2.c. Laws and Regulations Flashcards

(36 cards)

1
Q

Regulatory Compliance

A

Adherence to the laws specific to the industry in which you’re operating (LAW). Involves cyclical audits and assessments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Industry Compliance

A

Adherence to regulations that aren’t mandated by law, but can have severe impacts on your ability to conduct business
Ex: Payment Card Industry Data Security Standard (PCI DSS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Types of Controls (3)

A

Physical - MITIGATE risks
Administrative - Implement certain processes/procedures to MITIGATE risks
Technical - MANAGE risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Key Controls (3 points)

A
  1. Provide reasonable degree of assurance that risk will be mitigated
  2. If control fails, it’s unlikely that another control could take over for it
  3. Failure of this control will affect an entire process
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Compensating Controls

A

Replace impractical or unfeasible key controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Maintaining Compliance Steps (4)

A

Monitor > Review > Document > Report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

NIST

A

US National Institute of Standards and Technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

FISMA

A

Federal Information Security Management Act (Risk-based approach)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A.T.O.

A

Authority to operate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

FedRAMP

A

Federal Risk and Authorization Management Program - Rules for government agencies contracting with cloud providers
Ex: AWS, Azure
Single A.T.O. for business w/ any number of federal agencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

HIPAA

A

Health Insurance Portability and Accountability Act - CONGRESS LAW

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SOX

A

Sarbanes-Oxley Act - Regulates financial data, operations, and assets for publically held companies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

GLBA

A

Gramm-Leach-Bliley Act - Protects personal identifiable info (PII) and financial data of customers of financial institutions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CIPA

A

Children’s Internet Protection Act - Requires schools to prevent access to obscene/harmful content

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

COPPA

A

Children’s Online Privacy Protection Act - Protect privacy of minors younger than 13

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

FERPA

A

Family Educational Rights and Privacy Act - Protects student’s records

17
Q

GDPR

A

General Data Protection Regulation (EU Regulation)

18
Q

ISO

A

International Organization for Standardization - more than 21000 standards

19
Q

ISO 27000

A

“Information security management systems-overview and vocabulary”

20
Q

ISO 27001

A

“Information technology-Security techniques-information management systems-Requirements”

21
Q

ISO 27002

A

“Code of practice for information security controls”

22
Q

SP

A

National Institute of Standards and Technology

23
Q

SP 800-37

A

“Guide for applying the risk management framework to federal information systems”S

24
Q

SP 800-53

A

“Security and Privacy controls for federal information systems and organizations”

25
Privacy Act
CONGRESS LAW
26
Steps? of Controls. (6)
CATEGORIZE system based on info it handles and the impact of exposing/losing data SELECT controls based on system's categorization IMPLEMENT the controls and document implementation ASSESS the controls to ensure they are properly implemented and performing as expected AUTHORIZE or ban the use of the system based on the risk it faces and the controls implemented to mitigate that risk MONITOR the controls to ensure they continue to mitigate risk
27
Compliance in the cloud (3 tier pyramid)
Less Control ----> IaaS PaaS SaaS <---- More responsibility
28
IaaS
Infrastructure as a service - Virtual servers and storage
29
PaaS
Platform as a service - Prebuilt servers (database)
30
SaaS
Software as a service - specific application/application suite
31
Blockchain
A distributed and uneditable digital ledger
32
Cryptocurrency
Typically based on the use of blockchain
33
USA Patriot Act
To deter and punish terrorist acts
34
E FOIA
Electronic Freedom of Information Act - requires agencies to provide the public w/ electronic access to their "Reading Room" records
35
CFAA
Computer Fraud and Abuse Act - To reduce the hacking of government computer systems
36
CAN SPAM
Controlling the Assault of Non-Solicited Porn and Marketing - Gives recipients the right to spot entities from emailing them