Section 5.2 Regulations, Standards, and Frameworks Flashcards
What do you call any information that isn’t public or unclassified?
Sensitive Data
What do you call any information that can identify an individual (name, SSN, birthdate/place, biometric records, etc…)
PII
What do you call health information that can be related to a specific person?
Protected Health Information (PHI)
What regulation deals with the handling of data while maintaining privacy rights of an individual? Applies to any company with customers in the EU
GDPR
What do you call the process of removing all relevant data so that it is impossible to identify original subject or person?
Anonymization
What process could reduce or eliminate GDPR requirements?
Anonymization
What do you call the process of using pseudonyms (aliases) to represent other data? Can result in less stringent requirements than would otherwise apply under the GDPR.
Pseudonymization
What law is focused on services of banks, lenders, and insurance?
Gramm-Leach-Bliley Act (GLBA)
What act requires that government agencies include the activities of contractors in their security management programs?
Federal Information Security Management Act (FISMA)
What do you call a widely accepted set of policies and procedures intended to optimize the security of credit, debt, and cash card transactions?
PCI DSS
What do you call a not-for-profit organization that publishes information on cybersecurity best practice and threats? Provides benchmarks for different operating systems and provides controls to help secure your organization.
Center for Internet Security (CIS)
What is a set of guidelines and best practices to help organizations build and improve their cybersecurity posture? Aimed at private industry (commercial business)
Cyber Security Framework (CSF)
Which ISO is Security techniques for Information Security Management Systems: an international standard on how to manage information security?
ISO 27001
Which ISO is a Code of Practice for Information Security Controls, which aims to improve the management of information.
ISO 27002
Which ISO is an extension to 27001/27002 for Privacy Information Management - provides guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management Systems (PIMS)
ISO 27701