Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

23
What Are "reasonable security procedures and practices"
Post Body

I have a small part of the task of establishing "reasonable security procedures and practices" for a small company that hosts personally identifiable information. (PII) Their stack is Nodejs apps and SQL database back ends hosted in AWS.

My last job was in a PCI environment. Because the standard is pretty thorough, it was time consuming to set up, but not too hard to pass. NIST has many standards. The ones I read seem to apply to government contracts to various agencies.

For example, Calfornia has a law that defines PII, but provides no guidance as to what is minimal care: http://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.81.5

I am no longer in an industry that needs PCI standards and am at a loss as to where to go. Per the title, is there a documented standard for "reasonable security procedures and practices?"

Author
Account Strength
100%
Account Age
9 years
Verified Email
Yes
Verified Flair
No
Total Karma
18,957
Link Karma
2,534
Comment Karma
16,329
Profile updated: 3 days ago
Posts updated: 10 months ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
5 years ago