Ummm, what's the legal theory that allows a US state to regulate out of state commerce like this? On the other hand, I wouldn't want to be a web company based in Massachusetts and this might have more than a small effect on the Boston area's attractiveness to many startups.
If your database has Mass. residents, you need a security plan per Massachusetts
11–19 of 19 posts
Re: If your database has Mass. residents, you need a security plan per Massachusetts
#12Ummm, what's the legal theory that allows a US state to regulate out of state commerce like this? On the other hand, I wouldn't want to be a web company based in Massachusetts and this might have more than a small effect on the Boston area's attractiveness to many startups.
It would be the US Constitution, where it gives all rights that are not explicitly enumerated to the states.
Re: If your database has Mass. residents, you need a security plan per Massachusetts
#13Ummm, what's the legal theory that allows a US state to regulate out of state commerce like this? On the other hand, I wouldn't want to be a web company based in Massachusetts and this might have more than a small effect on the Boston area's attractiveness to many startups.
It would be the US Constitution, where it gives all rights that are not explicitly enumerated to the states.
Re: If your database has Mass. residents, you need a security plan per Massachusetts
#14Re: If your database has Mass. residents, you need a security plan per Massachusetts
#15Ummm, what's the legal theory that allows a US state to regulate out of state commerce like this? On the other hand, I wouldn't want to be a web company based in Massachusetts and this might have more than a small effect on the Boston area's attractiveness to many startups.
It seems silly to state legalities are out of scope when you're talking about a law, even if (or, especially if!) you're not writing for lawyers.
Re: If your database has Mass. residents, you need a security plan per Massachusetts
#16Earlier quoted context omitted.
Well - that's enough to make it relevant whenever there's a card transaction... that's going to affect a lot of people. This however "and perhaps the rest of the world" is complete FUD - noone outside of US cares about US state laws (unless you have some branch there of course - but then you already know you have a lot more paperwork to do).
There's no need to store any of those things in your database in order to allow card transactions.
Re: If your database has Mass. residents, you need a security plan per Massachusetts
#17I do like the idea of encrypting user names across the wire, but "to maintain a Written Information Security Plan (WISP) and file it with the state of Massachusetts" goes way too far, imho. I am not a lawyer nor a database geek, so perhaps your take will differ... UPDATE: "Massachusetts does not require that written information security programs be filed at this time, just that they exist," according to a second arti…
Re: If your database has Mass. residents, you need a security plan per Massachusetts
#18Re: If your database has Mass. residents, you need a security plan per Massachusetts
#19I do like the idea of encrypting user names across the wire, but "to maintain a Written Information Security Plan (WISP) and file it with the state of Massachusetts" goes way too far, imho. I am not a lawyer nor a database geek, so perhaps your take will differ... UPDATE: "Massachusetts does not require that written information security programs be filed at this time, just that they exist," according to a second arti…