Laws, Regulations & Compliance Flashcards

1
Q

12 Requirements of PCI DSS

A
  1. Install + maintain firewall configuration
  2. do not use vendor supplied defaults for passwords + other security parameters
  3. protect stored cardholder data
  4. encrypt transmission of cardholder data across open public networks
  5. protect systems against malware + regularly update AV
  6. develop + maintain secure systems and apps
  7. restrict access to cardholder data by N2K
  8. identify + authenticate access to system components
  9. restrict physical access to cardholder data
  10. track + monitor all access to network resources + cardholder data
  11. regularly test security systems + processes
  12. maintain policy that addresses information security
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Digital Millennium Copyright Act of 1998

A

prohibits circumvention of copy protection mechanisms (digital media) + limits liability for ISPs for activities of their users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Economic Espionage Act of 1996

A

penalties for theft of trade secrets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

FERPA

A

Education

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

GLBA - Graham Leach Biley Act

A

credit related PII; FIs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ECS - Electronic Communication Service (Europe)

A

notice of breaches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

4th Amendment

A

basis for privacy rights is the 4th amendment of the US constitution

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

1974 US Privacy Act

A

protection of PII on federal databases

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

1980 Organization for Economic Cooperation Development (OECD)

A

provides for data collection, specifications, safeguards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

1986 (amended 1996) US Computer Fraud and Abuse Act

A

trafficking in computer passwords or information that causes a loss of USD 1000 and more or could impair medical treatment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

1986 Electronic Communications Privacy Act

A

prohibits eavesdropping or interception without distinguishing private / public

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

CALEA - Communications Assistance for Law Enforecement Act 1994

A

amended the 1986 Electronic Communications Privacy Act; requires all communications carriers to make wiretaps possible for law enforcement with an appropriate court order, regardless of technology in use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

1987 US Computer Security Act

A

security training, develop security plan, identify sensitive systems on governmental agencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

1991 US Federal Sentencing Guidelines

A

responsibility on senior management with fines up to USD 290mn; invoke prudent man rule; address both individuals and organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

1996 US Economic and Protection Act

A

industrial and corporate espionage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

1996 US National Infrastructure Protection Act

A

encourages other countries to adopt similar framework

17
Q

HITECH - Health Information Technology for Economic and Clinical Health Act of 2009

A

update on HIPPA; data breach notification requirements; change in treatment of business associates (BAs) = organizations that handle PII on behalf of HIPPA covered entity –> written contract required