<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Joe's Amazing Technicolor Weblog &#187; Massachusetts</title>
	<atom:link href="http://slagwerks.com/blog/index.php/tag/massachusetts/feed/" rel="self" type="application/rss+xml" />
	<link>http://slagwerks.com/blog</link>
	<description></description>
	<lastBuildDate>Fri, 23 Jul 2010 22:31:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Does 201 CMR 17 apply to VOIP?</title>
		<link>http://slagwerks.com/blog/index.php/2010/05/13/does-201-cmr-17-apply-to-voip/</link>
		<comments>http://slagwerks.com/blog/index.php/2010/05/13/does-201-cmr-17-apply-to-voip/#comments</comments>
		<pubDate>Thu, 13 May 2010 17:46:58 +0000</pubDate>
		<dc:creator>joe</dc:creator>
				<category><![CDATA[Massachusetts]]></category>
		<category><![CDATA[Tech Stuff]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://slagwerks.com/blog/?p=368</guid>
		<description><![CDATA[Background: looking at going to a Voice Over IP phone system at work. Wondering if Massachusetts&#8217; new law about information security&#160;applies. Why it might not: a potential (MA based) vendor we&#8217;re talking to&#160;says We&#8217;ve not been asked this before and about 201 CMR 17 Compliance and I don&#8217;t particularly think it applies to our VoIP, or [...]]]></description>
			<content:encoded><![CDATA[<p>Background: looking at going to a Voice Over <span class="caps">IP</span> phone system at work. Wondering if Massachusetts&#8217; new law about information security&nbsp;applies.</p>
<p><strong>Why it might not:</strong> a potential (<span class="caps">MA</span> based) vendor we&#8217;re talking to&nbsp;says</p>
<blockquote><p>We&#8217;ve not been asked this before and about 201 <span class="caps">CMR</span> 17 Compliance and I don&#8217;t particularly think it applies to our VoIP, or VoIP in&nbsp;general</p></blockquote>
<p><strong>Why it might:</strong> Section 17.04 qualifies the applicability of the rule&nbsp;to</p>
<blockquote><p>Every person that owns or licenses personal information about a resident of the Commonwealth and electronically stores or transmits such information shall include&#8230;a security system covering its computers, including any wireless&nbsp;system</p></blockquote>
<p>Like just about any business, we definitely transmit personal information over our phone system, so I think the technical / legal question is whether an electronic phone system of the type in question is covered under the &#8220;its computers&#8221;&nbsp;phrase.</p>
<p>Stepping back from the legal to the practical, however, it seems fair to expect reasonable information security from our communications systems, including <span class="caps">VOIP</span>. At least in its intent, I think that&#8217;s what 201 <span class="caps">CMR</span> 17 is after. <span class="caps">VOIP</span> is still new enough that I suspect many prospective customers (like us!) aren&#8217;t quite sure what constitutes a reasonably secure installation, though we sense that there are all kinds of potential attack vectors not present in&nbsp;<span class="caps">POTS</span>.</p>
]]></content:encoded>
			<wfw:commentRss>http://slagwerks.com/blog/index.php/2010/05/13/does-201-cmr-17-apply-to-voip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>latest 201 CMR 17 hotness</title>
		<link>http://slagwerks.com/blog/index.php/2010/01/15/latest-201-cmr-17-hotness/</link>
		<comments>http://slagwerks.com/blog/index.php/2010/01/15/latest-201-cmr-17-hotness/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 13:54:48 +0000</pubDate>
		<dc:creator>joe</dc:creator>
				<category><![CDATA[Massachusetts]]></category>
		<category><![CDATA[Tech Stuff]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://slagwerks.com/blog/?p=342</guid>
		<description><![CDATA[You could be excused for having missed the news, but the 201 CMR 17 that was just about to go into effect over a year ago&#8230; is now just about to go into&#160;effect! some&#160;tidbits: 201 CMR may even apply to entities entirely outside of MA, as long as they have any data about Massholes in [...]]]></description>
			<content:encoded><![CDATA[<p>You could be excused for having missed the news, but the 201 <span class="caps">CMR</span> 17 that was just about to go into effect <a href="http://slagwerks.com/blog/index.php/2008/10/22/looking-further-into-ma-regulation-201-cmr-1700/">over a year ago</a>&#8230; is now <a href="http://www.hklaw.com/id24660/PublicationId2727/ReturnId31/contentid54375/">just about to go into&nbsp;effect</a>!</p>
<p>some&nbsp;tidbits:</p>
<ul>
<li>201 <span class="caps">CMR</span> may even <a href="http://arielsilverstone.com/library/201-cmr/">apply to entities entirely outside of <span class="caps">MA</span></a>, as long as they have any data about Massholes in their systems. So don&#8217;t get all smirky in Texas or&nbsp;wherever.</li>
<li>Who knew? Martha Coakley, as <span class="caps">AG</span>, gets credit for helping adjust 201 <span class="caps">CMR</span> to <a href="http://privacylaw.proskauer.com/tags/201-cmr-1700/">work better with business&#8217; realities</a>. That, and her Harpoon preference, really ought to be pushed more strongly by the&nbsp;campaign.</li>
<li>A useful collection of info can be found at <a href="http://201cmr17.com/">one of the ugliest websites in recent&nbsp;memory</a>.</li>
</ul>
<p>Fortunately, there doesn&#8217;t seem to be anything particularly unreasonable in the requirements, so organizations following good data security procedures shouldn&#8217;t have to do much work (if any) to be&nbsp;compliant.</p>
<ul></ul>
]]></content:encoded>
			<wfw:commentRss>http://slagwerks.com/blog/index.php/2010/01/15/latest-201-cmr-17-hotness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Looking further into MA regulation 201 CMR 17.00</title>
		<link>http://slagwerks.com/blog/index.php/2008/10/22/looking-further-into-ma-regulation-201-cmr-1700/</link>
		<comments>http://slagwerks.com/blog/index.php/2008/10/22/looking-further-into-ma-regulation-201-cmr-1700/#comments</comments>
		<pubDate>Wed, 22 Oct 2008 18:11:10 +0000</pubDate>
		<dc:creator>joe</dc:creator>
				<category><![CDATA[Massachusetts]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Tech Stuff]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://slagwerks.com/blog/?p=150</guid>
		<description><![CDATA[Thanks to MSCPA, I finally tracked down the Governor&#8217;s press release which, at first glance, has a reasonably clear description of the regulation&#8217;s intent. Also came across an analysis by Beth Israel&#8217;s CIO, a positive blurb from a Maine consultancy, and a brief mention by a MA payroll&#160;company. As for me, I still need to [...]]]></description>
			<content:encoded><![CDATA[<p>Thanks to <a href="http://www.mscpaonline.org/news/news_detail.php?news_id=118"><span class="caps">MSCPA</span></a>, I finally tracked down the <a href="http://www.mass.gov/?pageID=gov3pressrelease&amp;L=1&amp;L0=Home&amp;sid=Agov3&amp;b=pressrelease&amp;f=090822_identity_theft_prevention_executive_order&amp;csid=Agov3">Governor&#8217;s press release</a> which, at first glance, has a reasonably clear description of the regulation&#8217;s intent. Also came across <a href="http://geekdoctor.blogspot.com/2008/10/massachusetts-data-protection.html">an analysis by Beth Israel&#8217;s <span class="caps">CIO</span></a>, <a href="http://pdxmsp.typepad.com/my_weblog/2008/10/following-oregons-lead---massachusetts-201-cmr-1700.html">a positive blurb from a Maine consultancy</a>, and <a href="https://www.visionpayroll.com/kb/tag/201-cmr-1700/">a brief mention by a <span class="caps">MA</span> payroll&nbsp;company</a>.</p>
<p>As for me, I still need to do my official audit of our procedures vs. those specified by the&nbsp;regulation.</p>
]]></content:encoded>
			<wfw:commentRss>http://slagwerks.com/blog/index.php/2008/10/22/looking-further-into-ma-regulation-201-cmr-1700/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>new Massachusetts personal info requirements</title>
		<link>http://slagwerks.com/blog/index.php/2008/09/25/new-massachusetts-personal-info-requirements/</link>
		<comments>http://slagwerks.com/blog/index.php/2008/09/25/new-massachusetts-personal-info-requirements/#comments</comments>
		<pubDate>Thu, 25 Sep 2008 21:30:47 +0000</pubDate>
		<dc:creator>joe</dc:creator>
				<category><![CDATA[Massachusetts]]></category>
		<category><![CDATA[Tech Stuff]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://slagwerks.com/blog/?p=74</guid>
		<description><![CDATA[Networks Unlimited just sent out a note (thanks!) about the Mass Office of Consumer Affairs&#8217; new Standards for The Protection of Personal Information of Residents of the Commonwealth, aka 201 CMR 17.00: M.G.L. c. 93H. It outlines the responsibilities of anyone who gathers personal information on Mass residents. At a glance, they look pretty reasonable. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://networksunlimited.com">Networks Unlimited</a> just sent out a note (thanks!) about the Mass Office of Consumer Affairs&#8217; new<br />
<a href="http://www.mass.gov/?pageID=ocamodulechunk&amp;L=1&amp;L0=Home&amp;sid=Eoca&amp;b=terminalcontent&amp;f=idtheft_201cmr17&amp;csid=Eoca">Standards for The Protection of Personal Information of Residents of the Commonwealth</a>, aka 201 <span class="caps">CMR</span> 17.00: <span class="caps">M.G.L.</span> c. 93H. It outlines the responsibilities of anyone who gathers personal information on Mass residents. At a glance, they look pretty reasonable. From the&nbsp;intro:</p>
<blockquote><p>Every person that owns, licenses, stores or maintains personal information about a resident of the Commonwealth shall develop, implement, maintain and monitor a comprehensive, written information security program applicable to any records containing such personal&nbsp;information.</p></blockquote>
<p>It&#8217;ll be interesting to sit down with this <span class="amp">&amp;</span> see how our policies <span class="amp">&amp;</span> procedures match&nbsp;up.</p>
]]></content:encoded>
			<wfw:commentRss>http://slagwerks.com/blog/index.php/2008/09/25/new-massachusetts-personal-info-requirements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>This Saturday: Grassroots Use of Technology Conference</title>
		<link>http://slagwerks.com/blog/index.php/2008/06/23/this-saturday-grassroots-use-of-technology-conference/</link>
		<comments>http://slagwerks.com/blog/index.php/2008/06/23/this-saturday-grassroots-use-of-technology-conference/#comments</comments>
		<pubDate>Mon, 23 Jun 2008 16:23:25 +0000</pubDate>
		<dc:creator>joe</dc:creator>
				<category><![CDATA[Massachusetts]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[nonprofit]]></category>

		<guid isPermaLink="false">http://slagwerks.com/blog/?p=60</guid>
		<description><![CDATA[On my agenda this weekend is the &#8216;08 edition of the Grassroots Use of Technology conference, happening up in Lowell. I was a volunteer at the conference back in &#8216;04 and &#8216;05, but I&#8217;ve been out of town for the last&#160;couple. This year I&#8217;ll be wearing my IT Manager hat &#38; looking to pick people&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>On my agenda this weekend is the &#8216;08 edition of the <a href="http://organizerscollaborative.org/conference">Grassroots Use of Technology</a> conference, happening up in Lowell. I was a volunteer at the conference back in &#8216;04 and &#8216;05, but I&#8217;ve been out of town for the last&nbsp;couple.</p>
<p>This year I&#8217;ll be wearing my <a href="http://www.linkedin.com/in/joeslag"><span class="caps">IT</span> Manager</a> hat <span class="amp">&amp;</span> looking to pick people&#8217;s brains particularly about mass emailing, online donations, and fundraisining&nbsp;tools.</p>
]]></content:encoded>
			<wfw:commentRss>http://slagwerks.com/blog/index.php/2008/06/23/this-saturday-grassroots-use-of-technology-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hello, Peak Oil</title>
		<link>http://slagwerks.com/blog/index.php/2007/10/19/hello-peak-oil/</link>
		<comments>http://slagwerks.com/blog/index.php/2007/10/19/hello-peak-oil/#comments</comments>
		<pubDate>Fri, 19 Oct 2007 15:25:07 +0000</pubDate>
		<dc:creator>joe</dc:creator>
				<category><![CDATA[Massachusetts]]></category>
		<category><![CDATA[peak oil]]></category>

		<guid isPermaLink="false">http://slagwerks.com/blog/index.php/2007/10/19/hello-peak-oil/</guid>
		<description><![CDATA[Thursday was the fifth day in a row crude prices have set new&#160;records. &#8201;&#8212;&#8201;( extremely out-of-context quote from yahoo story on oil futures&#8217; first trip over $90 / barrel ) Heating oil prices not looking so good lately,&#160;either.]]></description>
			<content:encoded><![CDATA[<blockquote><p>Thursday was the fifth day in a row crude prices have set new&nbsp;records.</p></blockquote>
<p><em>&thinsp;&#8212;&thinsp;( extremely out-of-context quote from yahoo story on <a href="http://news.yahoo.com/s/ap/20071018/ap_on_bi_ge/oil_prices;_ylt=AruHFnuAVqfG6j2nA3x8eKSs0NUE">oil futures&#8217; first trip over $90 / barrel</a> )</em><br />
<a href="http://www.flickr.com/photos/18474854@N00/1636514364/" title="Photo Sharing"><img src="http://farm3.static.flickr.com/2258/1636514364_f45da820ae_m.jpg" alt="Mass Heating Oil prices, October 19 2007" align="right" height="192" width="240" /></a></p>
<p>Heating oil prices not looking so good lately,&nbsp;either.</p>
]]></content:encoded>
			<wfw:commentRss>http://slagwerks.com/blog/index.php/2007/10/19/hello-peak-oil/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The rest of the upcoming election</title>
		<link>http://slagwerks.com/blog/index.php/2006/10/25/the-rest-of-the-upcoming-election/</link>
		<comments>http://slagwerks.com/blog/index.php/2006/10/25/the-rest-of-the-upcoming-election/#comments</comments>
		<pubDate>Wed, 25 Oct 2006 19:13:14 +0000</pubDate>
		<dc:creator>joe</dc:creator>
				<category><![CDATA[Massachusetts]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[elections]]></category>

		<guid isPermaLink="false">http://slagwerks.com/blog/?p=4</guid>
		<description><![CDATA[I have nothing further to add about the high profile portions of the upcoming Massachusetts election. My thoughts about the less widely covered&#160;parts: Green-Rainbow endorsed Jill Stein for Secretary of State, because the person in charge of state elections ought to show up for his own&#160;debates. The brand-new Working Families party endorsed Rand Wilson for [...]]]></description>
			<content:encoded><![CDATA[<p>I have nothing further to add about the high profile portions of the upcoming Massachusetts election. My thoughts about the less widely covered&nbsp;parts:</p>
<p>Green-Rainbow endorsed <a href="http://en.wikipedia.org/wiki/Jill_Stein">Jill Stein</a> for Secretary of State, because the person in charge of state elections <a href="http://www.leftinlowell.com/2006/09/01/galvin-a-no-show-in-worcester/">ought to show up for his own&nbsp;debates</a>.</p>
<p>The brand-new Working Families party endorsed <a href="http://en.wikipedia.org/wiki/Rand_Wilson">Rand Wilson</a> for Auditor. Fascinating interview with Wilson&nbsp;<a href="http://www.jessekb.com/2006/09/28/future-of-voting-in-massachusetts-part-iii-rand-wilson-for-state-auditor/">here</a>.</p>
<p>On a related topic, I&#8217;m voting yes on question two. Good discussion in the interview above; an example of how it&#8217;s worked in New York&nbsp;<a href="http://www.massballotfreedom.com/newyork">here</a>.</p>
<p>Also voting yes on question three, for <a href="http://www.leftinlowell.com/2006/10/23/yes-on-question-three/">these&nbsp;reasons</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://slagwerks.com/blog/index.php/2006/10/25/the-rest-of-the-upcoming-election/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
