2.c. Laws and Regulations Flashcards

1
Q

Regulatory Compliance

A

Adherence to the laws specific to the industry in which you’re operating (LAW). Involves cyclical audits and assessments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Industry Compliance

A

Adherence to regulations that aren’t mandated by law, but can have severe impacts on your ability to conduct business
Ex: Payment Card Industry Data Security Standard (PCI DSS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Types of Controls (3)

A

Physical - MITIGATE risks
Administrative - Implement certain processes/procedures to MITIGATE risks
Technical - MANAGE risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Key Controls (3 points)

A
  1. Provide reasonable degree of assurance that risk will be mitigated
  2. If control fails, it’s unlikely that another control could take over for it
  3. Failure of this control will affect an entire process
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Compensating Controls

A

Replace impractical or unfeasible key controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Maintaining Compliance Steps (4)

A

Monitor > Review > Document > Report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

NIST

A

US National Institute of Standards and Technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

FISMA

A

Federal Information Security Management Act (Risk-based approach)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A.T.O.

A

Authority to operate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

FedRAMP

A

Federal Risk and Authorization Management Program - Rules for government agencies contracting with cloud providers
Ex: AWS, Azure
Single A.T.O. for business w/ any number of federal agencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

HIPAA

A

Health Insurance Portability and Accountability Act - CONGRESS LAW

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SOX

A

Sarbanes-Oxley Act - Regulates financial data, operations, and assets for publically held companies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

GLBA

A

Gramm-Leach-Bliley Act - Protects personal identifiable info (PII) and financial data of customers of financial institutions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CIPA

A

Children’s Internet Protection Act - Requires schools to prevent access to obscene/harmful content

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

COPPA

A

Children’s Online Privacy Protection Act - Protect privacy of minors younger than 13

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

FERPA

A

Family Educational Rights and Privacy Act - Protects student’s records

17
Q

GDPR

A

General Data Protection Regulation (EU Regulation)

18
Q

ISO

A

International Organization for Standardization - more than 21000 standards

19
Q

ISO 27000

A

“Information security management systems-overview and vocabulary”

20
Q

ISO 27001

A

“Information technology-Security techniques-information management systems-Requirements”

21
Q

ISO 27002

A

“Code of practice for information security controls”

22
Q

SP

A

National Institute of Standards and Technology

23
Q

SP 800-37

A

“Guide for applying the risk management framework to federal information systems”S

24
Q

SP 800-53

A

“Security and Privacy controls for federal information systems and organizations”

25
Q

Privacy Act

A

CONGRESS LAW

26
Q

Steps? of Controls. (6)

A

CATEGORIZE system based on info it handles and the impact of exposing/losing data
SELECT controls based on system’s categorization
IMPLEMENT the controls and document implementation
ASSESS the controls to ensure they are properly implemented and performing as expected
AUTHORIZE or ban the use of the system based on the risk it faces and the controls implemented to mitigate that risk
MONITOR the controls to ensure they continue to mitigate risk

27
Q

Compliance in the cloud (3 tier pyramid)

A

Less Control —->

IaaS PaaS SaaS

<—- More responsibility

28
Q

IaaS

A

Infrastructure as a service - Virtual servers and storage

29
Q

PaaS

A

Platform as a service - Prebuilt servers (database)

30
Q

SaaS

A

Software as a service - specific application/application suite

31
Q

Blockchain

A

A distributed and uneditable digital ledger

32
Q

Cryptocurrency

A

Typically based on the use of blockchain

33
Q

USA Patriot Act

A

To deter and punish terrorist acts

34
Q

E FOIA

A

Electronic Freedom of Information Act - requires agencies to provide the public w/ electronic access to their “Reading Room” records

35
Q

CFAA

A

Computer Fraud and Abuse Act - To reduce the hacking of government computer systems

36
Q

CAN SPAM

A

Controlling the Assault of Non-Solicited Porn and Marketing - Gives recipients the right to spot entities from emailing them