GCGA Ch. 11 Security Compliance (ST) Flashcards
(6 cards)
Compliance programs
ensure that an organization complies with all of its legal and contractual obligations.
Due diligence
refers to the actions taken to ensure the organization is aware of all legal requirements applicable to its operations. It involves understanding the risks, regulations, and standards relevant to the business and taking the necessary steps to align with them. Due care, meanwhile, is the continuous effort to ensure the organization adheres to these requirements and addresses any identified non-compliance in a timely manner.
Attestation
refers to the verification by individuals within the organization or third parties that the organization is compliant with the relevant rules and regulations.
Acknowledgement
the recognition and acceptance of these compliance standards by employees and other stakeholders.
The right to be forgotten
empowers individuals to request that their personal data be erased from a company’s records under specific circumstances.
Data inventory
a detailed list of where important data is kept, who can get to it, and why it’s used. Data retention policies say how long data should be kept and how to get rid of it safely when it’s not needed anymore.