Managed Services from Netropole Inc.
  • Home
  • Contact
  • Search
  • Solutions & Services
    • Monitoring and Remediation
    • Complete Coverage
    • Backup and Disaster Recovery Solutions
      • FlashBack Demo
    • Portland Computer Repair and Network Support
    • FAQ
  • Why Managed Services
  • About Netropole
    • Contact Us
    • Partnerships and Certifications
  • News & Events
    • Free Portland IT Support Newsletter
    • Upcoming Events
    • Technology Blog
  • Free Stuff
    • Free Problem Prevention Network Audit
    • Free Managed Services Whitepaper / Case Study
    • Small Business Owner Report
    • Multimedia
Some light reading to keep
you ahead of the tech curve...
Questions? Call us:
503-241-3499
Oregon Identity Theft Protection Act

Oregon Identity Theft Protection Act

Posted in [Computer User Information], [Strategic IT Planning Information] By SuperUser Account

Is your company in compliance with state law? 

In the past 10 years, over 10,000 new regulations have been placed on the books by local, state, and federal agencies pertaining to the handling, storage, and disposal of confidential client, patient, and employee documents and information. For example, the state of Massachusetts has recently enacted one of these privacy laws and is requiring anyone who has business in that state to comply by March 2010.  The regulation will set standards for protecting and storing personal information about any residents in paper or electronic form. Basically, ANY company that holds social security numbers (your employees’ Social Security numbers, for example), credit cards, or financial statements needs to comply with these regulations or the fines for not doing so can be hefty.

In 2007, the Oregon legislature passed the Oregon Consumer Identity Theft Protection Act, which gave consumers more tools to protect themselves against identity theft. Like Massachusetts, Oregon businesses and government agencies now have a clear direction and expectations to ensure the safety of the personal identifying information they maintain. Personal information is defined as a name in used in any combination with a Social Security number, Oregon driver’s license number, financial information (credit or debit card numbers), or security passwords that would allow someone access to a financial account.

A security plan is required by the State of Oregon for all businesses...
A security plan includes administrative, technical, and physical safeguards. Administrative safeguards identify what personal information you keep and how to keep it safe, training employees in security program practices and procedures, and ensuring that contracted service providers are capable of supplying and maintaining systems that protect sensitive information.

Technical safeguards include assessing security risks in your computer network, which include detecting, preventing, and responding to cyber attacks, as well as having a backup system in place so you can quickly recover your files in the event of a disaster or system failure.

Physical safeguards include protecting against unauthorized access to or use of personal identifying information, and
disposing of information that is no longer 
needed by way of shredding, burning or erasing electronic data that is unreadable or cannot be reconstructed.

Here are some suggestions to help your business meet some of the requirements. Begin by identifying the computers or servers where personal information is stored along with all connections to the computers where you store sensitive information. These include the internet, computers at your branch offices, computers used by service providers to support your network, and wireless devices like inventory scanners cell phones, laptop computers and PDA’s.

Do not store sensitive consumer data on any computer with an Internet connection unless it’s essential for conducting business. Encrypt the information you send to third parties over the internet and consider encrypting sensitive information that is stored on your computer network or portable storage devices. 

Scan computers on your network regularly to identify and profile the operating system and open network services. If you find services that you do not need, disable them to stop hackers and prevent potential security problems. Assess the vulnerability of each connection to commonly known or reasonably foreseeable attacks. Maintain central log files of security-related information to monitor activity on your network, the log will provide information that can identify the computers that can be compromised. Monitor incoming traffic for signs that someone is trying to hack in. Keep an eye out for activity from new users, multiple log-in attempts from unknown users or computers, and higher-than-average traffic at unusual times of the day. Monitor outgoing traffic for signs of a data breach. Watch for unexpectedly large amounts of data being transmitted from your system to an unknown user. If large amounts of information are being transmitted from your network, investigate to make sure the transmission is authorized. Before you outsource any of your business functions, such as payroll, web hosting, and data processing, investigate the company’s data security practices and compare their standards to yours and if possible, visit their facilities.

Portland Managed Services can help you meet these requirements. The first step would be for us to conduct system security review. A security review will alert you to any unauthorized users, open ports, viruses, spyware, and more. There is no charge or obligation for this review but we need time to work them into our schedule so the earlier you call to schedule a time, the better. Give us a call at 503-241-2499. ∆

 

Return TopTrackbackPrintPermalink
Currently rated 0.0 by 0 people
Popular tags: Security audit

Share this Post

Previous Entry: How to Track and Recover Your Stolen Laptop and Other Business-Critical Devices
Next Entry: Dave's Corner Column - December 2009
Related Posts:

  • Inexpensive Marketing Ideas for Small Businesses
  • Do You Need to Buy a PC?
  • How to get rid of your old computers and still be green
    On processing, please waiting for ...
    Comments are closed for this post, but if you have spotted an error or have additional info that you think should be in this post, feel free to contact me.
    Subscribe to Our Monthly Newsletter

    Do you like our Blog Content? You can have our complete newsletter emailed to you every month by subscribing below...

    Do you like our Blog Content? You can have our complete newsletter emailed to you every month by subscribing below...

    Free IT Newsletter

     

    News that you can use - delivered to your inbox every month...

    Enter the code shown above
    Submit
    * Required
    Technology Blog
    • Home
    • Rss Feed
    Technology Blog
    • Computer User Information
    • Dave's Corner Column
    • Smart Phone and Wireless
    • Software Infomation
    • Strategic IT Planning Information
    Technology Blog
    • Apple
    • Apple iPad
    • business continuation
    • Cloud computing
    • downtime
    • iPad
    • Microsoft
    • monitoring
    • network audit
    • Network Management
    • Office 2010
    • office productivity
    • Oregon law
    • paperless office
    • printer
    • printer buying guide
    • Productivity
    • resource audit
    • search engine marketing
    • searching
    • Security audit
    • Sharepoint
    • spam
    • Spring clean your PC
    • technology
    • temporary files
    • title tag
    • Veloclothes
    • virtualization
    • Windows Home Server
    View All Tags
    Technology Blog
    • July, 2010
    • June, 2010
    • April, 2010
    • February, 2010
    • January, 2010
    • December, 2009
    • January, 2007
    Technology Blog
    FREE Problem Prevention Audit

    We Want To Give You a FREE Problem-Prevention Network Audit ($495 Value)!

    If you are a new client to us, I'd like to invite you to sign up for a FREE Problem Prevention Network Audit to demonstrate how we can make your computer and technology headaches go away finally and forever.  At no charge or obligation, one of our senior technicians will come on-site and perform a 27-point performance and tune-up assessment to pinpoint any vulnerabilities to viruses, hackers, or data loss, and to show you how to improve the speed and reliability or your computer network.

    Why are we giving this away for free?  We simply offer this to all prospective customers as a way of introducing ourselves to you without the risk.  Other companies have paid more than $495 and we can only afford to give a couple away each month - so don't wait...

    Click here now to sign up for a FREE Problem Prevention Network Audit today!

    Microsoft Gold Partner Netropole Managed Services
    Microsoft Gold Partner Netropole Managed Services
    • Home
    • Are Managed Services Right for You?
    • Solutions & Services
    • About Netropole
    • News & Events
    • Contact
    • Sitemap
    • Search