Day-5-27th march@Legal Flashcards
In US three types of common LAW
> Criminal
Civil (Tort)
Administrative
criminal law
> crimes committed against society
beyond reasonable doubt
felony serious crime , normally in jail for more than 1 year
misdemeanor less serious crime , jail inprisonment for less than 1 year
civil law
> Against individual or company that can create injury, loss ,damage, death > based upon the preponderance of evidence
Criminal vs Civil
> both have punishment
civil has compensatory
criminal has deterrence
civil has statutory damages
According to federal sentencing guideline
Sr corp officer are responsible personally if their org fails to comply with applicable laws .
Administrative laws are regulatory laws
enforced by Govt agencies , penalty financial or imprisonment
risk appetite vs risk tolerance
Risk appetite: amount and type of risk that an organization is willing to pursue or retain
Risk tolerance: organization’s or stakeholder’s readiness to bear the risk after risk treatment in order to achieve its objectives
Intellectual Property organizations
USPTO ,WIPO, WCO,WTO,TRIP
PRIVACY AND DATA PROTECTION LAWS PRINCIPALS
> must be collected fairly and lawfully
must only be used for the purposes for which it was collected
must be accurate and kept upto date
must be accessible to individuals who request a report on personal informations about themselves
individuals have the right to correct if there is any error
personal data cant be disclosed to other org
trnamission of personal data to locations is prohibited where equivalent security is not ensured
us federal privacy act 1974
Personal informations stored by federal agencies cant disclose to any others
HIPAA
privacy standards for PI health informations
Hitech vs HIPAA
However, there is a difference between HIPAA and HITECH with regards to patients´ rights.
Prior to HITECH, patients were unable to find out who their ePHI had been disclosed to (both authorized and unauthorized where known). In 2011, the Department of Health & Human Services published a HITECH-required Rule that allows patients to request access reports. These reports explain to patients who accessed and viewed their ePHI and under what authority.
HITRUST and HIPAA
hipaa is a framework or compliance law, hitrust is a company which help companies to achieve this law.
GLBP
PII stored in Financial origanization
PCI DSS Principles
Credit CARD industry >build and maintain a secure network >protect cardholder data >maintain vulnerability management program >implement strong access control >regularly monitor and test network >maintain an information security policy
Computer Fraud and abuse act -crime
f federal -govt cmputers, f financial informations f foriegn relationship informations
electronic communications and privacy act
unauthorized monitring or evesdropping wiretapping
>can access email but not voice email
us computer security act
special security for compuers holding sensitive informations
us federal sentencing guideline
due care violations for organizations
us economic espionage act
patent trade secret protection
us child pornography act
distribution of child pornography
us patriot act
> wiretap is allowed > voice email access is allowed > mobile tap is allowed
pen device
to collect outgoing number list from a phone number
trap device
to collect incoming numbers