Security and Risk Management Flashcards
What are the four main types of compliance obligations?
Criminal law, Civil Law, Administrative Law, Private Regulations
What sets Criminal law apart from the other types of law?
Violations of criminal law may be punishable by jail
What are the most common results of Civil law cases?
Monetary payments, or refraining from an action
What does Administrative law provide?
Procedural rules and regulations where missing from civil or criminal law
What gives Private regulations their power?
Contractual obligations such as PCI compliance
What is the most common intersection of security and the constitution?
The fourth ammendment
What does the fourth amendment state?
A person has a right against unlawful searches and seizures
What are the three HIPAA covered entities?
Healthcare providers, health insurers, and health information clearinghouses
FERPA regulations protect what?
Handling of student records, provides right of inspection, right to request corrections, restricts release
What does the Gram-Leach Billey Act (GLBA) cover?
Financial services sector
What does GLBA require?
Written information security program, designated security officer, limitations of file sharing
Children’s online privacy protection act (COPPA) protects children under 13 how?
Requires websites have a privacy policy, provides for parental inspection and deletion, as well as consent
Privacy act of 1974 restricts the sharing of information for who?
Federal organizations only
Computer Fraud and Abuse ACT (CFFA) makes what a federal offense?
Unauthorized access to any machine that is engaged in interstate commerce
Electronic Communications Privacy Act (ECPA) does what?
Restricts government interception of communications