IS3350 CHAPTER 9 Flashcards
A law that requires that state residents be notifies if an entity experiences a security breach that compromises their personal data is called ___?
BREACH NOTIFICATION LAW
The materials generated while creating laws. It includes committee reports and hearings. It also transcripts of debate and reports issued by legislatures. It is reviewed to help determine what a legislature intended when it created a law and is called ___?
LEGISLATIVE HISTORY
A legal concept that protects an entity from liability if it follows the law is called a ___?
SAFE HARBOR
- The ChoicePoint data breach was the triggering event that caused many states to create data protection laws.
TRUE OR FALSE
TRUE
- California’s breach notification law went into effect in ___.
2003
- Most states define personal information as NAME and which of the following elements?
- Date of birth
- Address
- Phone number
- Social Security number
- None of the above
Social Security number
- An encryption safe harbor is ___.
A legal concept that protects an entity from liability if it follows the law
- What is a stat breach notification law?
- A law that requires that residents be notified if a dam breaks
- A law that requires residents be notified if a business has a security breach that compromises their personal data
- A law that requires that residents be notified if a business has a security breach that compromises the business’s confidential data
- A law that requires that businesses be notified if a government has a security breach that compromises the business’s confidential data
- None of the above
A law that requires residents be notified if a business has a security breach that compromises their personal data
- Which types of entities are sometimes excluded from breach notification laws?
- GLBA financial institutions
- HIPAA covered entities
- Out-of-state businesses
- 1 & 2 only
- 1, 2, & 3
GLBA financial institutions
&
HIPAA covered entities
- What is NOT a business day?
- An official workday
- A day of the week that includes Monday through Friday
- Memorial Day
- Tuesday
- None of the above
Memorial Day
- “Clear and conspicuous” notice means that ___.
A person must be able to easily understand it.
- Which states allow data breach notification to be given by telephone?
- California
- Colorado
- North Carolina
- 1 & 2
- 2 & 3
Colorado
&
North Carolina
- What technology standards are permitted under the Nevada encryption law?
- PCI DSS
- SO 1799
- NIST
- FTC
- HIPAA
NIST
- Which states have required businesses to follow all, or part, of the PCI DSS?
- Minnesota
- Nevada
- California
- 1 & 2
- 1 & 3
Minnesota
&
Nevada
- A private cause of action is ___.
A legal concept that describes a person’s right to sue another for harm that the latter caused.