Best Practices for Data Security and Protecting

Published  . 0 views
↓ Download
Best Practices for Data Security and Protecting
1 / 1
Best Practices for Data Security and Protecting - slide 1 of 31 Best Practices for Data Security and Protecting - slide 2 of 31 Best Practices for Data Security and Protecting - slide 3 of 31 Best Practices for Data Security and Protecting - slide 4 of 31 Best Practices for Data Security and Protecting - slide 5 of 31 Best Practices for Data Security and Protecting - slide 6 of 31 Best Practices for Data Security and Protecting - slide 7 of 31 Best Practices for Data Security and Protecting - slide 8 of 31 Best Practices for Data Security and Protecting - slide 9 of 31 Best Practices for Data Security and Protecting - slide 10 of 31 Best Practices for Data Security and Protecting - slide 11 of 31 Best Practices for Data Security and Protecting - slide 12 of 31 Best Practices for Data Security and Protecting - slide 13 of 31 Best Practices for Data Security and Protecting - slide 14 of 31 Best Practices for Data Security and Protecting - slide 15 of 31 Best Practices for Data Security and Protecting - slide 16 of 31 Best Practices for Data Security and Protecting - slide 17 of 31 Best Practices for Data Security and Protecting - slide 18 of 31 Best Practices for Data Security and Protecting - slide 19 of 31 Best Practices for Data Security and Protecting - slide 20 of 31 Best Practices for Data Security and Protecting - slide 21 of 31 Best Practices for Data Security and Protecting - slide 22 of 31 Best Practices for Data Security and Protecting - slide 23 of 31 Best Practices for Data Security and Protecting - slide 24 of 31 Best Practices for Data Security and Protecting - slide 25 of 31 Best Practices for Data Security and Protecting - slide 26 of 31 Best Practices for Data Security and Protecting - slide 27 of 31 Best Practices for Data Security and Protecting - slide 28 of 31 Best Practices for Data Security and Protecting - slide 29 of 31 Best Practices for Data Security and Protecting - slide 30 of 31 Best Practices for Data Security and Protecting - slide 31 of 31
Description: Best Practices for Data Security and Protecting Personal Information MCLE March 2017 Presenter Matthew Pettine, CGEIT, CISA, ASE, MCSE, MCDBA, MBA Managing Director, IT Advisory Practice MFA Cornerstone Consulting (978) 557-5354

Related Topics

Download Presentation

"Best Practices for Data Security and Protecting" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Best Practices for Data Security and Protecting Personal Information

MCLE – March 2017<br>
slide2. Presenter Matthew Pettine, CGEIT, CISA, ASE, MCSE, MCDBA, MBA
Managing Director, IT Advisory Practice
MFA Cornerstone Consulting
(978) 557-5354
mpettine@mfacornerstone.com Page 2 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide3. About MFA Proactive CPA and consulting firm with national and global reach
Founded in 1982
Over 150 professionals, including 25 partners
Located in Tewksbury, Massachusetts Page 3 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide4. About MFA Business Tax
Individual, Family and Fiduciary Tax
State and Local Tax
Audit and Assurance
Technical Accounting Advisory
Transaction Services
Valuation
Litigation Support Fraud and Forensic Accounting
Business Performance Enhancement
Sarbanes-Oxley Compliance
Internal Controls
IT Advisory
Wealth Management
Retirement Plan Advisory
Professional Staffing Page 4 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide5. Some Privacy and Electronic Data Regulations Health Information Privacy Accountability Act (HIPAA)
Health Information Technology for Economic and Clinical Health (HITECH)
Financial Service Modernization Act (Graham-Leach-Bliley GLBA)
Family Educational Rights and Privacy Act of 1974 (FERPA)
FTC – Fair and Accurate Credit Transactions Act (FACTA) Red Flags Rule
Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 (CAN-SPAM Act)
Massachusetts Privacy Regulations: 201 CMR 17
PCI -DSS (Payment Card Industry – Data Security Standards) Page 5 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide6. Common Themes Physical, Technical and Administrative Controls
Protection against unauthorized access or disclosure
Notification Requirements
Written Policies
Training
Business Process Development and Monitoring

Enforcement and Penalties! Page 6 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide7. Massachusetts Privacy Regulations: 201 CMR 17 Law is designed to protect the personal information of Massachusetts citizens

Intent of law is to prevent personal information from being breached in the first place

As opposed to merely addressing what must happen in the wake of a security breach

Establishes minimum standards, responsibilities and reporting protocol Page 7 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide8. Massachusetts Personal Data Security Law Personal information to be protected includes:
A citizen’s name (first & last or first initial & last name) COMBINED with one or more of the following:

Credit card number
Social security number
Financial account number
State issued identification number Page 8 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide9. Applies to individuals and businesses that own, license, store or maintain “personal information” about a citizen of Massachusetts

HR Departments – I9s, background checks, direct deposits, health and life insurance, 401(k)s
Finance Departments – third-party vendors and sole proprietors
Dealing directly with credit card-based retail sales
Real estate, mortgage and investments Massachusetts Personal Data Security Law Page 9 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide10. Failure to Comply If an information breach occurs, and no prescribed information security efforts were in place – companies may be subject to both criminal and civil penalties

Fines established under Massachusetts General Law 93H-93I

Very specific public notification requirements

Damage to reputation if security breach occurs

Significant time, resources and costs required to properly handle a security breach Page 10 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide11. Becoming Compliant Page 11 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide12. Steps to Achieve Compliance Organizational Risk Assessment
Create a Written Information Security Plan (WISP)
Computer system security
Vendor management
Training employees
Monitoring protocols Page 12 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide13. Step 1: Risk Assessment Identify where sensitive information is handled and stored within the business
Identify potential risks
Evaluate controls relative to existing risks
Gap analysis and remediation plan Page 13 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide14. Step 2: Create a Written Information Security Plan (WISP) Designate a security coordinator
Document information flows
Document general computer controls
Develop organizational policies
Develop employee consequences for non-adherence Page 14 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide15. Step 3: Computer System Security Regulations include specific requirements related to computer system security

Authentication – Encryption
Access Controls – Firewalls & OS Patches
Data Transmission – Viruses & Malware
Monitoring – Training Page 15 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide16. Step 3: Computer System Security (Continued) Authentication

Control of User Accounts

“Control of IDs”
“Reasonably secure passwords”
Control of password security
Restrict access to active users
Block access after multiple attempts Page 16 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide17. Step 3: Computer System Security (Continued) Access Controls

Restrict access to those who “need to know” to perform their jobs

File system security / permissions
Third-party tools available

Assign IDs and passwords

Unique (not shared)
“Not vendor supplied defaults” Page 17 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide18. Step 3: Computer System Security (Continued) Data Transmission
Encryption of transmitted data

“Where technically feasible”
Web Sites (SSL / https)
Email (PGP / 3rd party services)
Remote Access Solutions
Online Service Providers
Wireless (“All Data”) Page 18 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide19. Step 3: Computer System Security (Continued) Monitoring

“Reasonable monitoring of systems for unauthorized use of or access to personal information”

Intrusion Detection
Application Logs
Server Firewalls
Network Security Logs
File System Auditing Page 19 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide20. Step 3: Computer System Security (Continued) Encryption of Personal Information Stored on Portable Devices

Laptops

Encryption vs. Passwords
File-based vs. Entire Laptop
Operating System vs. Third Party Solutions
“Other Devices”

Portable Hard Drives (USB devices)
Backup Media
CDs, DVDs, iPhones, PDAs Page 20 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide21. Step 3: Computer System Security (Continued) Firewalls & OS Patches

Firewall Protection

“Reasonably up-to-date”
Vendor supported and routinely updated

Operating System Security Patches

Automatic update features
Servers & workstations
User considerations Page 21 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide22. Step 3: Computer System Security (Continued) Viruses & Malware

“Reasonably up-to-date versions”
“Must include malware protection”
Supported by vendor

Up-to-date patches and definitions
“Set to receive the most current security updates on a regular basis” Page 22 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide23. Step 3: Computer System Security (Continued) “Education and training of employees on the proper use of the computer security system and the importance of personal information security.”

New hire orientation
Specific routine organizational efforts Page 23 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide24. Step 4: Assessing 3rd Party Vendors Must ensure that third party providers have the capacity to protect personal information you give them access to
Payroll providers
Health insurance broker
Background check provider
401(k) provider
Online/Cloud Service providers
Cleaners & disposal crews
Conduct due diligence
Make safeguards a condition of your contract with them Page 24 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide25. Step 5: Training Employees Organizations must train their employees on a regular basis

Training sessions need to be documented
Employee attendance at training sessions needs to be documented as well
Sanctions for violations need to be clear and contain disciplinary measures
Measures must be in place to prevent terminated employees from accessing records containing personal information Page 25 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide26. Step 6: Monitoring Compliance Ensuring employee training
Executing on violations in a demonstrable and evidenced manner
Regular review of policies for relevancy
Reviewing organizational adherence to established operational protocol Page 26 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide27. Additional Resources The Massachusetts Personal Data Security Law – August 2010
http://www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf

Frequently Asked Questions regarding The Massachusetts Personal Data Security Law
http://www.mass.gov/Eoca/docs/idtheft/201CMR17faqs.pdf

An MFA Perspective Article on the new Massachusetts Personal Data Security Law
http://www.mfa-cpa.com/mfa-news-and-resources/thought-leadership/PDFs/massachusetts-privacy-law-update-nov09.pdf

MFA Web Seminar Presentation on the new Massachusetts Personal Data Security Law
http://www.mfa-cpa.com/mfa-news-and-resources/thought-leadership/ma_privacy_form.asp

Understand how MFA can help in your efforts toward compliance: MFA's Privacy and Data Protection Services
http://www.mfacornerstone.com/Solutions/IT-Advisory/MFAPrivacyAndDataProtectionServices.pdf Page 27 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide28. Questions? Page 28 | Copyright 2017. MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide29. How to Contact Us Matthew Pettine, CGEIT, CISA, ASE, MCSE, MCDBA, MBA
Managing Director, IT Advisory Practice
MFA Cornerstone Consulting
(978) 557-5354
mpettine@mfacornerstone.com Page 29 | Copyright 2017 MFA – Moody, Famiglietti & Andronico, LLP. All rights reserved.<br>
slide30. Thank You Follow us on /mfacpa.boston Follow us on /mfacpa<br>
slide31. MFA - Moody, Famiglietti & Andronico | MFA Cornerstone Consulting
MFA Capital Advisors | MFA Asset Management
MFA Talent Management | MFA Global<br>