Regulations Flashcards
ISO/IEC 27001
Provides a framework for implementing an information security management system (ISMS). 14 Domains
ISO/IEC 15408
Establishes common criteria for evaluating IT security capabilities and assurance.
Evaluation Assurance Level (EAL)
Seven levels of IT security assurance, from functionally tested (EAL1) to formally verified (EAL7).
ISO/IEC 27701
Extends ISO 27001 for privacy information management, aligning with global privacy standards.
NIST SP 800-53
Outlines security and privacy controls for federal and enterprise information systems.
PCI DSS
Sets standards for securing payment card transactions and protecting cardholder data.
GDPR
General Data Protection Regulation for EU citizens’ personal data privacy and security.
CCPA
California Consumer Privacy Act protects residents’ data and grants opt-out rights.
LGPD
Brazil’s General Data Protection Law governs data privacy and rights similar to GDPR.
HIPAA
Regulates security and privacy of healthcare data in the U.S.
PIPEDA
Personal Information Protection and Electronic Documents Act governs data privacy in Canada.
SOX (Sarbanes-Oxley Act)
Ensures accurate financial reporting and protects shareholders against fraud.
CMMC
Cybersecurity Maturity Model Certification ensures supply chain security for U.S. defense sector.
COBIT
Framework for managing and governing enterprise IT to align with business goals.
CSA STAR
Cloud Security Alliance Security, Trust, and Assurance Registry evaluates cloud providers.
IEC 62443
Standards for securing industrial automation and control systems against cyber threats.
SOC 1
Focuses on financial reporting controls and their effectiveness for auditors and organizations.
SOC 2
Evaluates controls for security, availability, processing integrity, confidentiality, and privacy.
SOC 3
General-use report of SOC 2 compliance for public sharing without detailed control information.
FIPS 140-2
U.S. standard for cryptographic modules, with 4 levels of security for safeguarding data.
FIPS 140-2 Levels
Level 1: Basic security requirements.
Level 2: Tamper-evident features required.
Level 3: Physical security to prevent tampering.
Level 4: Complete security against physical/logical attacks.
ISO/IEC 27017
Provides guidelines for information security controls specific to cloud services.
GLBA
Requires financial institutions to protect consumer data and provide privacy notices.
ISO/IEC 27018
Protection of PII in Public Cloud
ISO/IEC 27050
Electronic Discovery (eDiscovery)
ISO/IEC 11900
Coding of Audio-Visual Objects
ISO/IEC 11889
Trusted Platform Module (TPM) Standard
ISO/IEC 20000-1
ITIL like
ISO/IEC 19011
Guidelines for Auditing Management Systems
ISO/IEC 18772
Guidance on Managing Personal Financial Planning