Compass IT Compliance Blog / Compliance (15)

Updates to MA 201 CMR 17 Data Breach Law

boston-1099418_1920

The Laws, they are a’ changin’… …to paraphrase Bob Dylan. And I’m speaking about privacy and breach laws. It would seem that every other day we hear of another set of customer data being compromised at another company. It could be just name and address, but it could be phone number, S …

Read Story

The Dangers of a Written Information Security Program (WISP)

binding-contract-948442_1280.jpg

This is a guest post that was written by Joel Goloskie, Esq. Joel is Senior Counsel with Pannone, Lopes, Devereaux, & O'Gara in Boston. Joel is a member of the firms Healthcare, Litigation, and Corporate & Business Teams. Joel advises and assists his clients on the various int …

Read Story

The NIST Cybersecurity Framework - The Protect Function

stockvault-cyber-security-concept-with-red-padlock-on-data-screen180401.jpg

For the second part of our series on the NIST Cybersecurity Framework, we are going to be discussing the Protect function. Last time we discussed the Identify function which talked about the need to really understand your critical infrastructure, your systems, and the risks associated …

Read Story

HIPAA Compliance and Audit Controls - What You Need to Know

Add a little bit of body text.png

If you have read the news lately on healthcare and specifically HIPAA, you probably saw references to a recent HIPAA settlement between Memorial Health Systems of Florida and the Department of Health and Human Services (HHS). I’m sure the amount of the settlement caught your attention …

Read Story

5 Quick Tips To Help With Information Security

security-265130_640.jpg

Information Security is a moving target. Once you "think" that you have it figured out, boom, here comes another new threat to knock you back on your heels and question just how strong your Information Security program is. That's the bad news. The good news is that we are going to giv …

Read Story

IT GRC - Compliance

stockvault-book-ampamp-glasses-127786.jpg

Over the past week we have been discussing an overview of IT Governance, Risk, and Compliance as well as diving into each of the components that make up this program. Today we are going to talk about the final piece of the IT GRC puzzle: Compliance.

Read Story

Subscribe by email