Showing posts with label Mass. General Law 93H. Show all posts
Showing posts with label Mass. General Law 93H. Show all posts

March 12, 2010

GraVoc Website Updates

The last week has brought some changes to the GraVoc website.  The transformation of the GraVoc Software website (http://www.gravocsoftware.com) is now complete and much easier to navigate and get information on the software products offered by the company. 

Some of the products offered include the GFS field service management platform, several utilities to integrate into Microsoft Dynamics GP, and the versatile GCMS cemetery and crematory management application for GraVoc’s many clients in the death care industry.

Also new to the GraVoc website is a case study regarding GraVoc’s Massachusetts General Law 93-H services.  GraVoc’s information security team launched a recent project to help a client comply with the standards presented by the Massachusetts Data Security Law.

To access this case study and to learn more about GraVoc’s Mass. Data Security Law services, please click here.

GraVoc Associates, Inc, founded in 1994 and based in Peabody, MA, serves the Greater Boston area, New England, and beyond in the practices of information systems, information security, and professional services.  We strongly encourage you to explore the revamped GraVoc website, available at http://www.gravoc.com, in its entirety to learn more about the company and what it can do for your business.

February 19, 2010

93H: There Is A Reason For This

As the deadline for compliance with the Massachusetts Data Security Law approaches (March 1st is now two weeks away), many businesses are undoubtedly looking at the new burdens that are being thrown at them and wondering if it’s necessary.  Perhaps the Massachusetts legislature got bored one day and decided to inconvenience businesses by requiring them to write information security policies and implement safeguards.  Maybe they have friends in the encryption or consulting industries.  But a recent report has given further evidence to what many already knew:  Identity theft is a growing problem and businesses that handle people’s sensitive information should make efforts to make sure that if this data is stolen, they are not the ones responsible for it.

A research group concluded there were over 11 million US identity fraud victims in 2010, a 12-percent increase perhaps caused by bad economic times (hat tip to the ISMG).  Surprisingly, over two-thirds of this crime was executed using non-technical methods, emphasizing that identity theft prevention is not specifically an IT burden.  This growing crime cost victims $54 billion in 2010.  By comparison, ID theft victims lost three times what all of Bernie Madoff’s victims lost during Madoff’s entire career.

GraVoc Associates, Inc’s information security team, which has worked primarily with the highly-regulated financial services industry in the past, has begun to work with non-financial clients with Massachusetts Data Security Law (M.G.L. 93H or 201 CMR 17.00) compliance services.  A free on-demand webinar has been recorded and distributed to existing GraVoc clients, and will be made available on GraVoc.com later on this week.  The standards required by this law, while they are not nearly as aggressive as they were when originally penned, can require a lot of work, and many businesses have gone to GraVoc for advisory and help with compliance with this law.

GraVoc Associates, founded in 1994, provides a wide range of solutions in the fields of information security, information systems, and professional services.  The GraVoc News Blog has been following developments regarding the Mass. Data Security Law since the blog’s inception in 2008, and you may find value in perusing the archives for more information.  For additional information about GraVoc’s services in all three fields, we strongly encourage you to browse GraVoc.com.

August 31, 2009

Mass. Law: No Longer Strongest In Country?

Last week, the Massachusetts Office of Consumer Affairs and Business Regulation decided to issue a revised version of 201 CMR 17.00, the regulation that outlines and enforces compliance to M.G.L. 93H.  Not only did the OCABR delay the effective date for a third time, but saying the changes in the language have “softened” the aggressive nature of the law would be an understatement.

While this is good news for the smaller enterprises, such as a business that only stores personal information of its six employees or small businesses that don’t have thousands upon thousands of dollars to spend on some of the physical and technical safeguards prescribed by the old version of the regulation, information security experts (such as the ones who wrote scathing indictments of the changes here and here) argue that this regulation has been softened to the point that is rendered worthless.  One of the authors wrote that retail firm TJX would have been compliant with this regulation when they experienced the data breach that inspired it.

Highlights from the changes:

  • Perhaps the most significant change is the removal of the personal information inventory piece.  This may have been the most cumbersome and unrealistic part of the regulations, but also may have been the most important.  It is difficult to protect information if you don’t know where it is.  Other states already do require the personal information inventory in their data protection laws.
  • Words like “reasonable” and “technically feasible” permeate the new version of the document, while they were used very sparingly in the old version.  Information safeguards, including encryption password strength, and the installation of virus definitions, security patches, and firewall protection, previously had specific standards to be in compliance with the law.  The new standards use the “reasonable” and “technically feasible” terminology.  As it may ease small businesses’ financial burden, these words are certainly vague and open to interpretation.
  • The Frequently Asked Questions that accompany the document on the Massachusetts OCABR website further illuminate the problems with the use of these terms.  The FAQs state that email messages with personal information do not need to be encrypted if the process is not “technically feasible,” for example.  A noncompliant business can readily answer to authorities simply by saying “I did not find this safeguard to be technically feasible.”  
  • The language of the regulation removes accountability for those who “store or maintain” personal information.  This would suggest that if a company keeps its records at a hosted storage facility or with a service bureau, the vendor is no longer responsible for this information.  Other provisions regarding vendor management are similarly weakened or taken out completely—a contract including compliance is required but enforcement of a vendor’s compliance is no longer documented.
  • Compliance as an ongoing process is also put into question with the changes.  There is no longer language regarding assessing risk associated with information, processes, or applications and putting in appropriate safeguards.  Language requiring monitoring the effectiveness is also removed. 
  • Similarly, thorough investigation of any network intrusions were previously mandated by the regulation.  They are no longer explicitly required unless unless they result in a data breach.  A business no longer has to report or document any unauthorized physical access to computer systems.  Restricting access to systems, such as server rooms, is also completely eradicated from the document.
  • Language regarding employee access to personal information is substantially less stringent.  Language regarding limiting access to those with a “need to know” is eradicated and the word “immediately” has been removed from the part requiring companies to revoke physical and electronic access to records when an employee leaves the organization.

There are six months left before the revised compliance deadline.  With the revised provisions in the regulations, compliance is much more achievable.  However, compliance with these weakened regulations might not be enough to keep information safe anymore.

GraVoc Associates, Inc, located in Peabody, MA, is celebrating fifteen years in the practices of information security, information systems, and technology and professional consulting.  For more information on GraVoc’s compliance services aligned with the Massachusetts Data Protection Law, please contact GraVoc at 978-538-9055 or visit the GraVoc website at http://www.gravoc.com.  More information on this law has been covered in the GraVoc News Blog, so by clicking “Massachusetts Data Protection Law” below is also a useful source of information.

August 21, 2009

Mass. Data Protection Law Delayed, Softened

Earlier this week, the Massachusetts Office of Consumer Affairs and Business Regulations (OCABR) made the decision to delay the effective date of the Massachusetts Data Protection Law (also known as MGL 93H or 201 CMR 17.00) for the fourth time.  Businesses are expected to be in compliance with this law, which is designed to protect Massachusetts residents from identity theft, by March 1, 2010.

The original effective date of this law was January 1, 2009.  It was delayed until May 1, 2009 late last year, and in February it was moved back to January 1, 2010. 

The provisions and standards of data protection have also been amended.  While the law is still perhaps the most aggressive in the country, compliance is much more attainable with the revised provisions.  The amended law can be read in PDF format here.

This announcement can be interpreted many ways.  A pessimist may look at it in a way that the effective date may never come and that Massachusetts is writing this law for a public relations purpose.  Optimists may view the four separate delays and significant amendments to the regulation as a gesture by the state saying that they are listening and they understand the needs and limitations of small businesses.  It could possibly be indicative that the state and the OCABR are serious about enforcing compliance, so they are making changes so that compliance is actually a possibility for businesses.

This news will be covered in more depth on the GraVoc News Blog towards the end of next week.

GraVoc Associates, Inc., based in Peabody, MA, is celebrating fifteen years in Greater Boston.  GraVoc works with a variety of different clients in several sectors, providing services in the practices of information security, technology and professional services, and information systems.  GraVoc’s information security team has several years’ experience serving the highly-regulated financial services industry, and is committed to helping clients from any industry comply with the Massachusetts Data Protection Law.  For more information about GraVoc and its M.G.L. 93H compliance services, please visit GraVoc.com.

July 16, 2009

Massachusetts Data Protection Law: Encryption Standards

As the deadline for compliance with the Massachusetts Data Protection Law (MGL 93H & 201 CMR 17.00) rapidly approaches, many companies will be looking for information on what they have to do in order to achieve compliance with the regulations that are more aggressive than the “game-chang[ing]” law passed in Nevada.

The part of the law that has garnered the most attention is its emphasis on encrypting personal information.  For the sake of reference, the encryption-related requirements are printed below:

  • “To the extent technically feasible, encryption of all transmitted records and files containing personal information that will travel across public networks, and encryption of all data containing personal information to be transmitted wirelessly.”
  • “Encryption of all personal information stored on laptops or other portable devices.”

Source:  Mass.gov

Simply stated, encryption is a technical provision that makes it very difficult for an unauthorized individual to access electronic information.  Encryption is especially important with email transmission (in the case that the email is intercepted over a public network) and with portable devices such as laptops, PDAs, and flash drives (which are easily lost or stolen).

Peabody, MA-based GraVoc Associates, celebrating fifteen years of business in Greater Boston, New England, and beyond, understands that the encryption standard especially is an unusual burden for businesses that don’t typically have to concern themselves with detailed information security governance.  GraVoc’s information security personnel have been following the evolution of the Massachusetts Data Protection Law for several months, demonstrating their commitment to help both new and existing clients comply with this challenging law with appropriate procedures and products.  For more information about MGL-93H services, as well as more information about GraVoc’s services in their other practices of information systems and financial and professional consulting, please visit GraVoc.com.

July 13, 2009

Mass. Data Protection Deadline: Less than Six Months Away

The Massachusetts Data Protection Law, sometimes referred to as Massachusetts General Law 93H & I or 201 CMR 17.00, goes into effect on January 1, 2010, and the general consensus is that the effective date is NOT going to be delayed for a third time. This law requires all companies with “personal information” pertaining to a Massachusetts resident to have a comprehensive written information security policy. It also requires companies with any personal information to undergo reasonably-daunting efforts to protect both paper and electronic files to prevent a data breach.

“Personal information” is defined as a person’s name or first initial and last name in conjunction with a social security number, a government issued ID number, a driver’s license number, or a financial account number (including credit and debit card number). This covers both customer information and employee information, so virtually every business in the state will have to comply with this law.

The many provisions required by this aggressive law include procedural controls, physical controls, and technological controls. Among the more challenging measures to be mandated under this law are the following:

  • A comprehensive, written information security policy regarding the protection of information both in physical and electronic forms.
  • A vendor management program that ensures that all vendors, service providers, and contractors with access to personal information are also taking adequate measures to curb identity theft and data breaches and to become compliant with this law.
  • Higher levels of physical information protection, such as the use of locked containers and the employment of locked facilities.
  • Challenging standards for electronic data protection, including the encryption of hard drives and portable devices like laptops, PDAs, and flash drives that contain personal information.

As this law sets very high standards and expectations and threatens to levy strict fines against noncompliant businesses, small and midsized businesses may not know where to turn. GraVoc’s information security team has been monitoring the law’s provisions and its evolution over the past year.  GraVoc is committed to helping clients comply with this law and proactively quell the risk of data breaches and identity theft.

GraVoc Associates, Inc, a full-service consulting firm based in Peabody, MA, is celebrating 15 years of business in Greater Boston and throughout New England. GraVoc offers a wide range of services in the fields of information security, information systems, and technology and financial services, including Massachusetts Data Protection Law compliance services. For more information on GraVoc’s information security work in the highly-regulated financial industry or more information about 93H compliance services, please visit GraVoc.com.

March 4, 2009

New MGL 93-H Deadline: January 1, 2010

The Massachusetts Office of Consumer Affairs and Business Regulation (OCABR) has again pushed back the date at which the new Massachusetts General Law 93-H goes into effect. The new date is January 1, 2010.

MGL 93-H is better known as the "Massachusetts Data Protection Law."

A press release from the OCABR is available here.

Massachusetts General Laws 93-H and 93-I are generally considered the toughest laws in the nation regarding identity theft prevention. This law requires businesses containing either paper or electronic files with personal identifiable information to have a comprehensive information security policy. The specification of the information security policy are available in PDF format here.

Governor Deval Patrick announced the impending enforcement of this law last fall and GraVoc Associates, Inc. was one of the first firms to address the law’s tough standards. Starting in November, GraVoc began offering services to help small businesses safeguard its customers’ and employees’ personal information and comply with MGL 93-H. Since, the OCABR has given businesses more time to undertake 93-H compliance efforts, pushing back the January 1, 2009 deadline to May 1, 2009, and now to January 1, 2010.

GraVoc Associates, Inc, a full-service consulting firm based in Peabody, MA, is celebrating 15 years of business in Greater Boston and throughout New England. A versatile business, GraVoc offers a wide range of services in the fields of information systems, information technology, financial services, and information security. For more information on GraVoc, please visit GraVoc.com or call GraVoc’s offices at 978-538-9055.

February 18, 2009

Personal Identifiable Information Defined

A hot-button issue in information security right now is "personal identifiable information," especially as the May 1st deadline for Massachusetts General Law 93-H (also known as the Massachusetts Data Protection Law) approaches. The law states that any business possessing "personal information" of any Massachusetts resident, including customers, employees, and the like, is required to have a comprehensive information security program, among other provisions outlined in GraVoc's MGL 93-H quick link.

Personal identifiable information, as defined in MGL 93-H is a resident's first name and last name or first initial and last name along with:
  • The person's social security number.
  • The person's driver's license or state-issued identification card number.
  • The person's financial account number, with or without any access codes or passwords that provide access to the person's financial account.

In other fields, including forensics, personal identifiable information is defined with a broader scope; this definition is strictly for the purposes of MGL 93-H governance.

The quick link available above describes the range of services GraVoc can provide to help your business comply with MGL 93-H. However, the most popular service as of this point is the personal identifiable information (PII) inventory, where GraVoc professionals conduct interviews with your business's personnel, determining where PII is collected and how it is stored both electronically and physically.

Based in Peabody, Massachusetts, GraVoc Associates, Inc. is celebrating its fifteenth anniversary helping small businesses and financial institutions find solutions in the fields of information security information technology, and beyond. To learn more about GraVoc's services regarding MGL 93-H compliance, please consult the new http://www.gravoc.com/ or call GraVoc's office at 978-538-9055.

November 18, 2008

MGL 93H Deadline Extended

On Friday November 14th, the Massachusetts Office of Consumer Affairs and Business Regulations announced that the compliance deadlines for Massachusetts General Law 93H (Massachusetts Data Protection Law) would be extended. Under the former provisions, businesses had to adhere to new identity theft prevention regulations by January 1, 2009. The deadline has now been extended to May 1, 2009. For more information on MGL 93H and how GraVoc can help your business stay compliant, please click on the MGL 93H Quick Link.


November 7, 2008

MGL-93H

We're excited to announce that we will be offering services to help your business comply with Massachusetts General Law Chapter 93 H. Check back for more news or contact us today at (978) 538-9055.