Chapter 4 Flashcards
3 Categories of Laws
Criminal Law
Civil Law
Administrative Law
Which type of law does this describe?
preserve peace; involve police and other law enforcement agencies
Criminal Law
Which type of law does this describe?
provide for an orderly society; settled between individuals and organizations
Civil Law
what type of law does this describe?
rules and procedures that should be followed in every possible situations
executive orders, policies, procedures, and regulations
Administrative Law
Where are administrative Laws published?
Code of Federal Regulations (CFR)
Computer Fraud and Abuse Act (CFAA)
first cyber-crime-specific legislation in US
expansion of Comprehensive Crime Control Act
National Information Infrastructure Protection Act of 1996
covers computer systems used in international commerce and interstate commerce
extends protections beyond computer systems like railroads, pipelines, electric grids, etc.
damage to critical portions of national infrastructure as a felony
Federal Sentencing Guidelines (1991)
formalized prudent person rule
three burdens of proof for negligence
prudent person rule
requires senior executives to take personal responsibility for ensuring due care
3 burdens of proof for negligence
- person must have legally recognized obligation
- must have failed to comply with recognized standards
- must be a causal relationship between negligence and damages
FISMA - Federal Information Security Management Act
requires federal agencies implement an infosec profram that covers the agency’s ops - to include contractors
replaced Computer Security Act of 1987 and the Government Information Security Reform Act of 2000
Which organization is responsible for developing the FISMA implementation guidelines?
NIST
Federal Cybersecurity Laws of 2014
Federal Information Systems Modernization Act
Cybersecurity Enhancement Act
National Cybersecurity Protection Act
Federal Information Systems Modernization Act
modified 2002 FISMA by centralizing federal cybersecurity responsibility with the DHS
except:
defense-related cybersecurity remain responsibility of SecDef
intelligence-related cybersec remains responsibility of director of national intel
Cybersecurity Enhancement Act
NIST is responsible for coordination nationwide work on voluntary cybersec standards
National Cybersecurity Protection Act
DHS establishes a national cybersec and commo integration center to be the interface between federal agencies and civilian orgs to share cyber risks, incidents, analysis, and warnings
4 types Intellectual Property
copyrights
trademarks
patents
trade secrets
Copyright law - primary purpose
guarantees the creators of “original works of authorship” protection against duplication of their work
8 categories of copyright protection
Literary
Musical
Dramatic
Pantomimes/Choreography
Pictorial, graphical, sculptural
Motion pictures
Sound recordings
Architectural
What category of copyright does source code fall under?
literary works
Digital Millennium Copyright Act (DMCA)
prohibits attempts to circumvent copyright protection mechanisms
limits liabilities of ISPs when circuits are used by criminals violating copyright law
streaming audio/video over the internet is “eligible nonsubscription transmissions” - not illegal
Trademarks
words, slogans, and logos used to identify a company and its products or services
™ (TM)
shows you intend to protect works or slogans as trademarks
® (R)
symbolizes a trademark registered with the USPTO - United States Patent and Trademark Office
Patents
protect IP rights of inventors for 20 years - after which they become public domain
3 requirements for Patents
- must be new
- must be useful
- must not be obvious
trade secrets
IP that is critical to business, and would cause significant damage if disclosed to competitors