<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Joe's Amazing Technicolor Weblog &#187; privacy</title>
	<atom:link href="http://slagwerks.com/blog/index.php/tag/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://slagwerks.com/blog</link>
	<description></description>
	<lastBuildDate>Fri, 23 Jul 2010 22:31:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Does 201 CMR 17 apply to VOIP?</title>
		<link>http://slagwerks.com/blog/index.php/2010/05/13/does-201-cmr-17-apply-to-voip/</link>
		<comments>http://slagwerks.com/blog/index.php/2010/05/13/does-201-cmr-17-apply-to-voip/#comments</comments>
		<pubDate>Thu, 13 May 2010 17:46:58 +0000</pubDate>
		<dc:creator>joe</dc:creator>
				<category><![CDATA[Massachusetts]]></category>
		<category><![CDATA[Tech Stuff]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://slagwerks.com/blog/?p=368</guid>
		<description><![CDATA[Background: looking at going to a Voice Over IP phone system at work. Wondering if Massachusetts&#8217; new law about information security&#160;applies. Why it might not: a potential (MA based) vendor we&#8217;re talking to&#160;says We&#8217;ve not been asked this before and about 201 CMR 17 Compliance and I don&#8217;t particularly think it applies to our VoIP, or [...]]]></description>
			<content:encoded><![CDATA[<p>Background: looking at going to a Voice Over <span class="caps">IP</span> phone system at work. Wondering if Massachusetts&#8217; new law about information security&nbsp;applies.</p>
<p><strong>Why it might not:</strong> a potential (<span class="caps">MA</span> based) vendor we&#8217;re talking to&nbsp;says</p>
<blockquote><p>We&#8217;ve not been asked this before and about 201 <span class="caps">CMR</span> 17 Compliance and I don&#8217;t particularly think it applies to our VoIP, or VoIP in&nbsp;general</p></blockquote>
<p><strong>Why it might:</strong> Section 17.04 qualifies the applicability of the rule&nbsp;to</p>
<blockquote><p>Every person that owns or licenses personal information about a resident of the Commonwealth and electronically stores or transmits such information shall include&#8230;a security system covering its computers, including any wireless&nbsp;system</p></blockquote>
<p>Like just about any business, we definitely transmit personal information over our phone system, so I think the technical / legal question is whether an electronic phone system of the type in question is covered under the &#8220;its computers&#8221;&nbsp;phrase.</p>
<p>Stepping back from the legal to the practical, however, it seems fair to expect reasonable information security from our communications systems, including <span class="caps">VOIP</span>. At least in its intent, I think that&#8217;s what 201 <span class="caps">CMR</span> 17 is after. <span class="caps">VOIP</span> is still new enough that I suspect many prospective customers (like us!) aren&#8217;t quite sure what constitutes a reasonably secure installation, though we sense that there are all kinds of potential attack vectors not present in&nbsp;<span class="caps">POTS</span>.</p>
]]></content:encoded>
			<wfw:commentRss>http://slagwerks.com/blog/index.php/2010/05/13/does-201-cmr-17-apply-to-voip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>new Massachusetts personal info requirements</title>
		<link>http://slagwerks.com/blog/index.php/2008/09/25/new-massachusetts-personal-info-requirements/</link>
		<comments>http://slagwerks.com/blog/index.php/2008/09/25/new-massachusetts-personal-info-requirements/#comments</comments>
		<pubDate>Thu, 25 Sep 2008 21:30:47 +0000</pubDate>
		<dc:creator>joe</dc:creator>
				<category><![CDATA[Massachusetts]]></category>
		<category><![CDATA[Tech Stuff]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://slagwerks.com/blog/?p=74</guid>
		<description><![CDATA[Networks Unlimited just sent out a note (thanks!) about the Mass Office of Consumer Affairs&#8217; new Standards for The Protection of Personal Information of Residents of the Commonwealth, aka 201 CMR 17.00: M.G.L. c. 93H. It outlines the responsibilities of anyone who gathers personal information on Mass residents. At a glance, they look pretty reasonable. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://networksunlimited.com">Networks Unlimited</a> just sent out a note (thanks!) about the Mass Office of Consumer Affairs&#8217; new<br />
<a href="http://www.mass.gov/?pageID=ocamodulechunk&amp;L=1&amp;L0=Home&amp;sid=Eoca&amp;b=terminalcontent&amp;f=idtheft_201cmr17&amp;csid=Eoca">Standards for The Protection of Personal Information of Residents of the Commonwealth</a>, aka 201 <span class="caps">CMR</span> 17.00: <span class="caps">M.G.L.</span> c. 93H. It outlines the responsibilities of anyone who gathers personal information on Mass residents. At a glance, they look pretty reasonable. From the&nbsp;intro:</p>
<blockquote><p>Every person that owns, licenses, stores or maintains personal information about a resident of the Commonwealth shall develop, implement, maintain and monitor a comprehensive, written information security program applicable to any records containing such personal&nbsp;information.</p></blockquote>
<p>It&#8217;ll be interesting to sit down with this <span class="amp">&amp;</span> see how our policies <span class="amp">&amp;</span> procedures match&nbsp;up.</p>
]]></content:encoded>
			<wfw:commentRss>http://slagwerks.com/blog/index.php/2008/09/25/new-massachusetts-personal-info-requirements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
