Compliance Flashcards
Criminal Justice Information Services (CJIS)
Used by state and local agencies wanting to access the FBI’s CJIS.
Cloud Security Alliance (CSA) STAR Certification
obtained for Azure, Intune, and Power BI. Based on ISO/IEC 27001. includes Commercial Cloud.
General Data Protection Regulation (GDPR)
imposes rules on companies, government agencies, non-profits, and others offering goods or services to people in the EU, or related to EU residents (regardless of location the service resides)
Health Insurance Portability and Accountability Act (HIPAA)
regulates patient PHI (Protected Health Information). Also satisfies HITECH (Health Information Technology for Economic and Clinical Health)
ISO/IEC 27018
related to personal data
SOC 1, 2, & 3
standard reporting model used by Microsoft.
NIST CSF
a voluntary framework.
FedRAMP Moderate & High
for US government and government contractors
UK Gov (G-Cloud)
used by UK government services.