Legal, Regulations, Standards Flashcards

1
Q

Patent

A

Grants ownership of an invention and provides enforcement for owner to exclude others from practicing the invention. After 20 years the idea is open source of application. 20 years from time of application. Invention must be:
Novel (no one has this idea before)
Useful (possible to use or useful to someone)
Nonobvious (inventive work)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Copyright

A

Granted 70 years after creators death or 95 years after creation (corporations). Automatic - no need registration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Trade Secret

A

Tell no one, but if discovered, not protected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Trademark (TM or (R).

A

Brands, logo, slogans - must be registered and renewable every 10 yrs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PCI-DSS

A

Payment Card Industry - Data Security Standard
requires merchants and others to meet minimum set of requirements - security policies, devices, control techniques and monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SOX

A

Sarbanes Oxley Act of 2002. Financial Reporting of public traded companies

after ENRON and World Online debacle Independent review by external accountants.
Section 302: CEO’s CFO’s can be sent to jail when information they sign is incorrect. CEO SIGN
Section 404 is the about internal controls assessment: describing logical controls over accounting files; good auditing and information security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

GLBA

A

Gramm-Leach-Bliley Act - For Financial institutions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

EU GDPR

A

The General Data Protection Regulation 2016/679 is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area. It also addresses the export of personal data outside the EU and EEA areas

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

HIPAA

A

Health Insurance Portability and Accountability Act
For Private Health Information by health insurers, providers
- 3 rules - Privacy rule, Security Rule and Breach notification rule
- mandates physical, admin and technical safeguards
- Risk Analysis is required

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Security Breach Notification

A

Each US state has different laws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

ECPA

A

Electronic Communications Privacy Act

protect against warrantless wiretaping

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

PATRIOT ACT

A

Expands law enforcement electronic monitoring capabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

CFAA

A

Computer Fraud and Abuse Act

- most commonly used law to prosecute computer crimes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

OECD Privacy Guidelines

A

30 member guidelines for protecting privacy (including US)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Wassenaar Arrangement

A

Export/Import of arms and dual-use goods and technologies

  • cryptology is dual use
  • Iran, Iraq, China, Russia has strict import on too strong encryption
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ISC2 Preamble

A

The safety and welfare of society and common good, duty to our principles and to each other requires that we adhere, and be seen to adhere to the highest ethical standard of behavior

17
Q

Canons

A
  1. Protect society, common good, necessary public trust and confidence, and the infrastructure
  2. Act honorably, justly, honestly, responsibly, legally
  3. Provide diligent and competent service to our principles
  4. advance and protect the profession
18
Q

OCTAVE

A

Operationally Critical Threat, Asset, Vulnerability Evaluation - Self Directed Risk Mgt
is a security framework for determining risk level and planning defenses against cyber assaults. The framework defines a methodology to help organizations minimize exposure to likely threats, determine the likely consequences of an attack and deal with attacks that succeed.

19
Q

ITIL

A

Info Technology Infra Library - set of practices for IT Service Mgt

20
Q

COBIT

A

Control Objectives for IT
- Goals for IT - stakeholder needs mapped to IT related goals
COBIT provides an implementable “set of controls over information technology and organizes them around a logical framework of IT-related processes and enablers

21
Q

COSO

A

Committee of Sponsoring Organisations
- Goals for entire organisation

Dedicated to providing thought leadership through the development of frameworks and guidance on enterprise risk management, internal control, and fraud deterrence.

22
Q

FRAP

A

Facilitated Risk Analysis Process
FRAP analyzes one system, application or segment of business processes at a time. FRAP assumes that additional efforts to develop precisely quantified risks are not cost effective because: such estimates are time consuming.

23
Q

ISO/IEC 27000

A

Information security management systems — Overview and vocabulary[

24
Q

ISO/IEC 27001

A

ISMS Requirements

25
Q

ISO/IEC 27002

A

Code of practice for ISMS

26
Q

ISO/IEC 27003

A

Implementable guidelines for ISMS

27
Q

ISO/IEC 27004

A

Monitor, measurement, analysis, evaluation for ISMS

28
Q

ISO/IEC 27005

A

Standards based approach to risk mgt

29
Q

ISO/IEC 27799

A

Directives on protecting PHI

30
Q

ISO/IEC 15408

A

Common Criteria
framework in which computer system users can specify their security functional and assurance requirements

Defines a protection profile that specifies the security requirements and protections of a product that is to be evaluated.

Products can be certified

  • EAL0 –Inadequate assurance
  • EAL1 –Functionally tested
  • EAL2 –Structurally tested
  • EAL3 –Methodically tested and checked
  • EAL4 –Methodically designed, tested and reviewed
  • EAL5 –Semi formally designed and tested
  • EAL6 –Semi formally verified design and tested
  • EAL7 –Formally verified design and tested
31
Q

ISO/IEC 21827

A

SSE-CMM (Maturity Model)