Regulations Flashcards
ISO/IEC 27001
Provides a framework for implementing an information security management system (ISMS). 14 Domains
ISO/IEC 15408
Establishes common criteria for evaluating IT security capabilities and assurance.
Evaluation Assurance Level (EAL)
Seven levels of IT security assurance, from functionally tested (EAL1) to formally verified (EAL7).
ISO/IEC 27701
Extends ISO 27001 for privacy information management, aligning with global privacy standards.
NIST SP 800-53
Outlines security and privacy controls for federal and enterprise information systems.
PCI DSS
Sets standards for securing payment card transactions and protecting cardholder data.
GDPR
General Data Protection Regulation for EU citizens’ personal data privacy and security.
CCPA
California Consumer Privacy Act protects residents’ data and grants opt-out rights.
LGPD
Brazil’s General Data Protection Law governs data privacy and rights similar to GDPR.
HIPAA
Regulates security and privacy of healthcare data in the U.S.
PIPEDA
Personal Information Protection and Electronic Documents Act governs data privacy in Canada.
SOX (Sarbanes-Oxley Act)
Ensures accurate financial reporting and protects shareholders against fraud.
CMMC
Cybersecurity Maturity Model Certification ensures supply chain security for U.S. defense sector.
COBIT
Framework for managing and governing enterprise IT to align with business goals.
CSA STAR
Cloud Security Alliance Security, Trust, and Assurance Registry evaluates cloud providers.