Concise Laws/Regs

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/74

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:49 AM on 10/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

75 Terms

1
New cards

FIPS 140-2

A detailed federal government standard for cryptographic modules, including HSMs.

A U.S. government encryption standard, and vendors often ensure that their hardware and software is FIPS 140‐2‐certified.

2
New cards

What is an accounting report on controls at a service organization that replaces older SAS 70 type reports?

A. SOC 1

B. SSAE 18

C. GAAP

D. SOC 2

Explanation

A. SOC 1

An accounting report is specifically about financials.

❌ SSAE 18 sounds right but doesn’t provide specifically an accounting report. It provides an attestation from CPAs/accountants.

3
New cards

CCM

Cloud Controls Matrix.

A security controls framework that provides mapping/cross relationships with the main industry‐accepted security standards, regulations, and controls frameworks such as the ISO 27001/27002, ISACA’s COBIT, and PCI‐DSS

The CCM cross‐references many industry standards, laws, and guidelines.

4
New cards

PIPEDA

The Personal Information Protection and Electronic Documents Act is a Canadian law relating to data privacy.

5
New cards

NIST Five Essential Characteristics of Cloud Computing

On-demand self-service, Broad network access, Resource pooling, Rapid elasticity, Measured service

6
New cards

NERC/CIP

The North American Electric Reliability Corporation’s Critical Infrastructure Program (NERC/CIP) provides security standards for electric utilities and other elements of critical infrastructure.

7
New cards

FISMA

The Federal Information Security Management Act (FISMA)

Managing federal government/agencies information security, including government contractors

For example, even though Company X is a private company, if it's operating with/on behalf of the government, FISMA requirements can therefore apply to that contractor/company.

8
New cards

CALEA


The Communications Assistance to Law Enforcement Act (CALEA) requires that all communications carriers make wiretaps possible for law enforcement officials who have an appropriate court order.

Requires that communications service providers cooperate with law enforcement requests

9
New cards

COBIT

The Control Objectives for Information Technology (COBIT) provide a generalized/broad governance/management framework for IT organizations.

10
New cards

ISO 27701

Provides control guidance for privacy programs.

How personal information is handled, privacy risks.

ISO 27001 → ISMS = Information Security Management System

ISO 27701 → PIMS = Privacy Information Management System

11
New cards

ISO 9000

Quality management

12
New cards

ISO 22301

Defines business continuity plans, systems, and processes

13
New cards

ISO 27001

Requirements for an Information security management system (ISMS)

Can be audited against to provide a certification that an organization has a holistic, comprehensive program of internal security controls.

14
New cards

ISO 27002

Guidance for security controls for ISMS

15
New cards

ISO 27017

Cloud security controls and guidance

16
New cards

ISO 27018

Cloud privacy

PII/privacy in public clouds

8=P, P for Privacy or PII.

17
New cards

ISO 20000-1

IT services, operational controls, ITIL, COBIT, IT service management

Concerned with managing IT services/Service Management Systems (SMS) effectively

NOT security related

18
New cards

ISO 27034

Application security.

Relevant to secure application development/application lifecycle security.

ONF, ANF

19
New cards

ONF

Organizational Normative Framework

The organization's centralized repository/framework for application-security information and controls.

20
New cards

ANF

Application Normative Framework

Security framework for a specific application

21
New cards

ONF vs ANF

ONF = organization's overall application-security framework

ANF = security framework for a specific application

22
New cards

ISO 27037, 27041, 27042, 27043

27037: Collecting, identifying, and preserving electronic evidence

27041: Validate proper tools/methods

27042: Digital evidence analysis

27043: Incident investigation principles and processes

23
New cards

What are the 4 ISO standards for handling digital evidence?

ISO 27037, 27041, 27042, 27043

24
New cards

ISO 27037

Guide for collecting, identifying, and preserving electronic evidence

25
New cards

ISO 27041

Validate proper tools/methods

26
New cards

ISO 27042

Guide for digital evidence analysis

27
New cards

ISO 27043

Incident investigation principles and processes

28
New cards

ISO 27050-1

Overview and principles for eDiscovery

29
New cards

ISO 28000

Supply chain security

30
New cards

ISMS = ___ ___

ISO 27001

31
New cards

ISO 31000

Risk Management

A general risk-management framework

Not a certifiable standard

Only provides guidance

32
New cards

ISO 31010

Risk Assessment Techniques

Provides guidance for selecting/applying techniques for assessing risk in different situations.

"What techniques can we use to assess risk?"

33
New cards

ISO 15408

Common Criteria/EAL

Establishes concepts/principles for evaluating the security properties/security-certifying of IT products.

Common Criteria uses Protection Profiles and Security Targets to define what security requirements are being evaluated.

34
New cards

ISO 17788

Cloud Computing Overview and Vocabulary

Provides an overview of cloud computing and establishes cloud-computing terminology and definitions.

NOT a security-controls standard.

35
New cards

ISO 18788

Establishes requirements for a management system (how it’s managed) for private security operations.

Makes sure a private security organization has a structured, controlled, and accountable way of operating.

36
New cards

ISO 18788 5 Phases:

Policy: Establish organizational commitment/direction

Planning: Determine objectives, risks, programs, and plans

Implementation and Operation: Put the plans into practice

Performance Evaluation: Measure/monitor how things are performing

Management Review: Leadership reviews results and determines needed changes

37
New cards

In ISO 18788:2015 — Management System for Private Security Operations – Requirements with Guidance for Use, at which phase of continual improvement is the need for changes considered?

A. Policy

B. Management Review

C. Performance Evaluation

D. Implementation and Operation

B. Management Review

❌ Performance Eval is a measure/monitor how things are performing

38
New cards

In ISO 18788:2015 Management System for Private Security Operations – Requirements with Guidance for Use, at which phase of continual improvement are strategic programs and risk assessments completed?

A. Implementation and Operation

B. Planning

C. Policy

D. Performance Evaluation

B. Planning

❌ Risk assessments are done in the planning phase. You have to PLAN for potential risks in advance. Strategic programs to complete objectives are also completed in the Planning phase.

❌ Risk assessments should be done BEFORE anything is implemented.

❌ Performance Eval measured how well things are performing. It doesn't have anything to do with risk assessments.

39
New cards

Uptime Institute (UI)

About data-center infrastructure availability/resilience

40
New cards

UI Tier 1

Basic Site Infrastructure

Maintenance requires shutting down facility

Will be affected by infrastructure failures

Useful as a backup

Hot/warm/cold site

Cheaper to operate

41
New cards

UI Tier 2

Redundant Capacity

Good for operating in public cloud environment

Low overhead

42
New cards

UI Tier 3

Concurrently Maintainable

Maintenance can occur without shutting down IT operations.

Critical operations can continue during infrastructure failure

Multiple distribution paths

43
New cards

UI Tier 4

Fault tolerant

44
New cards

ECPA

Electronic Communications Privacy Act of 1986

Privacy of electronic communications

U.S. federal law concerning privacy/protection of wire, oral, and electronic communications.

45
New cards

FERPA

Family Educational Rights and Privacy Act

Gives parents rights concerning their children's education records, including:

Access to records, Requesting amendments, Disclosure of PII

46
New cards

FedRAMP

Federal Risk and Authorization Management Program

Provides a standardized approach to assessing and authorizing cloud computing products and services used by federal agencies.

Think → Federal government + cloud services/products

Intended to standardize security assessment and authorization of cloud services for federal use.

47
New cards

SOX

Sarbanes-Oxley Act - Requires publicly traded corporations to provide info about their financial status and implement controls to ensure accuracy

Enacted to protect shareholders and the public from enterprise accounting errors and fraudulent practices.

US Federal Law. Does not apply to other countries.

48
New cards

CLOUD Act

Clarifying Lawful Overseas Use of Data Act

Concerns government/law enforcement access to electronic data when data is stored across borders/countries.

International data.

49
New cards

SOC

System and Organization Controls

SOC reports provide assurance regarding controls at a service organization.

50
New cards

Belinda is auditing the financial controls of a manufacturing company and learns that the financial systems are run on a major IaaS platform. She would like to gain assurance that the platform has appropriate security controls in place to assure the accuracy of her client’s financial statements. What action should she take?

A. Perform an IT audit of the cloud provider.

B. Obtain a SOC 1 report.

C. Obtain a SOC 2 report.

D. Continue testing only controls at the client and note the use of the cloud provider in her report.

B. Obtain a SOC 1 report.

❌ SOC 2 is tempting, because it mentions “security controls”, but SOC 2 has nothing to do with proving the accuracy of financials.

51
New cards

SOC 1

Controls (security, access, processing, etc.) relevant to accurate, complete, and reliable financial reporting.

Provides an accounting report on controls at a service organization and replaces SAS 70 type reports.

2 subclasses (Type 1, 2)

52
New cards

SOC Type 1

Controls are suitably designed at a point in time

Type 1 tells you: "Were the controls appropriately designed on this date?"

53
New cards

SOC Type 2

Controls are suitably designed and operated effectively over a period of time

SOC 1 Type 2 is “Were the financial controls done properly over this period of time?”

SOC 2 Type 2 is “Were the security controls done properly over this period of time?”

54
New cards

SOC 2

Security/privacy/operational controls

Concerned with controls related to the Trust Services Criteria:

Security, Availability, Processing integrity, Confidentiality, Privacy

Includes Business Continuity measures (Availability)

55
New cards

The 5 Trust Services Criteria

Security, Availability, Processing integrity, Confidentiality, Privacy

56
New cards

SOC 3

Reports designed to be shared with the public/general use

“Seal of approval”

Has no data about the security controls

An assertion the audit was conducted and passed

57
New cards

Your organization is evaluating a provider's service offerings and wants to ensure that the provider can fulfill your organization's long-term financial commitments and stay operational. What report should your organization review?

A. Audited financials or due diligence assessments, and SOC 2

B. Type 1

C. Service Organization Control (SOC) 1

D. Type 2

A.

❌ Just SOC 1 does not provide information on whether the provider will stay operational in the long term.

❌ Type 2 tells you operational efficiency over a period of time, but not financials

❌ Type 1 tells you controls designed at a specific point in time, not over time/long term.

58
New cards

SSAE 18

Statement on Standards for Attestation Engagements

U.S. rules/standards for performing attestation engagements - when an independent CPA/accountant examines a company's controls and provides an assurance report about them.

Can be done on cloud providers. Done by independent, external audit firms.

Uses a framework, including SOC 1, SOC 2, and SOC 3 reports.

59
New cards

ISAE 3402

International Standard on Assurance Engagements 3402

It addresses assurance reports on controls at service organizations.

Used to guide SOC audits outside the United States

60
New cards

NIST SP 800-37

The Risk Management Framework (RMF)

Used by federal government agencies to manage enterprise risk

61
New cards

NIST 800-145

The NIST Definition of Cloud Computing

It defines the five essential characteristics (On-demand self-service, Broad network access, Resource pooling, Rapid elasticity, Measured service),

SaaS, IaaS, PaaS,

And the four deployment models (private, community, hybrid, public).

62
New cards

NIST 800-146

Cloud Computing Synopsis and Recommendations

It discusses Cloud-computing benefits, Open issues, Major classes of cloud technology, Opportunities, Risks and Recommendations for cloud computing

63
New cards

NIST 800-145 vs NIST 800-146

800-145 = Definition

800-146 = Recommendations/risks

64
New cards

NIST 800-92

Log management

65
New cards

NIST 800-40

Enterprise patch management

66
New cards

NIST 500-292

NIST Cloud Computing Reference Architecture

The architecture/roles/components of cloud computing, providing a framework for describing cloud services and their components.

"What does the cloud architecture look like?"

67
New cards

GLBA

The Gramm-Leach-Bliley Act

U.S. federal law primarily concerned with protecting consumers' nonpublic personal information (NPI) held by financial institutions.

68
New cards

The 3 Big Import/Export Restrictions

ITAR, EAR, The Wassenaar Arrangement

69
New cards

ITAR

International Traffic in Arms Regulations – US

State department prohibits defense-related exports (includes cryptography systems)

70
New cards

EAR

Export Administration Regulations – US

Department of Commerce prohibits dual-use items (tech used for both commercial/ military purposes)

71
New cards

The Wassenaar Arrangement

Group of 41 members mutually agreed to inform each other about conventional military shipments to nonmember countries

Not a treaty, not legally binding, not a US law

May require org to notify government to stay within compliance

International agreement/framework for export controls

72
New cards

GAPP

Generally Accepted Privacy Principles

Addresses how an organization should handle personal information.

It's a set of privacy principles used to evaluate and manage how organizations handle personal information.

73
New cards

In the Association of International Certified Professional Accountants (AICPA) Generally Accepted Privacy Principles, which principle indicates that your organization defines, documents, and communicates its privacy policies and procedures?

A. Management

B. Collection

C. Notice

D. Access

A. Management

❌ Notice is to tell people how their information is collected and used.

74
New cards

In the Association of International Certified Professional Accountants (AICPA) Generally Accepted Privacy Principles, which principle allows individuals to review and correct their information?

A. Management

B. Quality

C. Access

D. Security

C. Access

❌ Quality is the organization's responsibility to ensure. Not the individual's whos data it is.

❌ Security has to do with how the organization has protected private information. It doesn't have anything to do with correcting wrong information.

75
New cards

Which organization develops cybersecurity standards and guidance?

NIST