7 ms·
If your database has Mass. residents, you need a security plan per Massachusetts
- AnneTheAgile 16y agoI do like the idea of encrypting user names across the wire, but "to maintain a Written Information Security Plan (WISP) and file it with the state of Massachusetts" goes way too far, imho. I am not a lawyer nor a database geek, so perhaps your take will differ... UPDATE: "Massachusetts does not require that written information security programs be filed at this time, just that they exist," according to a second article, http://www.informationweek.com/news/security/government/showArticle.jhtml?articleID=224400426 http://www.informationweek.com/news/security/government/show... . That is alot better.
- AnneTheAgile 16y agoFor reference, the law's URL, which was cited in slantyyz's reference, was out of date. Here is the current link; http://www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf http://www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf
- attylynn 16y agoThere is absolutely no need to "file" the WISP with the state. The WISP is an internal document that state officials would likely look for in the event of a data security incident (i.e., a breach or report of lost data such as a missing laptop).
- hga 16y agoUmmm, what's the legal theory that allows a US state to regulate out of state commerce like this? On the other hand, I wouldn't want to be a web company based in Massachusetts and this might have more than a small effect on the Boston area's attractiveness to many startups.
- tzs 16y agoThe big thing with regulation of commerce is that a state can't do it in a way that favors in-state merchants over out-of-state merchants. This law appears to treat in-state and out-of-state merchants equally, so might be OK as for as regulation of interstate commerce law is concerned. (And it might not--this is a tricky area of law).
- dangrossman 16y agoIt would be the US Constitution, where it gives all rights that are not explicitly enumerated to the states.
- ggchappell 16y ago"... or to the people." Let's not forget that. (Not that it's terribly relevant to your point.)
- tomjen3 16y agoTrue, but the commerce clause is enumerated in the constitution.
- andrewf 16y ago--article snip-- I could wax eloquently on about the potential battle of states’ rights versus federal oversight and the potential for a Supreme Court challenge based on the Commerce Clause, but, this is an article for geeks, so I won’t go there. Instead, I’ll simply say once again: yikes. --snip-- It seems silly to state legalities are out of scope when you're talking about a law, even if (or, especially if!) you're not writing for lawyers.
- slantyyz 16y agoThe title itself is a little FUD-ish. According to this link: http://www.leapfile.com/MA-201-CMR-17 http://www.leapfile.com/MA-201-CMR-17 , it only applies to the following subset of data: --snip-- According to the definitions in 201 CMR 17.02, personal information is a Massachusetts resident’s first name or first initial and last name IN COMBINATION with any one of more of the following data related to the person: social security number, driver’s license number or state-issued identification card number, financial account number, credit or debit card number with or without any required security or access code or password that would permit access to financial information. --snip--
- viraptor 16y agoWell - that's enough to make it relevant whenever there's a card transaction... that's going to affect a lot of people. This however "and perhaps the rest of the world" is complete FUD - noone outside of US cares about US state laws (unless you have some branch there of course - but then you already know you have a lot more paperwork to do).
- bobbyi 16y agoThere's no need to store any of those things in your database in order to allow card transactions.
- viraptor 16y agoUnless I misunderstood this, it affects you even if you only transfer the information to a 3rd party: 17.04: Every person that owns or licenses personal information about a resident of the Commonwealth and electronically stores or transmits such information... Also many online shops allow you to save the info in case you want to reuse it in the future.
- nostrademons 16y agoIf you're not storing the information, presumably you don't need to encrypt the data that you're not storing. You do need to encrypt it while transferring it (i.e. use https instead of http), but if you don't do this already, shame on you! Similarly, if you're storing credit card numbers in plaintext in a database, shame on you! That's worse than storing plain-text passwords. I think the worst parts of this law are the "you have to file with the Massachusetts government" aspects. The technical stuff is basically common-sense data security that everyone should already be doing.
- m104 16y agoAfter reading the law, I'm either missing the part where data has to be encrypted in all databases or (more likely) the article is misleading. As I read it, the data in question has to be encrypted during transmission (SSL, no big deal) or while stored on a portable device. Nowhere did I get the sense that a web application must maintain encrypted database records at all times.