Laws, Standards, and Regulations Flashcards
Payment Card Industry Data Security Standard
PCI DSS
The PCI DSS standard covers any organization that directly accepts credit or debit card payments and applies to all entities involved in the card payment process
- Must maintain a vulnerability management program
- Must regularly monitor and test networks
- Must maintain information security policy
- Must implement strong access control measures
- Must maintain a secure network
- Must protect card holder data
Payment Card Industry Data Security Standard
PCI DSS
The PCI DSS standard covers any organization that directly accepts credit or debit card payments and applies to all entities involved in the card payment process
- Must maintain a vulnerability management program
- Must regularly monitor and test networks
- Must maintain information security policy
- Must implement strong access control measures
- Must maintain a secure network
- Must protect card holder data
Health Insurance Portability and Accountability Act (HIPAA)
HIPPA provides data privacy and protection of medical information. It specifies administrative, physical, and technical protection for all entities involved.
- Privacy rule
- Security rule
- Electronic transaction and code sets standards
- National identifier requirements
- Enforcement rule
Health Insurance Portability and Accountability Act (HIPAA)
HIPPA provides data privacy and protection of medical information. It specifies administrative, physical, and technical protection for all entities involved.
- Privacy rule
- Security rule
- Electronic transaction and code sets standards
- National identifier requirements
- Enforcement rule
Digital Millennium Copyright Act (DMCA)
The DMCA is a copyright law in the United States of America which implements the WIPO (World Intellectual Property Organization) Copyright Treaty and WIPO Performances and Phonograms Treaty.
Title I: WIPO Treaty Implementation
Title III: Computer Maintenance or Repair
Title IV: Miscellaneous Provisions
Title V: Protection of Certain Original Designs
Federal Information Security Management Act
FISMA
FISMA protects government information, operations, and assets against various threats.
- Standards for categorizing information and information systems by mission impact
- Standards for minimum security requirements for information and information systems
- Guidance for choosing appropriate security controls for information systems
- Guidance for assessing security controls in information systems
- Guidance for the security authorization of information systems
Federal Information Security Management Act
FISMA
FISMA protects government information, operations, and assets against various threats.