Chapter 3: Compliance Flashcards

1
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Regulations

A

Written rules issued by an executive body covering specific issues, and apply only to the specific entities that fall under the authority of the agency that issued them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Civil law system

A

Uses prewritten rules and not based on precedent; is different from civil (tort) laws, which work under a common law system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Common Law System

A

made up of criminal, civil, and administrative laws

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Customary law system

A

Addresses mainly personal conduct and uses regional traditions and customs as the foundations of the law; is usually mixed with another type of listed legal system rather than being the sole legal system used in a region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Religious law system

A

Laws are derived from religious beliefs and address an individual’s religious responsibilities; commonly used in Muslim countries or regions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Mixed law system

A

Uses two or more legal systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Criminal law

A

deals with an individual’s conduct that violates government laws developed to protect the public

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Civil law

A

deals with wrongs committed against individuals or organizations ending in injury or damages; no prison time as a punishment, usually requires financial restitution

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Administrative law

A

Regulatory law; covers standards of performance or conduct expected by government agencies from companies, industries, and certain officials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Island-hopping attacks

A

an attacker compromises an easier target that has a trusted connection to the ultimate target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

APT

A

advanced persistent threat; sophisticated threat actor with the means and will to devote extraordinary resources to compromising a specific target and remaining undetected for extended periods of time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Data breach

A

a security event which results in the actual or potential compromise of the confidentiality or integrity of protected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

PII

A

personally identifiable information; data which can be used to uniquely identify, contact, or locate a single person or used with other sources to identify a single individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

TDF

A

transborder data flow; movement of machine-readable data across a political boundary like a country’s border

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Data localization laws

A

Require certain types of data to be stored and process in that country, sometimes exclusively

17
Q

IP

A

Intellectual property; type of property created by human intellect consisting of ideas, inventions, and expressions uniquely created by a person and protected from unauthorized use by others

18
Q

License

A

an agreement between an IP owner (licensor) and somebody else (licensee), granting the party rights to use the IP in very specific ways

19
Q

Trade secrets

A

proprietary to a company, often include information which provides a competitive edge; information is protected as long as the owner takes the necessary protective actions

20
Q

Copyright

A

protects the expression of ideas rather than the ideas themselves

21
Q

Trademarks

A

protect words, names, product shapes, symbols, colors, or a combination of these used to identify products or a company; items used to distinguish products from the competitors’ products

22
Q

Patent

A

grants ownership and enables the owner to legally enforce their rights to exclude others form using the invention covered by the patent

23
Q

Due diligence

A

defined as doing everything within one’s power to prevent a bad thing from happening; normally associated with leaders, laws, and regulations

24
Q

Due care

A

taking the precautions that a reasonable and competent person would take in the same situation; normally applicable to everyone; its absence could show negligence

25
Q

Administrative investigations

A

focused on policy violations

26
Q

Criminal investigations

A

aimed at determining whether there is cause to believe someone committed a crime

27
Q

Civil investigation

A

Triggered when a lawsuit is imminent or ongoing and similar to a criminal investigation; except that instead or working with law enforcement agencies you will probably be working with attorneys from both sides

28
Q

Regulatory investigation

A

initiated by a government regulator when there is reason to believe the organization is not in compliance

29
Q

Data breach notification requirements

A

GDPR has strictest breach notification requirements; within 72 hours of becoming aware of the breach

30
Q

Software piracy

A

using a software product that it is not authorized to use; can have significant financial and even criminal repercussions

31
Q

To control the public distribution of an original white paper written by staff

A

Copyright to protect

32
Q

Federal Privacy Act of 1974

A

created to protect personal data; information can only be used for the reason for which it was collected

33
Q

GDPR

A

General Data Protection Regulation; privacy law