<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Looking further into MA regulation 201 CMR 17.00</title>
	<atom:link href="http://slagwerks.com/blog/index.php/2008/10/22/looking-further-into-ma-regulation-201-cmr-1700/feed/" rel="self" type="application/rss+xml" />
	<link>http://slagwerks.com/blog/index.php/2008/10/22/looking-further-into-ma-regulation-201-cmr-1700/</link>
	<description></description>
	<lastBuildDate>Thu, 30 Jul 2009 15:44:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: joe</title>
		<link>http://slagwerks.com/blog/index.php/2008/10/22/looking-further-into-ma-regulation-201-cmr-1700/comment-page-1/#comment-8113</link>
		<dc:creator>joe</dc:creator>
		<pubDate>Fri, 24 Oct 2008 14:32:33 +0000</pubDate>
		<guid isPermaLink="false">http://slagwerks.com/blog/?p=150#comment-8113</guid>
		<description>Thanks, Tom. In particular, I found the table comparing the relevant standards helpful.</description>
		<content:encoded><![CDATA[<p>Thanks, Tom. In particular, I found the table comparing the relevant standards&nbsp;helpful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Cornelius</title>
		<link>http://slagwerks.com/blog/index.php/2008/10/22/looking-further-into-ma-regulation-201-cmr-1700/comment-page-1/#comment-8112</link>
		<dc:creator>Tom Cornelius</dc:creator>
		<pubDate>Thu, 23 Oct 2008 21:20:20 +0000</pubDate>
		<guid isPermaLink="false">http://slagwerks.com/blog/?p=150#comment-8112</guid>
		<description>The ramifications go beyond the potential fines from the law. Where this really will affect every business and organization is in terms of liability. If a business fails to comply with a known requirement (e.g. 201 CMR 17.00), that company can be found professionally negligent. Since it is easy to prove or disprove due care and due diligence by the fact there are quantifiable standards, a law as this makes it easy to hold a company accountable. Unfortunately for the company, if they are not compliant and a verdict is awarded, insurance will not cover the loss. This is unfamiliar to most business owners, since they do not equate non-compliance with their computer security with negligent behavior. This can easily put a business into bankruptcy.

Here is an interesting handout on the new law from MA and how it stacks up against other requirements such as HIPAA, SOX, GLBA, FACTA, and the PCI DSS. Check out: http://www.isecuritypolicy.com/pdf/commonwealth.pdf</description>
		<content:encoded><![CDATA[<p>The ramifications go beyond the potential fines from the law. Where this really will affect every business and organization is in terms of liability. If a business fails to comply with a known requirement (e.g. 201 <span class="caps">CMR</span> 17.00), that company can be found professionally negligent. Since it is easy to prove or disprove due care and due diligence by the fact there are quantifiable standards, a law as this makes it easy to hold a company accountable. Unfortunately for the company, if they are not compliant and a verdict is awarded, insurance will not cover the loss. This is unfamiliar to most business owners, since they do not equate non-compliance with their computer security with negligent behavior. This can easily put a business into bankruptcy.</p>
<p>Here is an interesting handout on the new law from <span class="caps">MA</span> and how it stacks up against other requirements such as <span class="caps">HIPAA</span>, <span class="caps">SOX</span>, <span class="caps">GLBA</span>, <span class="caps">FACTA</span>, and the <span class="caps">PCI</span> <span class="caps">DSS</span>. Check out:&nbsp;<a href="http://www.isecuritypolicy.com/pdf/commonwealth.pdf" rel="nofollow">http://www.isecuritypolicy.com/pdf/commonwealth.pdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gribley</title>
		<link>http://slagwerks.com/blog/index.php/2008/10/22/looking-further-into-ma-regulation-201-cmr-1700/comment-page-1/#comment-8110</link>
		<dc:creator>gribley</dc:creator>
		<pubDate>Thu, 23 Oct 2008 19:07:07 +0000</pubDate>
		<guid isPermaLink="false">http://slagwerks.com/blog/?p=150#comment-8110</guid>
		<description>Yeah, I was wondering about this too.  Does it have any relevance for a certain project we have worked on together?  I fear that it does...</description>
		<content:encoded><![CDATA[<p>Yeah, I was wondering about this too.  Does it have any relevance for a certain project we have worked on together?  I fear that it&nbsp;does&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
