ExamGecko
Question list
Search
Search

Related questions











Question 90 - CIPP-US discussion

Report
Export

What does the Massachusetts Personal Information Security Regulation require as it relates to encryption of personal information?

A.

The encryption of all personal information of Massachusetts residents when all equipment is located in Massachusetts.

Answers
A.

The encryption of all personal information of Massachusetts residents when all equipment is located in Massachusetts.

B.

The encryption of all personal information stored in Massachusetts-based companies when all equipment is located in Massachusetts.

Answers
B.

The encryption of all personal information stored in Massachusetts-based companies when all equipment is located in Massachusetts.

C.

The encryption of personal information stored in Massachusetts-based companies when stored on portable devices.

Answers
C.

The encryption of personal information stored in Massachusetts-based companies when stored on portable devices.

D.

The encryption of all personal information of Massachusetts residents when stored on portable devices.

Answers
D.

The encryption of all personal information of Massachusetts residents when stored on portable devices.

Suggested answer: D

Explanation:

The Massachusetts Personal Information Security Regulation (201 CMR 17.00) requires that any person or entity that owns or licenses personal information of Massachusetts residents must implement and maintain a comprehensive written information security program that includes administrative, technical, and physical safeguards to protect such information.One of the technical requirements of the regulation is to encrypt all personal information of Massachusetts residents that is stored on laptops or other portable devices, regardless of where the equipment is located12.The regulation defines personal information as a person's first name and last name or first initial and last name in combination with any one or more of the following data elements that relate to such person: (a) Social Security number; (b) driver's license number or state-issued identification card number; or financial account number, or credit or debit card number, with or without any required security code, access code, personal identification number or password, that would permit access to a resident's financial account1.The regulation also requires encryption of all transmitted records and files containing personal information that will travel across public networks, and encryption of all data containing personal information to be transmitted wirelessly1.Reference:

Regulation 201 CMR 17.00: Standards for the Protection of Personal Information of MA Residents

Massachusetts Law Raises the Bar for Data Security

asked 22/11/2024
Alan Phillips
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first