Regulations Flashcards

1
Q

ISO/IEC 27001

A

Provides a framework for implementing an information security management system (ISMS). 14 Domains

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ISO/IEC 15408

A

Establishes common criteria for evaluating IT security capabilities and assurance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Evaluation Assurance Level (EAL)

A

Seven levels of IT security assurance, from functionally tested (EAL1) to formally verified (EAL7).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ISO/IEC 27701

A

Extends ISO 27001 for privacy information management, aligning with global privacy standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

NIST SP 800-53

A

Outlines security and privacy controls for federal and enterprise information systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

PCI DSS

A

Sets standards for securing payment card transactions and protecting cardholder data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

GDPR

A

General Data Protection Regulation for EU citizens’ personal data privacy and security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CCPA

A

California Consumer Privacy Act protects residents’ data and grants opt-out rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

LGPD

A

Brazil’s General Data Protection Law governs data privacy and rights similar to GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

HIPAA

A

Regulates security and privacy of healthcare data in the U.S.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

PIPEDA

A

Personal Information Protection and Electronic Documents Act governs data privacy in Canada.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SOX (Sarbanes-Oxley Act)

A

Ensures accurate financial reporting and protects shareholders against fraud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

CMMC

A

Cybersecurity Maturity Model Certification ensures supply chain security for U.S. defense sector.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

COBIT

A

Framework for managing and governing enterprise IT to align with business goals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

CSA STAR

A

Cloud Security Alliance Security, Trust, and Assurance Registry evaluates cloud providers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

IEC 62443

A

Standards for securing industrial automation and control systems against cyber threats.

17
Q

SOC 1

A

Focuses on financial reporting controls and their effectiveness for auditors and organizations.

18
Q

SOC 2

A

Evaluates controls for security, availability, processing integrity, confidentiality, and privacy.

19
Q

SOC 3

A

General-use report of SOC 2 compliance for public sharing without detailed control information.

20
Q

FIPS 140-2

A

U.S. standard for cryptographic modules, with 4 levels of security for safeguarding data.

21
Q

FIPS 140-2 Levels

A

Level 1: Basic security requirements.
Level 2: Tamper-evident features required.
Level 3: Physical security to prevent tampering.
Level 4: Complete security against physical/logical attacks.

22
Q

ISO/IEC 27017

A

Provides guidelines for information security controls specific to cloud services.

23
Q

GLBA

A

Requires financial institutions to protect consumer data and provide privacy notices.

24
Q

ISO/IEC 27018

A

Protection of PII in Public Cloud

25
Q

ISO/IEC 27050

A

Electronic Discovery (eDiscovery)

26
Q

ISO/IEC 11900

A

Coding of Audio-Visual Objects

27
Q

ISO/IEC 11889

A

Trusted Platform Module (TPM) Standard

28
Q

ISO/IEC 20000-1

A

ITIL like

29
Q

ISO/IEC 19011

A

Guidelines for Auditing Management Systems

30
Q

ISO/IEC 18772

A

Guidance on Managing Personal Financial Planning