week 7 compliance - shorter

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/36

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:37 PM on 9/25/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

37 Terms

1
New cards

What are the three sources of compliance?

Laws, industry standards and internal policies.

2
New cards

What does the Privacy Act regulate?

How covered Australian organisations handle personal information.

3
New cards

Who generally falls under the Privacy Act?

Government agencies and businesses earning over $3 million, plus exceptions.

4
New cards

What is the NDB Scheme?

Reporting eligible data breaches likely to cause serious harm.

5
New cards

What is the NDB assessment deadline?

Within 30 days.

6
New cards

Who is notified of an eligible data breach?

The OAIC and affected individuals.

7
New cards

What does OAIC stand for?

Office of the Australian Information Commissioner.

8
New cards

What is the maximum serious Privacy Act penalty?

Greater of $50m, 3× benefit, or 30% adjusted turnover.

9
New cards

What must be reported under the Cyber Security Act?

Covered ransomware payments within 72 hours.

10
New cards

Are ransomware payments automatically illegal?

No; covered payments must be reported.

11
New cards

What does SOCI stand for?

Security of Critical Infrastructure.

12
New cards

What are the SOCI reporting deadlines?

12 hours for significant impact; otherwise 72 hours.

13
New cards

What is a CIRMP?

A program managing critical infrastructure risks.

14
New cards

What does CPS 234 cover?

Information security and cyber resilience.

15
New cards

What does CPS 230 cover?

Operational resilience and third-party risk.

16
New cards

What does ACSC stand for?

Australian Cyber Security Centre.

17
New cards

What are the Essential Eight?

Apps, app patches, macros, hardening, admin, OS patches, MFA, backups.

18
New cards

What are the Essential Eight maturity levels?

Levels 0–3.

19
New cards

What is GDPR?

EU law protecting personal data.

20
New cards

Controller vs processor under GDPR?

Controller decides why/how; processor handles data for it.

21
New cards

What does HIPAA protect?

US protected health information.

22
New cards

What does GLBA regulate?

Privacy and security in US financial institutions.

23
New cards

What does SOX regulate?

Financial reporting controls in US public companies.

24
New cards

What is the document hierarchy?

Strategy → Policy → Standard → Procedure → Guideline.

25
New cards

Policy vs procedure?

Policy states the rule; procedure explains the steps.

26
New cards

What is fiduciary duty?

A duty to act in another party’s best interests.

27
New cards

Due care vs due diligence?

Take reasonable action vs continually investigate and verify.

28
New cards

What four controls help prevent fraud?

Separation of duties, job rotation, vacations and AUP.

29
New cards

What is an AUP?

Rules for acceptable use of organisational assets.

30
New cards

What is PCI DSS?

Security standard for payment-card data.

31
New cards

What are PCI DSS’s three steps?

Assess → Remediate → Report.

32
New cards

What is COBIT?

Framework for governing and managing enterprise IT.

33
New cards

COBIT: governance vs management?

Governance directs; management implements.

34
New cards

What is ISO 27001?

Requirements for an information security management system.

35
New cards

What is ISO 27002?

Guidance on information-security controls.

36
New cards

What is ISO 31000?

Risk-management guidance.

37
New cards

What is NIST SP 800-30?

A guide for conducting risk assessments.