MA 201 CMR 17
* 17.03: (1) Every person that owns, licenses, stores or maintains personal information about a resident of the Commonwealth shall develop, implement, maintain and monitor a comprehensive, written information security program...
* 17.04: (6) For files containing personal information on a system that is connected to the Internet, there must be reasonably up-to-date firewall protection and operating system security patches, reasonably designed to maintain the integrity of the personal information.
* 17.04: (7) Reasonably up-to-date versions of system security agent software which must include malware protection and reasonably up-to-date patches and virus definitions, or a version of such software that can still be supported with up-to-date patches and virus definitions, and is set to receive the most current security updates on a regular basis.
PCI DSS
* Requirement 12: Maintain a policy that addresses information security for employees and contractors.
* Requirement 1: Install and maintain a firewall configuration to protect cardholder data
* Requirement 5: Use and regularly update anti-virus software or programs










