6) Laws & Regulations Flashcards
(T/F) A cybersecurity professional must be proficient with all current laws, both state and federal, that may apply to the organization he/she works with.
False
The number of laws and their complexities make it difficult for any one person to keep abreast of them, but the organization must have other resources studying these laws and making sure compliance is met. The information security specialist, Legal and HR departments, executives, and even industry groups will work together to make sure no laws or regulations are violated.
FISMA refers to ___.
The Federal Information Security Modernization Act of 2014
Not all schools are required to comply with this law.
FERPA
Federal agencies must comply with the law administered by the Department of Homeland Security.
FISMA
This law puts the burden to stop some forms of financial data sharing in the hands of the customer.
GLBA
This broad law includes privacy aspects of past, current and future PHI.
HIPAA
Although this law is aimed at public companies, it provides a blueprint of financial responsibility and transparency that many organizations strive to follow.
SOX
(T/F) As long as the laws are abided by, industry standards without legal impacts may be ignored.
False
(T/F) International computing laws must be considered if any customer resides outside the U.S.
True
PII must always be monitored for compliance. What does PII stand for?
Personally identifiable information
This law provides a framework for ensuring the effectiveness of information security controls in federal government.
FISMA
This law improves the efficiency and effectiveness of the health care system and protects patient privacy.
HIPAA
This law protects the privacy of students and their parents.
FERPA
This law regulates the financial practice and governance of corporations.
SOX
This law protects the customers of financial institutions.
GLBA