CISSP ch 4 Flashcards

1
Q

CFAA

A

Computer fraud and abuse act

Makes it a crime to access, use, damage or modify a FEDERAL computer system, financial institution, medical records or affecting interstate commerce

Outlaws creation of malicious code that might cause damage to a computer system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

National Information Infrastructure Protection Act of 1996

A

Broadens CFAA to include international commerce and national infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Federal Sentencing Guidelines 1991

A

Formalize prudent person rule, which requires senior executives to take personal responsibility for ensuring the due care that ordinary prudent individuals would exercise in the same situation

Allowed organizations and executives to minimize punishment for infractions by demonstrating due diligence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

FISMA

A

Federal information security management act 2007

Require federal agencies to implement an information security program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

FISMA 2014

A

Federal information systems modernization act

Centralizes federal cyber security responsibility with the department of homeland security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Cyber security enhancement act 2014

A

Charged NIST with coordinating voluntary cyber security standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

WIPO

A

World intellectual property organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

DMCA

A

Digital millennium copyright act

Limits liability of Internet service providers when their circuits are used to violate copyright law

Service providers must take prompt action to remove copyrighted material upon notification to benefit from liability exemption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Copyright lasts for…

A

70 years after death of last author

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Parents last for

A

20 years after application to register patent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

ITAR

A

International traffic in arms regulations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

USML

A

United states munitions list

List of items covered under ITAR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

EAR

A

export administration regulations

Covers a broader set of items that are designed for commercial use but have military applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CCL

A

Commerce control list

Items covered by EAR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

BIS

A

Department of commerce’s Bureau of Industry and Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ECPA

A

Electronic communications privacy act of 1986

Makes it a crime to invade the electronic privacy of an individual

Broadened the federal wiretap act

17
Q

CALEA

A

Communications assistance for law enforcement act if 1994

Amended the ECPA

Requires all communications carriers to make wiretaps possible for law enforcement with an appropriate court order, regardless of the technology in use

18
Q

HIPAA

A

Health insurance portability and accountability act of 1996

Privacy and security regulations for hospitals, physicians, insurance companies and others that process or store private medical information about individuals

19
Q

HITECH

A

Health information technology for economic and clinical health act of 2009

Updated HIPAA

20
Q

PHI

A

Protected health information

21
Q

COPPA

A

Children’s online privacy protection act of 1998

Parents must give consent to the collection of information about children younger than 13 prior to collection

22
Q

GLBA

A

Gramm Leach Bliley Act of 1999

Relaxed regulations concerning financial services

Regulates how financial institutions can handle private information

Limits type of information that could be exchanged, requiring written privacy policies to be provided to customers

23
Q

USA PATRIOT Act of 2001

A

Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act

Broadened powers of law enforcement + Intel agencies, including for monitoring of electronic communications

Allow for blanket authorization for a person to monitor all their communications

Allows government to obtain detailed information in user activity through the use of a subpoena (as opposed to a wiretap)

24
Q

FERPA

A

Family educational rights and privacy act

Affects any educational institution that accepts federal funding

Parents/students have right to inspect educational records, request correction

Schools may not release personal information from student records without written consent

25
Q

SOX

A

Sarbanes Oxley Act

Sets out information security controls for an organization’s financial systems

26
Q

®

A

Registered trade mark