Compliance, Laws, Regulations Flashcards

1
Q

What does (FISMA) stand for?

A

Federal Information Security Management Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does (FedRAMP) stand for?

A

Federal Risk and Authorization Management Program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Where does FISMA apply to?

A

It applies to all US Federal and State Government Agencies That administer federal programs such as Medicare and all private companies that support, sell, or receive grant money from federal government

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Federal Risk and Authorization Management

A

This applies to SAAS tools and Cloud platform providers like AWS and AZURE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ATO

A

Authority To Operate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does (HIPAA) Stand for?

A

The Health insurance portability and accountability act
Founded at (1996)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does (PHI) Stand for?

A

Protected health information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Sarbanes-Oxley Act (SOX) (founded 2002)

A

Regulates financial data, operation, and assets for publicly held companies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Gramm-Leach-Bliley Act (GLBA)

A

Protects information Such as Personally identifiable information (PII).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Children’s Internet Protection ACT (CIPA)

A

Requires schools and libraries to prevent children from accessing obscene or harmful content over the internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Children Online Privacy Protection Act (COPPA)

A

Protects the privacy of minors younger than 13 by restricting organizations from collecting their PII

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The Family Educational Rights and Privacy Act (FERPA) was founded 1974

A

Insures to protect students at all levels once turned 18. The rights to these records shift from parent to student

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

General Data Protection Regulation (GDPR) European Union 2018

A

covers data protection and privacy for all individuals in the European Union

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Payment Card Industry Data Security Standard (PCI DSS)

A

an information security standard designed to protect cardholder data and reduce fraud and data breaches across the payment ecosystem

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

International Organization for Standardization (ISO) Created in 1926

A

covers technology, Food safety, and agriculture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SP 800-37 Framework

A
  1. Categorize
  2. Select
  3. Implement
  4. Assess
  5. Authorize
  6. Monitor
17
Q

(SAAS)

A

Software as a service (EX: Provides access to a specific application or application suite like google Apps)

18
Q

(PAAS)

A

Platform as a service (EX: Database or web server like azure)

18
Q

(IAAS)

A

Infrastructure as a service (EX, Virtual Servers and storage like Google Cloud and Amazon web services)

19
Q

NIST

A

National institute of standards and technology

20
Q

Health Information Technology for Economic and Clinical Health Act (HITECH)

A

Legislation enacted as part of the American Recovery and Reinvestment Act 2009. HITECH aims to promote the adoption and meaningful use of health information technology (health IT) in the United States.

21
Q

what does due care mean

A

Often called prudent man rule, which is doing what any responsible person would do

22
Q

Define due diligence

A

The management of due care ensuring the implemented security measure was done correctly

23
Q

Define Gross negligence

A

The opposite of due care and suffering a negative loss, you can be legally held liable

24
Q

Human intelligence (Humint)

A

Any Data that was gathered by talking to people