2/1/08

Massachusetts Proposes Strict Data Security Measures, Including the Use of Encryption

The Massachusetts Office of Consumer Affairs and Business Regulation has released proposed regulations for implementing data security requirements contained in a Massachusetts breach notification law enacted last August. ... the Office was tasked with preparing regulations "to safeguard the personal information of [Massachusetts] residents." The proposed regulations interpret this mandate broadly. They would require any entity that holds personal information about a Massachusetts resident not only to develop and maintain a written information security program, but also to use a firewall, antispyware, and antivirus software, and physical access restrictions to protect the information. In addition, the regulations would require such entities to use strong encryption when transmitting personal information "across public networks," making Massachusetts the second state (after Nevada) to specifically require encryption. The Massachusetts regulations thus continue a significant trend toward governments' specifying the means that businesses must use to implement data security.

- The law: http://www.mass.gov/legis/laws/seslaw07/sl070082.htm
- The proposed regulation: http://www.mass.gov/?pageID=ocamodulechunk&L=1&L0=Home&sid=Eoca&b=terminalcontent&f=reg201cmr17&csid=Eoca

No comments: