1/36
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What are the three sources of compliance?
Laws, industry standards and internal policies.
What does the Privacy Act regulate?
How covered Australian organisations handle personal information.
Who generally falls under the Privacy Act?
Government agencies and businesses earning over $3 million, plus exceptions.
What is the NDB Scheme?
Reporting eligible data breaches likely to cause serious harm.
What is the NDB assessment deadline?
Within 30 days.
Who is notified of an eligible data breach?
The OAIC and affected individuals.
What does OAIC stand for?
Office of the Australian Information Commissioner.
What is the maximum serious Privacy Act penalty?
Greater of $50m, 3× benefit, or 30% adjusted turnover.
What must be reported under the Cyber Security Act?
Covered ransomware payments within 72 hours.
Are ransomware payments automatically illegal?
No; covered payments must be reported.
What does SOCI stand for?
Security of Critical Infrastructure.
What are the SOCI reporting deadlines?
12 hours for significant impact; otherwise 72 hours.
What is a CIRMP?
A program managing critical infrastructure risks.
What does CPS 234 cover?
Information security and cyber resilience.
What does CPS 230 cover?
Operational resilience and third-party risk.
What does ACSC stand for?
Australian Cyber Security Centre.
What are the Essential Eight?
Apps, app patches, macros, hardening, admin, OS patches, MFA, backups.
What are the Essential Eight maturity levels?
Levels 0–3.
What is GDPR?
EU law protecting personal data.
Controller vs processor under GDPR?
Controller decides why/how; processor handles data for it.
What does HIPAA protect?
US protected health information.
What does GLBA regulate?
Privacy and security in US financial institutions.
What does SOX regulate?
Financial reporting controls in US public companies.
What is the document hierarchy?
Strategy → Policy → Standard → Procedure → Guideline.
Policy vs procedure?
Policy states the rule; procedure explains the steps.
What is fiduciary duty?
A duty to act in another party’s best interests.
Due care vs due diligence?
Take reasonable action vs continually investigate and verify.
What four controls help prevent fraud?
Separation of duties, job rotation, vacations and AUP.
What is an AUP?
Rules for acceptable use of organisational assets.
What is PCI DSS?
Security standard for payment-card data.
What are PCI DSS’s three steps?
Assess → Remediate → Report.
What is COBIT?
Framework for governing and managing enterprise IT.
COBIT: governance vs management?
Governance directs; management implements.
What is ISO 27001?
Requirements for an information security management system.
What is ISO 27002?
Guidance on information-security controls.
What is ISO 31000?
Risk-management guidance.
What is NIST SP 800-30?
A guide for conducting risk assessments.