Safeguarding Sensitive Information. Agenda Overview Why are we here? Roles and responsibilities Information Security Guidelines Our Obligation Has This.

Similar presentations


Presentation on theme: "Safeguarding Sensitive Information. Agenda Overview Why are we here? Roles and responsibilities Information Security Guidelines Our Obligation Has This."— Presentation transcript:

1 Safeguarding Sensitive Information

2 Agenda Overview Why are we here? Roles and responsibilities Information Security Guidelines Our Obligation Has This Ever Happened to You? Contract to Safeguard Sensitive Information Wrap-up 2

3 Our Obligation: Laws and Regulations Massachusetts data breach law/regulations – Definition of personal information – Obligation for notification when exposed – Data destruction requirements – Requirement to have written information security program (WISP) Company policy – Privacy and disclosure of information – Information policies 3

4 Types of Sensitive Information 1. Sensitive regulated information requiring notification 2. Sensitive regulated information not requiring notification 3. Sensitive information 4

5 Sensitive Regulated Information Requiring Notification Personal Information Requiring Notification  Social Security #  Credit Card #  Financial Account #  Driver’s License # Notification required if there was a potential for unauthorized use! Inform Information Security Team 5

6 Sensitive Regulated Information Not Requiring Notification HIPAA (Health Insurance Portability and Accountability Act)  Information related to health status, provision of health care, or payment of health care FMLA  Information related to Family & Medical Leave Act FERPA  Student records Inform HR Information Security Team 6

7 Sensitive Information Date of birth Home address Salary information Performance/disciplinary information Other? Inform HR Information Security Team 7

8 Key Take-Aways Massachusetts law and company policy impact how certain sensitive data are handled EVERYONE is responsible for compliance  Know what sensitive data you have  Develop good computing practices  Follow HR Information Security Guidelines  Report a potential breach to HR Information Security Team 8

9 Key Take-Aways If you can’t protect it – don’t collect it  You can’t lose what you don’t have Know what you have  You can’t protect what you don’t know you have 9


Download ppt "Safeguarding Sensitive Information. Agenda Overview Why are we here? Roles and responsibilities Information Security Guidelines Our Obligation Has This."

Similar presentations


Ads by Google