90 likes | 127 Views
Understand roles, regulations, and guidelines for protecting sensitive information. Learn about laws, data breach requirements, and company policies to prevent unauthorized access.
E N D
Agenda • Overview • Why are we here? • Roles and responsibilities • Information Security Guidelines • Our Obligation • Has This Ever Happened to You? • Contract to Safeguard Sensitive Information • Wrap-up
Our Obligation: Laws and Regulations • Massachusetts data breach law/regulations • Definition of personal information • Obligation for notification when exposed • Data destruction requirements • Requirement to have written information security program (WISP) • Company policy • Privacy and disclosure of information • Information policies
Types of Sensitive Information Sensitive regulated information requiring notification Sensitive regulated information not requiring notification Sensitive information
Sensitive Regulated Information Requiring Notification Personal Information Requiring Notification • Social Security # • Credit Card # • Financial Account # • Driver’s License # Notification required ifthere was a potentialfor unauthorized use! Inform Information Security Team
Sensitive Regulated Information Not Requiring Notification • HIPAA (Health Insurance Portability and Accountability Act) • Information related to health status, provision of health care, or payment of health care • FMLA • Information related to Family & Medical Leave Act • FERPA • Student records Inform HR Information Security Team
Sensitive Information Date of birth Home address Salary information Performance/disciplinary information Other? Inform HR Information Security Team
Key Take-Aways • Massachusetts law and company policy impact how certain sensitive data are handled EVERYONE is responsible for compliance • Know what sensitive data you have • Develop good computing practices • Follow HR Information Security Guidelines • Report a potential breach to HR Information Security Team
Key Take-Aways • If you can’t protect it – don’t collect it • You can’t lose what you don’t have • Know what you have • You can’t protect what you don’t know you have