Domain 1 - Chapter 4 - Laws, Regulations, and Compliance Flashcards

1
Q

What is administrative law?

A

Used by government agencies to effectively carry out their day-to-day to do business.
Published in the Code of Federal Regulations (CFR).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is criminal law?

A

Criminal law protects society against the basic principles we believe in (murder, rape, theft, arson..)
Preserve peace and keep society safe.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is civil law?

A

Provides the framework for the transaction of business between people and organizations.
Usually no law enforcement involvement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the CFAA?

A

Computer Fraud and Abuse Act

First major piece of cybercrime-specific legislation in the U.S.

Protects computers used by the government or in interstate commerce from a variety of abuses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the ECPA?

A

Electronic Communications Privacy Act

Makes it a crime to invade the electronic privacy of an individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When were Federal Sentencing Guidelines released?

A

1991

Provided punishment guidelines to help federal judges interpret computer crime laws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is FISMA?

A

Federal Information Security Management Act.

Requires federal agencies implement an information security program.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the Federal Information Systems Modernization Act

A

Centralized cybersecurity responsibility to the Department of Homeland Security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

NIST SP 800-53

A

Security and Privacy Controls for Federal Information Systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

NIST SP 800-171

A

Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

NIST Cybersecurity Framework (CSF)

A

Voluntary risk-based framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the DMCA?

A

Digital Millennium Copyright Act (DMCA)

Prohibits the circumvention of copy protection mechanism placed in digital media and limits the liability of internet service providers for activities of their users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How long is copyright protected for?

A

by one or more authors - until 70 years after the death of the last surviving author

works for hire and anonymous works - 95 year from the date of the first publication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the Economic Espionage Act of 1996?

A

Provides penalties for individuals found guilty of the theft of trade secrets. Harsher penalties for benefiting a foreign government.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a contractual license?

A

Written agreements between a software vendor and a user.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is shrink-wrap agreement?

A

License agreements are written on the outside of software packaging

17
Q

What is a click-through agreenment?

A

Browser wrap agreements

18
Q

Gramm-Leach-Bliley Act (GLBA)

A

A law passed in 1999 that eased the strict governmental barriers between financial institutions. Banks, insurance companies, and credit providers were severely limited in the services they could provide and the information they could share with each other. GLBA somewhat relaxed the regulations concerning the services each organization could provide.

19
Q

USA PATRIOT ACT

A

Uniting and Strengthening America by Providing Appropriate Tools Require to Intercept and Obstruct Terrorism Act of 2001

Greatly broadened the powers of law enforcement organizations and intelligence agencies across a number of areas, including the monitoring electronic communications.

20
Q

Identity Theft and Assumption Deterrence Act

A

Made identity theft a crime

21
Q

What is GDPR?

A

General Data Protection Regulation

EU’s comprehensive privacy laws

22
Q

What is the PIPEDA?

A

Personal Information Protection and Electronic Documents Act

Canada’s privacy law

23
Q

What federal agency deals with export of encryption software?

A

BIS -Bureau of Industry and Security -Department of Commerce

24
Q

What is CALEA?

A

Communications Assistance for Law Enforcement Act

Requires communication carriers assist law enforcement with the implementation of wiretaps when done under appropriate court order.