Please do not leave this page until complete. This can take a few moments.
A written information security policy, or WISP, is vital. Make sure there's a person in charge of enforcing it.
Sensitive data, especially personally identifiable information, must be encrypted at all times, from the server, to the cloud, to a laptop or USB drive.
Simply having a firewall isn't enough – it needs to be kept up-to-date, and you should consider unified threat management (UTM).
You need to have up-to-date protection against malware, and the latest patches and virus definitions to guard against intrusion. Implement an update schedule.
It's not enough to have systems and policies; you must also educate staff and boost user awareness. Employees should be trained and sign off on security awareness at least annually.
Make sure security expectations are clear in your contracts, and always perform due diligence.
Make sure employees only have access to data that's vital for them to perform their duties.
View this as a continuous process, not a finite task. You must review your security procedures at least once a year to ensure they're up to the task.
If you're resisting the allocation of proper security resources, you should be aware that the state will levy serious fines for compromising regulations.
Just because you have complied with the regulation doesn't guarantee your data is safe. It's a solid foundation for the information security program you should continue to build.
(NOTE: A Massachusetts regulation places responsibility on businesses for protecting consumers' personal information).
Michelle Drolet is founder of Towerwall, a data security services provider in Framingham. Contact her at michelled@towerwall.com.
Stay connected! Every business day, WBJ Daily Report will be delivered to your inbox by noon. It provides a daily update of the area’s most important business news.
Sign upWorcester Business Journal provides the top coverage of news, trends, data, politics and personalities of the Central Mass business community. Get the news and information you need from the award-winning writers at WBJ. Don’t miss out - subscribe today.
SubscribeWorcester Business Journal presents a special commemorative edition celebrating the 300th anniversary of the city of Worcester. This landmark publication covers the city and region’s rich history of growth and innovation.
See Digital EditionStay connected! Every business day, WBJ Daily Report will be delivered to your inbox by noon. It provides a daily update of the area’s most important business news.
Worcester Business Journal provides the top coverage of news, trends, data, politics and personalities of the Central Mass business community. Get the news and information you need from the award-winning writers at WBJ. Don’t miss out - subscribe today.
Worcester Business Journal presents a special commemorative edition celebrating the 300th anniversary of the city of Worcester. This landmark publication covers the city and region’s rich history of growth and innovation.
In order to use this feature, we need some information from you. You can also login or register for a free account.
By clicking submit you are agreeing to our cookie usage and Privacy Policy
Already have an account? Login
Already have an account? Login
Want to create an account? Register
In order to use this feature, we need some information from you. You can also login or register for a free account.
By clicking submit you are agreeing to our cookie usage and Privacy Policy
Already have an account? Login
Already have an account? Login
Want to create an account? Register
This website uses cookies to ensure you get the best experience on our website. Our privacy policy
To ensure the best experience on our website, articles cannot be read without allowing cookies. Please allow cookies to continue reading. Our privacy policy
0 Comments