Chapter 6: Laws and Regulations Flashcards
provides a framework for ensuring the effectiveness of information security controls in government
FISMA (The Federal Information Security Modernization Act)
legislation intended to protect government information, operations, and assets from any natural or manmade threat
FISMA (The Federal Information Security Modernization Act)
requires each federal agency to develop, document, and implement an information security program to protect its info and info systems
Federal Information Security Modernization Act)
improves efficiency and effectiveness of the health care system
Health Insurance Portability and Accountability Act (HIPAA)
certain provisions within HIPAA require privacy protections for individually identifiable health information
Protected Health Information (PHI)
mandate safeguards to protect patient privacy
HIPAA Privacy Rule
sets limits on the use of disclosure of patient information without authorization and grants individuals rights over their own health records
HIPAA Privacy Rule
protects the privacy of students and their parents
The Family Educational Rights Privacy Act (FERPA)
requires all schools that receive funds from programs administered by the U.S. Department of Education to comply with the standards regarding the disclosure and maintenance of educational information, personally identifiable information, and directory information
The Family Educational Rights Privacy Act (FERPA)
grants certain rights to students and parents regarding the student’s own records
The Family Educational Rights and Privacy Act (FERPA)
regulated the financial practice and governance of corporations
Sarbanes-Oxley Act (SOX)
designed to protect investors and the general public by establishing requirements regarding reporting and disclosure practices
Sarbanes-Oxley Act (SOX)
mandates standard in regards to areas such as corporate board responsibility, auditor independence, fraud accountability, internal controls assessment, and enhanced financial disclosures
Sarbanes-Oxley Act (SOX)
established the Public Company Accounting Oversight Board (PCAOB)
Sarbanes-Oxley Act (SOX)
oversees public accounting firms and independently ensures compliance with SOX for auditing practices
Public Company Accounting Oversight Board (PCAOB)
protects the customers of financial institutions, essentially any company offering financial products or services, financial or investment advice, or insurance.
The Gramm-Leach-Bliley (GLBA)
requires financial institutions to safeguard a consumer’s “nonpublic personal information or NPI”
The Gramm-Leach-Bliley Act (GLBA) Privacy Rule
mandates the disclosure of an institution’s information collection and information sharing practices, and establishes requirements for providing privacy notices and opt-out to consumers
The Gramm-Leach-Bliley Act (GLBA)
money laundering
Bank Secrecy Act (BSA)
Telecommunications assistance for law enforcement
Communications Assistance for Law Enforcement Act of 1994(CALEA)
Rules for spam
Controlling the Assault of Non-Solicited Pornography and Marketing (CAN SPAM)
computer fraud and abuse
Computer Fraud and Abuse Act of 1986(CFAA)
protecting children from harmful content
Children’s Internet Protection Act of 2001 (CIPA)
Private data of children
Children’s Online Privacy Protection act of 1998 (COPPA)
DMV records
Driver’s Privacy Protection Act of 1994 (DPPA)
Government documents (E FOIA)
Electronic Freedom of Information Act of 1996
Credit Information
Equal Credit opportunity act (ECOA)
electronic communications (wiretaps)
Electronic Communications Privacy Act of 1986 (ECPA)
Transfer of funds
Electronic Funds Transfer Act ( EFTA)
Electronic Banking
Fair and Accurate Credit Transactions Act (FACTA)
Credit Records (CCRA)
Consumer Credit Reporting Reform Act of 1996
Debt Collection
Fair Debt Collection Practices Act (FDCPA)
Energy Regulation
Federal Energy Regulatory Commission (FERC)
Education Records `
family education rights and privacy act of 1974 (FERPA)
securities
Financial Industries Regulatory Authority (FINRA)
government information security
federal information security management act (FISMA)
unfair trade practices
Federal Trade Commission Act (FTCA)
consumer financial information
gramm-leach-bliley financial services modernization act of 1999 (GLBA)
patient information
health insurance portability act (HIPAA)
health information technology
health information technology for economic and clinical health act(HITECH)
import and export of defense items
international traffic in arms regulation(ITAR)
economic and trade sanctions
office of foreign assets control (OFAC)
payment cards
payment application data security standards PCI DSS)
privacy of journalist
privacy protection act of 1978(PPA)
privacy of financial institutions
right to financial privacy act of of 1978 (RFPA)
breach notifications
California Senate bill 1386 (SB 1386)
accuracy of corporate financial information
sarbanes-oxley act (SOX)
telephone solicitation
Telephone Consumer Protection Act of 1991 (TCPA)
anti terrorism
uniting and strengthening america by providing appropriate tools required to intercept and obstruct terrorism act of 2001 (USA PATRIOT ACT)
automated matching of privacy act records
computer matching and privacy protection act (CMPPA)
identity theft
federal identity theft and assumption deterrence act (FITAD)
telemarketing
do no call registry
government accounting and administrative controls
Federal Managers Financial Integrity Act (FMFIA)
requirement for US voting systems
Help America Vote act of 2002 (HAVA)
department of homeland security data
homeland security act of 2002
securities customer information
NASD rule 3110
data for securities transactions
SEC rule 17a-4
electronic signatures
title 21 code of federal regulations
a matter that is very specific to the industry in which a given company or organization is operating and how it is structured (often more far reaching than imagined)
regulatory compliance
comes packaged with cyclical audits and assessments to ensure that everything is being carried out according to specification
regulatory compliance
regulations that are not mandated by law but can have severe impacts upon our ability to conduct business
industry compliance