Section 4: Policies and Frameworks Flashcards
HIPAA
Health Insurance Portability and Accountability Act (HIPAA)
▪ Affects healthcare providers, facilities, insurance companies, and medical data clearing houses
Sarbanes-Oxley (SOX)
Publicly traded U.S. corporation are affected by this regulation and must follow certain accounting methods and financial reporting
GLBA
Affects the security of personal identifiable information, prohibits sharing financial information with any third-parties, and provides guidelines for securing that financial information
FISMA
Federal Information Security Management Act of 2002 (FISMA)
▪ Affects federal agencies and require them to develop, document, and implement an agency-wide information systems security program
FERPA
Family Educational Rights and Privacy Act (FERPA)
▪ A federal law that protects the privacy of student education records
COPPA
o Children’s Online Privacy Protection Act (COPPA)
▪ Imposes certain requirements on websites owners and online services that are directed to children under 13 years of age
▪ COPPA can put a ton of extra requirements on companies trying to serve younger markets with educational content
GDPR
General Data Protection Regulation (GDPR)
▪ It states that personal data cannot be collected, processed or retained without the individual’s informed consent
▪ GDPR provides a provision in the law to ensure a user has the right to withdraw their consent at any time
SLA
This agreement is concerned with the ability to support and respond to problems within a given timeframe while providing the agreed upon level of service to the user
MSA
This is an agreement for future agreements, allowing the organizations involved to negotiate future contracts much more quickly since they can reference the Master Service Agreement
NDA
Signed between two parties and define what data is considered
confidential and cannot be shared outside of the relationship
MOU
A non-binding agreement between two or more organizations to detail an intended common line of action
BPA
Conducted between two business partners and establishes the conditions of their relationship