6) Laws & Regulations Flashcards

1
Q

(T/F) A cybersecurity professional must be proficient with all current laws, both state and federal, that may apply to the organization he/she works with.

A

False

The number of laws and their complexities make it difficult for any one person to keep abreast of them, but the organization must have other resources studying these laws and making sure compliance is met. The information security specialist, Legal and HR departments, executives, and even industry groups will work together to make sure no laws or regulations are violated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

FISMA refers to ___.

A

The Federal Information Security Modernization Act of 2014

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Not all schools are required to comply with this law.

A

FERPA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Federal agencies must comply with the law administered by the Department of Homeland Security.

A

FISMA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

This law puts the burden to stop some forms of financial data sharing in the hands of the customer.

A

GLBA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

This broad law includes privacy aspects of past, current and future PHI.

A

HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Although this law is aimed at public companies, it provides a blueprint of financial responsibility and transparency that many organizations strive to follow.

A

SOX

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

(T/F) As long as the laws are abided by, industry standards without legal impacts may be ignored.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

(T/F) International computing laws must be considered if any customer resides outside the U.S.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

PII must always be monitored for compliance. What does PII stand for?

A

Personally identifiable information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

This law provides a framework for ensuring the effectiveness of information security controls in federal government.

A

FISMA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

This law improves the efficiency and effectiveness of the health care system and protects patient privacy.

A

HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

This law protects the privacy of students and their parents.

A

FERPA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

This law regulates the financial practice and governance of corporations.

A

SOX

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

This law protects the customers of financial institutions.

A

GLBA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Relating to an organization’s adherence to laws, regulations, and standards.

A

Compliance

17
Q

Regulations mandated by law, usually requiring regular audits and assessments.

A

Regulatory Compliance

18
Q

Regulations or standards designed for specific industries.

A

Industry Compliance

19
Q

The state or condition of being free from being observed or disturbed by other people.

A

Privacy

20
Q

This act safeguards privacy through the establishment of procedural and substantive rights in personal data.

A

The Federal Privacy Act of 1974

21
Q

Rights relating to the protection of an individual’s personal information.

A

Privacy rights

22
Q

___ ensures the protection of information, operations, and assets in federal government.

A

FISMA

23
Q

___ protects the privacy of students and their parents.

A

FERPA

24
Q

___ sets limits on the use and disclosure of patient information and grants individuals rights over their own health records.

A

HIPAA

25
Q

___ regulates the financial practice and governance of corporations.

A

SOX

26
Q

___ protects the customers of financial institutions.

A

GLBA

27
Q

Some standards are not mandated by law but are managed and enforced by the industry, often via a council or committee. Which of the options below is an example of this industry compliance?

a) HIPAA
b) SOX
c) PCI DSS
d) FISMA
e) GLBA

A

c) PCI DSS