Security - Regulated Data Flashcards

1
Q

What is the PCI DSS and what does it do?

A

Payment Card Industry Data Security Standards

  1. PCI DSS defines the security standards for any organization that handles cardholder information for debit cards, credit cards, prepaid cards, any other type of payment cards.
  2. Any organization that accepts payment cards must ensure it complies with the PCI DSS to avoid fines or possible restriction from processing payment cards.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 6 goals of PCI DSS?

A
  1. Build and maintain a secure network
  2. Protect cardholder data
  3. Maintain a vulnerability management program
  4. Implement strong access control measures
  5. Regularly monitor and test networks
  6. Maintain an information security policy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the PCI DSS Goal of building and maintaining a secure network?

A
  1. Install and maintain a firewall configuration to protect cardholder data.
  2. Do not use vendor-supplied defaults for system passwords and other security parameters.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the PCI DSS goal of protecting cardholder data?

A
  1. Protect stored cardholder data.
  2. Encrypt transmission of cardholder data across open, public networks.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the PCI DSS goal of maintaining a vulnerability management program?

A
  1. Use and regularly update antivirus software or programs.
  2. Develop and maintain secure systems and applications.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the PCI DSS goal of implementing strong access control measures?

A
  1. Restrict access to cardholder data by business need to know.
  2. Assign a unique ID to each person with computer access.
  3. Restrict physical access to cardholder data.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the PCI DSS goal of regularly monitoring and testing networks?

A
  1. Track and monitor all access to network resources and cardholder data.
  2. Regularly test security systems and processes.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the PCI DSS goal of maintaining an information security policy?

A

An organization is required to maintain a policy that addresses information security for all personnel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is SOX?

A

The Sarbanes-Oxley Act (SOX) was enacted in 2002. It applies to any company publicly traded on the stock market. The goal of SOX is to increase transparency and formalize a system of checks and balances. It regulates how companies maintain financial records and secure financial data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is GLBA?

A

The Gramm-Leach-Bliley Act (GLBA) applies to any institution that offers loans, investment advice, or insurance. The GLBA requires these institutions to safeguard customer information and detail the practices for sharing consumer information. The FTC enforces GLBA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Personal information falls under what two categories?

A
  1. Personal government-issued information is anything that is assigned by the government including driver’s license and social security number.
  2. Personally identifiable information (PII) can include credit scores, address history, student records, and any information not assigned by the government that can identify a person.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is FERPA and what does it do?

A

Family Education Rights and Privacy Act

All educational institutions must keep detailed student records. The sensitive information kept in these files must be kept secure. FERPA provides institutions with procedures to secure this information including defining:
1. How to store the information.
2. Who the information can be shared with.
3. How long the data must be retained.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the CCPA and what does it do?

A

California Consumer Privacy Act

The CCPA allows California citizens to have control over their personal information that businesses collect. Key components of the CCPA include:
1. The right to know the information that a business collects about an individual.
2. The right to delete collected personal information.
3. The right to opt-out of the sale of an individual’s personal information.
4. The right to non-discrimination for exercising an individual’s CCPA rights.

Even though the CCPA applies to California citizens, many larger organizations allow citizens of other states to exercise these rights. These organizations find it too cost prohibitive to develop and apply the processes only to California residents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the GDPR and what does it do?

A

General Data Protection Regulation

The GDPR applies to citizens in the European Union and provides many of the same rights as the CCPA. Like the CCPA, many organizations that operate in both the EU and other countries provide these rights to all users regardless of location.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is HIPAA and what does it do?

A

Health Insurance Portability and Accountability Act

It is the primary law defining how healthcare information should be kept secure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What two parts of HIPAA should IT professionals be aware of?

A
  1. HIPAA Privacy Rule defines how to secure health data regardless of the format.
  2. HIPAA Security Rule defines how to secure health data that is stored electronically.
17
Q

Who enforces HIPAA?

A

Department of Health and Sciences