Domain 6 Legal and Compliance Flashcards

1
Q

FISMA

A

With any system that interacts with federal agencies in any way there are extensive requirements under FISMA for compliance with security controls required by the federal government

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

eDiscovery in the Cloud

A

determined by contractual requirements between the cloud customer and the cloud provider as well as largely driven by the cloud model employed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ISC/IEC 27050

A

Strives to establish an international accepted state for eDiscovery process and best practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Gramm-Leach-Blilley Act GLBA

A
  • Focuses on PII as it relates financial institutions
  • Institutions must provide all users and customers a written copy of their privacy policies and practices, including with whom and for what reasons their information may be shared
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Safe Harbor

A
  • A way to bridge the gap between EU and USA privacy regulations
  • Voluntary on behalf of the organization
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SOX

A

Regulates accounts and financial practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

General Data Protection Regulation - GDPR

A
  • Aims to strengthen and expand on personal and privacy protections
  • Adds official restrictions on the exporting of data outside of the EU
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Directive 95/46 EC

A

declared data privacy a human right.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Russia

A

Processing and storage of personal information or data on Russian citizens must be done from systems and databases that are physically located in Russia federation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Privacy

A
  • Use to be considered part of confidentiality

- related to an individual’s control over their own information and activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Cloud Control Matrix

A
  • provides a detailed approach and framework for cloud customers with a focus on controls that are pertinent and applicable to a cloud environment.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SSAE 16

A
  • focused on auditing methods
  • SOC reports
  • Replaced SAS 70
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SOC 1

A
  • internal controls as the relate to financial reporting
  • Type 1 - policies and procedures at a point in time
  • Type 2 - policies and procedures over a period in time (6 month minimum)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SOC 2

A
  • Meant to be internal
  • Type 1 - report on the suitability of design and controls
  • Type 2 - report on the effectiveness of the design and application of security controls
- 5 principles
.Availability
.Confidentiality
.Processing integrity
.Privacy
.Security
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SOC 3

A

Meant for external , general use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Audit Scope

A
  • Statement of purpose
  • Scope of audit
  • Reasons and goals for audit
  • Requirements for the audit
  • Audit criteria for assessment
  • Deliverables
  • Classification of audit - sensitivity level
17
Q

AISudit steps

A
  • Define the Scope
  • Define Objectives
  • Define Scope
  • Conduct Audit
  • Lesson Learned and Analysis
18
Q

ISO/IEC 27018

A
  • International standard for privacy involving cloud computing
- Five Principles
. Communication
. Consent
. Control
. Transparency
. Independent yearly audit
19
Q

Generally Accepted Privacy Principles (GAPP)

A
  • privacy standard focused on managing and preventing risks to privacy
  • developed jointly with Canadian and American Accountants
20
Q

Cloud Contract Considerations

A
  • Access to systems
  • Backup and data recovery
  • Data retention and disposal
  • Definition
  • Incident response
  • Litigation
  • Metrics
  • Performance requirements
  • Regulatory requirements
  • Security requirements
  • Termination