CSCI 2201: Chapter 6 Laws & Regulations Flashcards

1
Q

What does the USA PATRIOT Act stand for?

A

Computer Fraud and Abuse Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the USA PATRIOT Act applied to?

A

Computing and computer-related issue

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

True or False: Information security, privacy, HR, and legal departments work closely to each other to take care any law violations

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

European Union’s (EU) Data Protection Directive (Directive 95/46/EC):

A

Protects individual’s personally identifiable information (PII)

Much more stringent than current US requirements

Thus, if an US company is storing data on EU citizens in the United States, they must still comply with EU laws

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Regulatory Compliance is…

A

very specific to the industry in which a given company or organization is OPERATING and how it is STRUCTURED

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

An important detail about Industry Compliance is that…

A

Industries may have compliance with regulations not mandated by law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Privacy-related Information for E-commerce:

A

name, address, social security number, phone number, e-mail address, mobile device information, IP address, MAC address, and any number of other similar points of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Privacy-related Information for financial institutions or schools:

A

date of birth, information on dependants, credit history, previous residences, sample of a signature

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Thee unauthorized exposure of _______ information can be very harmful

A

privacy-related personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the penalties for unauthorized exposure of personal information?

A

lawsuits, reputational damage, fines from regulators, and a number of other expenses. For a large breach, the cost of mitigation can be hi

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Thee dictionary definition of privacy is…

A

“The state or condition of being free from being observed or disturbed by other people”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

InfoSec Example of the concept of privacy:

A

There are federal, state, local, and tribal laws that govern what can be done or recorded

We have to follow these laws if we have, e.g., camera as part of our security infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

According to USA Federal Privacy Act, the first privacy right is:

A

First: it requires government agencies to show an individual any records kept on him or her

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

According to USA Federal Privacy Act, the second privacy right is:

A

Second: it requires agencies to follow certain principles, called ‘fair information practices,’ when gathering and handling personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

According to USA Federal Privacy Act, the third privacy right is:

A

Third: it places restrictions on how agencies can share an individual’s data with other people and agencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

According to USA Federal Privacy Act, the fourth privacy right is:

A

Fourth: it lets individuals sue the government for violating its provisions

17
Q

Large business across all states, like Amazon, need to ensure…

A

compliance with all states and federal laws

18
Q

Example of sensitive data:

A

name, address, social security number, payment card data, date of birth, e-mail address, phone numbers, IP addresses, MAC addresses, operating system and application information, mobile device information, biometric data

19
Q

Asocial media company may not tread any of the information as sensitive but rather users may sign an agreement that…

A

their data is open

20
Q

Computing security laws and regulations may vary across…

A

geographical locations

21
Q

______________ might affect businesses and organizations

A

Regulatory compliance and industry compliance

22
Q

Privacy issues may come into play when…

A

conducting business

23
Q

Which of the following departments must work together to take care of any law violations?

a. Security
b. HR
c. Legal department
d. All of the above

A

d. All of the above

24
Q

Regulatory compliance in a specific company highly depends on ______

a. Its operations and structures
b. Its policies and regulations
c. Its Incident Response Plan and data policies
d. Its logging and data validation

A

a. Its operations and structures

25
Q

In e-commerce, privacy related information includes_______

a. E-mail address
b. IP address
c. Mailing Address
d. Social security number
e. All of the above

A

e. All of the above

26
Q

A large business that spans across all provinces of a country must ensure compliance with ____

a. Only federal laws
b. Only provincial laws
c. All provincial and federal laws
d. None of the above

A

c. All provincial and federal laws

27
Q

In the case of a data breach or a leak, it is important to __________ all the information and data that has been compromised.

a. Catalog and categorize
b. Trace and recover
c. Decrypt and evaluated.
d. None of the above

A

a. Catalog and categorize

28
Q

How can a compliance audit be a positive occurrence?

A

Answer: It can help the participating company to educate its employee, find and fix compliance issues, revisit the compliance policy to be consistent with standards

29
Q

If there is any information leak, what you must do as a security analyst?

A

Answer: You must create a catalog and categorize the compromised information.