Chapter 6 Flashcards
Your adherence to the rules and regulations that govern the information you handle and the industry within which you operate
Compliance
Your adherence to the laws specific to the industry in which you’re operating
Regulatory Compliance
Adherence to regulations that aren’t mandated by law but that can nonetheless have severe impacts upon your ability to conduct business
Industry Compliance
Mitigate risks to physical security
Physical Controls
Mitigate risks by implementing certain processes and procedures
Administrative Controls
Manages risks using technical measures
Technical Controls
A document that defines information security for an organization
Information Security Policy
The primary controls used to manage risk in your environment
Key Controls
Controls that replace impractical or unfeasible key controls
Compensating Controls
ATO
Authority To Operate
After an organization passes an audit, the federal agency they’re working with grants it an ____________.
Authority To Operate (ATO)
FISMA
Federal information Security Management Act
Provides a framework for ensuring the effectiveness of information security controls in all government agencies
Federal Information Security Modernization Act (FISMA)
FedRAMP
Federal Risk and Authorization Management Program (FedRAMP)
Defines rules for government agencies contracting with cloud providers
Federal Risk and Authorization Management Program (FedRAMP)
Certifications that consists of a single Authority To Operate (ATO) that allows an organization to do business with any number of federal agencies
Federal Risk and Authorization Management Program (FedRAMP)
HIPAA
Health Insurance Portability and Accountability Act
Protects the rights and data of patients in the US healthcare system
Health Insurance Portability and Accountability Act (HIPAA)
PHI
Protected Health Information
SOX
Sarbanes-Oxley Act
Regulates financial data, operations, and assets for publicly held companies
Sarbanes-Oxley Act (SOX)
GLBA
Gramm-Leach-Bliley Act
Protects the customers of financial institutions. Also mandates the disclosure of an institution’s information collection and information sharing practices, and established requirements for providing privacy notices and opt-outs to consumers.
Gramm-Leach-Bliley Act (GLBA)
COPPA
Children’s Online Privacy Protection Act of 1998
Imposes certain requirements on operators of websites or online directed to children under 13 years of age, and on operators of other websites or online services that have actual knowledge that they are collecting personal information online from a child under 13 years of age
Children’s Online Privacy Protection Act of 1998 (COPPA)
PCI-DSS
Payment Card Industry Standard
A set of security standards designed to ensure that ALL companies that accept, process, store or transmit credit card information maintain a secure environment
Payment Card Industry Standard (PCI-DSS)
Is Payment Card Industry Standard (PCI-DSS) a law?
No
The state or condition of being free from being observed or disturbed by other people
Privacy
The concept of an individual’s right to privacy is something that has been discussed for many years
Privacy Rights
Safeguards privacy through creating four procedural and substantive rights in personal data
Federal Privacy Act of 1974
What are the four procedural and substantive rights
- Requires government agencies to show an individual any records kept on him or her
- Requires agencies to follow certain principles, called ‘fair information practices,’ when gathering and handling personal data
- Places restrictions on how agencies can share an individual’s data with other people and agencies
- Lets individuals sue the government for violating its provisions
PII
Personally Identifiable Information
Information that can be used to identify an individual in any search (name, address, social security number, etc..)
Personal Identifiable Informaion (PII)
CIPA
Children’s Internet Protection Act
Requires schools and libraries to prevent children from accessing obscene or harmful content over the internet
Children’s Internet Protection Act
FERPA
Family Educational Rights and Privacy Act
Protects students’ records. Applies to students at all level.
Family Education Rights and Privacy Act (FERPA)
ISO
International Organization for Standardization
HITECH
FCRA