CHP 14 Flashcards
Policies
rules. The framework for operations, decision-making, and behaviors, setting the rules for a compliant and ethical corporate culture.
SDLC
SDLC policies govern software development within an organization.
ISO/IEC 27001
An international standard that provides an information security management system (ISMS) framework to ensure adequate and proportionate security controls are in place.
CDE
The Cardholder Data Environment (CDE) refers to the network of people, processes, and technologies that store, process, or transmit cardholder data.
ISO/IEC 27002
This is a companion standard to ISO 27001 and provides detailed guidance on specific controls to include in an ISMS.
ISO/IEC 27017
An extension to ISO 27001 and specific to cloud services.
ISO/IEC 27018
Another addition to ISO 27001, and specific to protecting personally identifiable information (PII) in public clouds.
FIPS
FIPS (Federal Information Processing Standards) —FIPS are standards and guidelines developed by NIST for federal computer systems in the United States that specify requirements for cryptography.
SOX
the Sarbanes-Oxley Act (SOX) mandates the implementation of risk assessments, internal controls, and audit procedures.
FISMA
Federal Information Security Management Act (FISMA)
FISMA, or the Federal Information Security Management Act, is a United States law enacted in 2002 to protect government information and operations against threats.
GLBA
a United States federal law that mandates financial institutions to protect the privacy of consumers’ personal financial information.
PIPEDA
The Personal Information Protection and Electronic Documents Act (PIPEDA) is a Canadian federal law that governs how private sector organizations collect, use, and disclose personal information in the course of commercial activities.
Healthcare
Health Insurance Portability and Accountability Act (HIPAA) (United States)
The General Data Protection Regulation (GDPR) (European Union)
Financial Services
Gramm-Leach-Bliley Act (GLBA) (United States)
Payment Card Industry Data Security Standard (PCI DSS ) (Contractual obligation)
Telecommunications
Communications Assistance for Law Enforcement Act (CALEA ) (United States )
“Allows LE to tap phones”