<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Governance Blog on IT governance, risk management, compliance and information security. &#187; 201 CMR 17.00</title>
	<atom:link href="http://blog.itgovernance.co.uk/tag/201-cmr-17-00/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.itgovernance.co.uk</link>
	<description>IT Governance Ltd source, create and deliver products and services to meet the real-world, evolving IT governance needs of today&#039;s organizations, directors, managers and practitioners.</description>
	<lastBuildDate>Tue, 07 Feb 2012 17:06:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Do you comply with the 201 CMR 17.00 &#8211; The Massachusetts Data Protection Law?</title>
		<link>http://blog.itgovernance.co.uk/do-you-comply-with-the-201-cmr-17-00-the-massachusetts-data-protection-law/</link>
		<comments>http://blog.itgovernance.co.uk/do-you-comply-with-the-201-cmr-17-00-the-massachusetts-data-protection-law/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 07:54:31 +0000</pubDate>
		<dc:creator>James Warren</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[201 CMR 17.00]]></category>

		<guid isPermaLink="false">http://blog.itgovernance.co.uk/?p=761</guid>
		<description><![CDATA[You are probably aware of the new data protection law and that every organization who collects, owns or licenses personal information about a resident of Massachusetts must now be in full compliance.<p><a href="http://blog.itgovernance.co.uk/do-you-comply-with-the-201-cmr-17-00-the-massachusetts-data-protection-law/">Do you comply with the 201 CMR 17.00 &#8211; The Massachusetts Data Protection Law?</a> is a post from: <a href="http://blog.itgovernance.co.uk">IT Governance Blog on IT governance, risk management, compliance and information security.</a></p>
]]></description>
		<wfw:commentRss>http://blog.itgovernance.co.uk/do-you-comply-with-the-201-cmr-17-00-the-massachusetts-data-protection-law/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to comply with the Massachusetts Data Protection Law</title>
		<link>http://blog.itgovernance.co.uk/how-to-comply-with-the-massachusetts-data-protection-law/</link>
		<comments>http://blog.itgovernance.co.uk/how-to-comply-with-the-massachusetts-data-protection-law/#comments</comments>
		<pubDate>Tue, 30 Mar 2010 08:21:03 +0000</pubDate>
		<dc:creator>James Warren</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[201 CMR 17.00]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[ITGP]]></category>

		<guid isPermaLink="false">http://blog.itgovernance.co.uk/?p=748</guid>
		<description><![CDATA[Many organizations accross the state of Massachusetts and organizations outside of Massachusetts, who collects, owns or licenses personal information about a resident of Massachusetts, are struggling to meet the requirements of the new Data Protection Law (201 CMR 17.00), which came into force on March 1st this year. If you fall into this category, or [...]<p><a href="http://blog.itgovernance.co.uk/how-to-comply-with-the-massachusetts-data-protection-law/">How to comply with the Massachusetts Data Protection Law</a> is a post from: <a href="http://blog.itgovernance.co.uk">IT Governance Blog on IT governance, risk management, compliance and information security.</a></p>
]]></description>
		<wfw:commentRss>http://blog.itgovernance.co.uk/how-to-comply-with-the-massachusetts-data-protection-law/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cost Effective Solution to Meet 201 CMR 17.00 Deadline!</title>
		<link>http://blog.itgovernance.co.uk/cost-effective-solution-to-meet-201-cmr-17-00-deadline/</link>
		<comments>http://blog.itgovernance.co.uk/cost-effective-solution-to-meet-201-cmr-17-00-deadline/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 13:03:57 +0000</pubDate>
		<dc:creator>James Warren</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[201 CMR 17.00]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Impementation Toolkit]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO27001]]></category>

		<guid isPermaLink="false">http://blog.itgovernance.co.uk/?p=560</guid>
		<description><![CDATA[Every organization who collects, owns or licenses personal information about a resident of Massachusetts will have to be in full compliance with 201 CMR 17.00 on or before March 1, 2010.
The term "personal information" is defined so broadly that nearly every Massachusetts business must comply with the regulations.<p><a href="http://blog.itgovernance.co.uk/cost-effective-solution-to-meet-201-cmr-17-00-deadline/">Cost Effective Solution to Meet 201 CMR 17.00 Deadline!</a> is a post from: <a href="http://blog.itgovernance.co.uk">IT Governance Blog on IT governance, risk management, compliance and information security.</a></p>
]]></description>
		<wfw:commentRss>http://blog.itgovernance.co.uk/cost-effective-solution-to-meet-201-cmr-17-00-deadline/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upgrade your ISO27001 ISMS to cover 201 CMR 17.00!</title>
		<link>http://blog.itgovernance.co.uk/upgrade-your-iso27001-isms-to-cover-201-cmr-17-00/</link>
		<comments>http://blog.itgovernance.co.uk/upgrade-your-iso27001-isms-to-cover-201-cmr-17-00/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 11:33:16 +0000</pubDate>
		<dc:creator>James Warren</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[201 CMR 17.00]]></category>
		<category><![CDATA[Impementation Toolkit]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO27001]]></category>

		<guid isPermaLink="false">http://blog.itgovernance.co.uk/?p=518</guid>
		<description><![CDATA[You can read the Massachusetts regulation yourself and decide how to revise your ISMS, or you can accelerate your compliance with 201 CMR 17.00 with The 201 CMR 17.00 Upgrade Toolkit which includes specific document revision instructions. <p><a href="http://blog.itgovernance.co.uk/upgrade-your-iso27001-isms-to-cover-201-cmr-17-00/">Upgrade your ISO27001 ISMS to cover 201 CMR 17.00!</a> is a post from: <a href="http://blog.itgovernance.co.uk">IT Governance Blog on IT governance, risk management, compliance and information security.</a></p>
]]></description>
		<wfw:commentRss>http://blog.itgovernance.co.uk/upgrade-your-iso27001-isms-to-cover-201-cmr-17-00/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Purchase The 201 CMR 17.00 and ISO 27001 Toolkit Today!</title>
		<link>http://blog.itgovernance.co.uk/purchase-the-201-cmr-17-00-and-iso-27001-toolkit-today/</link>
		<comments>http://blog.itgovernance.co.uk/purchase-the-201-cmr-17-00-and-iso-27001-toolkit-today/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 09:33:29 +0000</pubDate>
		<dc:creator>James Warren</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[201 CMR 17.00]]></category>
		<category><![CDATA[Impementation Toolkit]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO27001]]></category>

		<guid isPermaLink="false">http://blog.itgovernance.co.uk/?p=469</guid>
		<description><![CDATA[The 201 CMR 17.00 &#038; ISO 27001 Toolkit
Will save you months of work, help you avoid costly trial-and-error dead-ends, and ensure everything is covered to current 201 CMR 17.00 / ISO 27001 standard. <p><a href="http://blog.itgovernance.co.uk/purchase-the-201-cmr-17-00-and-iso-27001-toolkit-today/">Purchase The 201 CMR 17.00 and ISO 27001 Toolkit Today!</a> is a post from: <a href="http://blog.itgovernance.co.uk">IT Governance Blog on IT governance, risk management, compliance and information security.</a></p>
]]></description>
		<wfw:commentRss>http://blog.itgovernance.co.uk/purchase-the-201-cmr-17-00-and-iso-27001-toolkit-today/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Obliged to meet the 201 CMR 17.00 &#8211; Massachusetts Data Protection Law?</title>
		<link>http://blog.itgovernance.co.uk/obliged-to-meet-the-201-cmr-17-00-massachusetts-data-protection-law/</link>
		<comments>http://blog.itgovernance.co.uk/obliged-to-meet-the-201-cmr-17-00-massachusetts-data-protection-law/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 10:01:43 +0000</pubDate>
		<dc:creator>James Warren</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[201 CMR 17.00]]></category>
		<category><![CDATA[Impementation Toolkit]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[ISO27001 Training]]></category>

		<guid isPermaLink="false">http://blog.itgovernance.co.uk/?p=426</guid>
		<description><![CDATA[If you need motivation to move towards compliance, Massachusetts General Law, Chapter 93A, section 4 specifically authorizes the Attorney General to seek injunctive relief against the organization involved in the unauthorized act or practice. In addition, section 4 allows a court to impose a $5,000 civil penalty for each violation and if ‘violation‘ is interpreted to mean the unauthorized access to a single individual’s personal information, the potential damages could be enormous.<p><a href="http://blog.itgovernance.co.uk/obliged-to-meet-the-201-cmr-17-00-massachusetts-data-protection-law/">Obliged to meet the 201 CMR 17.00 &#8211; Massachusetts Data Protection Law?</a> is a post from: <a href="http://blog.itgovernance.co.uk">IT Governance Blog on IT governance, risk management, compliance and information security.</a></p>
]]></description>
		<wfw:commentRss>http://blog.itgovernance.co.uk/obliged-to-meet-the-201-cmr-17-00-massachusetts-data-protection-law/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Meet 2010 Compliance Laws</title>
		<link>http://blog.itgovernance.co.uk/meet-2010-compliance-laws/</link>
		<comments>http://blog.itgovernance.co.uk/meet-2010-compliance-laws/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 13:39:49 +0000</pubDate>
		<dc:creator>James Warren</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[201 CMR 17.00]]></category>
		<category><![CDATA[Data Protection Act]]></category>
		<category><![CDATA[ISMS]]></category>

		<guid isPermaLink="false">http://blog.itgovernance.co.uk/?p=316</guid>
		<description><![CDATA[In 2010 there will be two important compliance laws introduced which will affect the majority of North American organizations and many global organization too.
45 US States followed California when they introduced "SB1386", the Security Breach Information Act, which has specific and restrictive privacy breach reporting requirements.<p><a href="http://blog.itgovernance.co.uk/meet-2010-compliance-laws/">Meet 2010 Compliance Laws</a> is a post from: <a href="http://blog.itgovernance.co.uk">IT Governance Blog on IT governance, risk management, compliance and information security.</a></p>
]]></description>
		<wfw:commentRss>http://blog.itgovernance.co.uk/meet-2010-compliance-laws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The 201 CMR 17.00 &amp; ISO 27001 Toolkit</title>
		<link>http://blog.itgovernance.co.uk/the-201-cmr-17-00-iso-27001-toolkit/</link>
		<comments>http://blog.itgovernance.co.uk/the-201-cmr-17-00-iso-27001-toolkit/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 10:34:09 +0000</pubDate>
		<dc:creator>James Warren</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[201 CMR 17.00]]></category>
		<category><![CDATA[Framework]]></category>
		<category><![CDATA[Impementation Toolkit]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO27001]]></category>

		<guid isPermaLink="false">http://blog.itgovernance.co.uk/?p=281</guid>
		<description><![CDATA[Every organization who licenses personal information about a resident of Massachusetts shall be in full compliance with 201 CMR 17.00 on or before March 1, 2010.<p><a href="http://blog.itgovernance.co.uk/the-201-cmr-17-00-iso-27001-toolkit/">The 201 CMR 17.00 &#038; ISO 27001 Toolkit</a> is a post from: <a href="http://blog.itgovernance.co.uk">IT Governance Blog on IT governance, risk management, compliance and information security.</a></p>
]]></description>
		<wfw:commentRss>http://blog.itgovernance.co.uk/the-201-cmr-17-00-iso-27001-toolkit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Massachusetts Data Protection Law</title>
		<link>http://blog.itgovernance.co.uk/the-massachusetts-data-protection-law/</link>
		<comments>http://blog.itgovernance.co.uk/the-massachusetts-data-protection-law/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 14:11:44 +0000</pubDate>
		<dc:creator>James Warren</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[201 CMR 17.00]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO27001]]></category>

		<guid isPermaLink="false">http://blog.itgovernance.co.uk/?p=194</guid>
		<description><![CDATA[201 CMR 17.00, described by many as "one of the toughest in the nation", require ALL entities that licence, store or maintain personal information about a Massachusetts resident to implement a comprehensive information security program – even if the business or entity does not have offices in the state.<p><a href="http://blog.itgovernance.co.uk/the-massachusetts-data-protection-law/">The Massachusetts Data Protection Law</a> is a post from: <a href="http://blog.itgovernance.co.uk">IT Governance Blog on IT governance, risk management, compliance and information security.</a></p>
]]></description>
		<wfw:commentRss>http://blog.itgovernance.co.uk/the-massachusetts-data-protection-law/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

