Skip Ribbon Commands Skip to main content

Home

Home > Services > Regulatory

How can we help?

SecureState can also help with regulatory standards for business obligations such as HIPAA, GLBA or PCI compliances. The following list of regulations and standards are explained below in more detail:

  • Health Insurance Portability and Accountability Act (HIPAA)
  • Gramm-Leach-Bliley Act (GLBA)
  • PCI Data Security Standard
  • Sarbanes-Oxley Act of 2002 (SOX)
  • Technical Guide (TR-39, formerly known as TG-3)
  • North American Electric Reliability Corporation Critical Infrastructure Protection Standard (NERC CIP)

HIPAA Compliance

The Health Insurance Portability and Accountability Act (HIPAA), the privacy standard that affects those organizations that handle Personal Health Information (PHI), was put in place in 1998. This regulation provides controls that must be followed by all organizations that hand PHI. Most recently, HIPAA has gained a great deal of traction because of the HITECH Act of 2009 which was part of the Stimulus Package. This act expanded HIPAA compliance to all organizations that work with the healthcare industry as well as increasing fines and punishments for those that do not comply.

GLBA Compliance

The Gramm-Leach-Bliley Act (GLBA) of 1999 was implemented by the Senate Banking Committee to help financial service organizations establish GLBA compliance information security programs that will identify, assess, manage, and control risks that may threaten customer information.

PCI Compliance

The PCI Data Security Standard was developed in 1999 by the major credit card brands, and is the PCI compliance guideline for organizations to protect Cardholder Data. It has evolved into one of the most stringent and prescriptive standards to date focused on the protection of credit card data that is processed, transmitted, and/or stored.

SOX

The Sarbanes-Oxley Act of 2002 (SOX) was enacted to address fraudulent practices of corporate America in response to the Enron and WorldCom financial scandals. This standard forces companies to input accounting controls to counteract fraud in order to protect shareholders and the general public.

TR-39

Billions of Personal Identification Number (PIN) activated transactions are switched through shared ATM and POS networks each year. Each of these transactions is originated using a debit or credit card and PIN. With each interchange transaction, the security of the customer's PIN must rely on the security procedures and controls of the various processing entities and use certified devices such as Host Security Modules (HSM). The most common standard used to evaluate organizations is the Technical Guide (TR-39, formerly known as TG-3) developed by ANSI as part of the X9 standards for financial institutions.

NERC CIP

Following the terrorist attacks of 2001 and the blackout of 2003, the North American Electric Reliability Corporation (NERC) published the Critical Infrastructure Protection (CIP) Standards to help energy companies protect against an outside attack on the nation’s energy grid via the internet. Inside the CIP standards are the eight Cyber Security Standards that companies must be completely compliant with by 2010, when NERC will begin to conduct audits.

 
 

SecureState will evaluate your organization’s Incident Response Plan (IRP) for compliance requirements by conducting interviews and reviewing appropriate documentation including the IRP itself, IDS/IPS alerts and other supporting documents.

SecureState will use the ISO 27002:2005 8.2 Correction Action as a standard process used to follow when building an IRP.

Whether your business needs to meet HIPAA compliance or GLBA compliance guidelines, SecureState can help. We are your information security experts in regulatory standards. Contact Us Today!

 
 
Contact
Contact
News
News
Events
Events
Chat
Chat
Blog
Blog
Login
Login
Twitter
Twitter
LinkedIn
LinkedIn

Questions? Contact SecureState
First Name Email
Last Name Phone
All information is kept strictly confidential.

Website designed and developed by SecureState, © 2010 SecureState LLC. All rights reserved.
23340 Miles Road, Suite C, Cleveland, Ohio 44128-5493 | 800.903.6264 | Sitemap | Contact Us | News / Media | Events | Live Chat | Blog | My Login