Laws, Regulations & Compliance Flashcards
12 Requirements of PCI DSS
- Install + maintain firewall configuration
- do not use vendor supplied defaults for passwords + other security parameters
- protect stored cardholder data
- encrypt transmission of cardholder data across open public networks
- protect systems against malware + regularly update AV
- develop + maintain secure systems and apps
- restrict access to cardholder data by N2K
- identify + authenticate access to system components
- restrict physical access to cardholder data
- track + monitor all access to network resources + cardholder data
- regularly test security systems + processes
- maintain policy that addresses information security
Digital Millennium Copyright Act of 1998
prohibits circumvention of copy protection mechanisms (digital media) + limits liability for ISPs for activities of their users
Economic Espionage Act of 1996
penalties for theft of trade secrets
FERPA
Education
GLBA - Graham Leach Biley Act
credit related PII; FIs
ECS - Electronic Communication Service (Europe)
notice of breaches
4th Amendment
basis for privacy rights is the 4th amendment of the US constitution
1974 US Privacy Act
protection of PII on federal databases
1980 Organization for Economic Cooperation Development (OECD)
provides for data collection, specifications, safeguards
1986 (amended 1996) US Computer Fraud and Abuse Act
trafficking in computer passwords or information that causes a loss of USD 1000 and more or could impair medical treatment
1986 Electronic Communications Privacy Act
prohibits eavesdropping or interception without distinguishing private / public
CALEA - Communications Assistance for Law Enforecement Act 1994
amended the 1986 Electronic Communications Privacy Act; requires all communications carriers to make wiretaps possible for law enforcement with an appropriate court order, regardless of technology in use
1987 US Computer Security Act
security training, develop security plan, identify sensitive systems on governmental agencies
1991 US Federal Sentencing Guidelines
responsibility on senior management with fines up to USD 290mn; invoke prudent man rule; address both individuals and organizations
1996 US Economic and Protection Act
industrial and corporate espionage