Written Information Security Program (Wisp) For Protection Of Personal Information Template Page 8

ADVERTISEMENT

anti-virus, anti-spyware, and anti-malware protection and
reasonably up-to-date patches and virus definitions, or a
version of such software that can still be supported with up-to-
date patches and virus definitions, and is set to receive the most
current security updates on a regular basis.
D. Personal Information Removed from the Corporation
1. Employees and Board Members shall only remove paper or electronic
Personal Information from the Corporation when they have a
legitimate and authorized business purpose for removing such
information and only with prior authorization of the Executive
Director.
2. Any employee or Board Member of the Corporation removing
electronic Personal Information from the Corporation office shall only
do so on a secure device, such as an encrypted laptop or encrypted
USB drive.
3. Any employee or Board Member who removes Personal Information
from the Corporation must keep the Personal Information secured.
The measures taken to secure such Personal Information shall include
whatever is necessary to secure the information from unauthorized use
or access in the environment in which the employee or Board Member
must use the information for their legitimate business purpose.
4. Any employee or Board Member who experiences a data security
breach relating to Personal Information removed from the Corporation
shall immediately inform the Data Security Coordinator.
IV. PERSONAL INFORMATION SECURITY BREACH
A. Employees and members of the board of directors must notify the Data
Security Coordinator in the event of a known or suspected Personal
Information security breach or unauthorized use of Personal Information.
B.
The Corporation shall provide notice as soon as practicable and without
unreasonable delay when the Corporation (a) knows or has reason to know of
a Personal Information security breach, or (b) knows or has reason to know
that the Personal Information of a Massachusetts resident was acquired or
used by an unauthorized person or used for an unauthorized purpose. The
following notices shall be issued:
1. Notice shall be provided to the Massachusetts resident whose
information was acquired or otherwise affected by an unauthorized
person. Such notice shall include the nature of the breach of security
or unauthorized acquisition or use, and any steps the Corporation has
taken or plans to take relating to the incident.
8

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Life