 1, 2009 compliance date stated that businesses would require “certification that such service provider has a written, comprehensive information security program that [...]

Leave a Comment

201 CMR 17.00 Postponed Until January 2010

The Massachusetts Office of Consumer Affairs and Business Regulation (OCABR) this week pushed back the compliance date for its Standards for the Protection for Personal Information from May 1, 2009 to January 1, 2010.  This is the second delay to the Mass. legislation which was initially scheduled for January 2009. 
The revision was filed on Thursday, [...]

Leave a Comment

Are You Ready For 201 CMR 17.00 – Massachusetts’ New Privacy Law Sets Strict Standards for the Protection of Personal Information

201 CMR 17.00 — Massachusetts’ New Privacy Law Sets Strict Standards for the Protection of Personal Information

Leave a Comment

Regulatory Compliance…When Will It End

Most of the clients that we work with are just starting to breathe a little more easy having put the appopriate compliance measures in place to statisfy the last regulation that was mandated.  SOX, PCI, state-specific data privacy acts, HIPAA, GBLA.  The undertone to all of these regulations is confidentiality, availability, and integrity and includes [...]

Comments (1)