* 1. In what state is your company headquartered?

* 2. Does your company currently hold personal data (e.g., names, addresses, social security numbers, etc.) for customers in Nevada and/or Massachusetts?

* 3. If yes, can your company currently prove that all data for customers in these states is protected according to the specific state regulations now in place?

* 4. How have changing state regulations impacted your company’s security strategy as it pertains to protecting customer data (select the statement that most closely mirrors your strategy)?:

* 5. What methods does your company currently use to secure your customers’ personal data (check all that apply)?

* 6. Do you anticipate the passing of additional state-specific (or Federal) IT security regulations related to the protection of customer data in 2009?

* 7. If yes, how difficult do you expect it to be to adjust your company’s security strategy and prove that customer data remains secure?