week 7 compliance

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/45

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:32 PM on 9/25/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

46 Terms

1
New cards
What are the three sources of compliance requirements?
Laws/regulations, industry standards and internal organisational policies.
2
New cards
What is the Privacy Act 1988?
Australian law regulating how covered organisations handle personal information.
3
New cards
Which businesses are generally covered by the Privacy Act?
Australian businesses with annual turnover above $3 million, plus certain exceptions regardless of turnover.
4
New cards
What is the NDB Scheme?
The Notifiable Data Breaches Scheme requires notification of eligible data breaches likely to cause serious harm.
5
New cards
What must an organisation do after suspecting an eligible data breach?
Assess it within 30 days and, if eligible, notify the OAIC and affected individuals as soon as practicable.
6
New cards
What does OAIC stand for?
Office of the Australian Information Commissioner.
7
New cards
What is the maximum serious Privacy Act penalty?
The greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover.
8
New cards
What does the Cyber Security Act require for ransomware payments?
Covered organisations must report ransomware or cyber-extortion payments within 72 hours.
9
New cards
Does the Cyber Security Act make paying ransomware automatically illegal?
No. It imposes reporting obligations; it does not create a general ban on payment.
10
New cards
What does SOCI stand for?
Security of Critical Infrastructure.
11
New cards
What does the SOCI Act protect?
Critical infrastructure such as energy, communications, finance, healthcare, water, transport and data services.
12
New cards
What are the SOCI cyber-incident reporting deadlines?
12 hours for significant-impact incidents; 72 hours for other relevant incidents.
13
New cards
What is a CIRMP?
A Critical Infrastructure Risk Management Program covering cyber, personnel, supply-chain and physical risks.
14
New cards
What does APRA stand for?
Australian Prudential Regulation Authority.
15
New cards
What does CPS 234 cover?
Information-security capability, asset classification, incident response and independent assurance.
16
New cards
What does CPS 230 cover?
Operational resilience, business continuity and management of critical third-party providers.
17
New cards
What does ACSC stand for?
Australian Cyber Security Centre.
18
New cards
What is the Essential Eight?
Eight ASD/ACSC mitigation strategies forming a baseline for reducing common cyber risks.
19
New cards
Name the Essential Eight.
Application control; patch applications; configure macros; application hardening; restrict admin privileges; patch operating systems; MFA; regular backups.
20
New cards
What are the Essential Eight maturity levels?
Levels 0–3, where higher levels provide stronger protection against more capable attackers.
21
New cards
What is GDPR and who can it apply to?
EU data-protection law that can apply to organisations handling the personal data of people in the EU/EEA.
22
New cards
What is the difference between a GDPR controller and processor?
The controller decides why and how data is processed; the processor handles it for the controller.
23
New cards
What does HIPAA protect?
Protected Health Information handled by covered US healthcare organisations and associates.
24
New cards
What does GLBA regulate?
US financial institutions through privacy-notice and information-safeguard requirements.
25
New cards
What does SOX require?
US public-company executives must ensure the accuracy of financial reporting and internal controls.
26
New cards
What is the documentation hierarchy?
Strategy → Policy → Standard → Procedure → Guideline.
27
New cards
What is the difference between a policy and procedure?
A policy states high-level rules or why; a procedure explains the steps or how.
28
New cards
What is fiduciary duty?
A duty to act honestly and in the best interests of another person or organisation.
29
New cards
What is the difference between due care and due diligence?
Due care means taking reasonable protective action; due diligence means continually investigating and verifying that protection.
30
New cards
What four internal controls help prevent fraud?
Separation of duties, job rotation, mandatory vacations and Acceptable Use Policies.
31
New cards
What is an Acceptable Use Policy (AUP)?
Rules explaining how employees may and may not use organisational systems and assets.
32
New cards
How does separation of duties reduce fraud?
It divides a critical process between people so one person cannot complete and conceal fraud alone.
33
New cards
How do job rotation and mandatory vacations help detect fraud?
Another employee performs the role, making hidden manipulation or irregularities easier to uncover.
34
New cards
What is PCI DSS?
An industry standard for organisations that store, process or transmit payment-card data.
35
New cards
What are the three PCI DSS process steps?
Assess → Remediate → Report.
36
New cards
What does a QSA do?
A Qualified Security Assessor evaluates an organisation’s PCI DSS compliance.
37
New cards
What is COBIT mainly used for?
Governance and management of enterprise information and technology.
38
New cards
What is COBIT’s key distinction?
Governance evaluates and directs; management plans, builds, runs and monitors.
39
New cards
What is ISO 27001?
The requirements standard for establishing an Information Security Management System.
40
New cards
What is ISO 27002?
Guidance and recommended information-security controls.
41
New cards
What is ISO 31000?
Guidelines for managing organisational risk.
42
New cards
What is NIST SP 800-30?
A guide for conducting risk assessments.
43
New cards
Scenario: a serious privacy breach may harm customers—what applies?
Assess under the NDB Scheme and notify the OAIC and affected people if it is eligible.
44
New cards
Scenario: a critical infrastructure incident significantly disrupts availability—when report?
Within 12 hours under SOCI.
45
New cards
Scenario: one employee creates and approves payments—what control is missing?
Separation of duties.
46
New cards
Scenario: an organisation needs an ISMS certification standard—which one?
ISO 27001.