Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
Check out the new SourceForge HTML5 internet speed test! No Flash necessary and runs on all devices. ×
Security

Submission + - Massachusetts data security law, 201 CMR 17.00 (sqlmag.com)

emeraldd writes: This is a rather scary law, I'd have to say it is practically un-enforcable: "Here are the basics of the new law. If you have personally identifiable information (PII) about a Massachusetts resident, such as a first and last name, then you have to encrypt that data on the wire and as it’s persisted. Sending PII over HTTP instead of HTTPS? That’s a big no no. Storing the name of a customer in SQL Server without the data being encrypted? No way, Jose. You’ll get a fine of $5,000 per breach or lost record. If you have a database that contains 1,000 names of Massachusetts residents and lose it without the data being encrypted that’s $5,000,000. Yikes."
This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

Massachusetts data security law, 201 CMR 17.00

Comments Filter:

System checkpoint complete.

Working...