D320 Laws and Regulations

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/79

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:05 AM on 9/4/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

80 Terms

1
New cards

(ISC)2

International Information System Security Certification Consortium. A security certification granting organization with a long history of certifications that were difficult to get. This difficulty has made their certificates seen as having higher value in the industry.

2
New cards

Administrative Law

Law created and enforced by executive branch agencies rather than directly by legislatures.

3
New cards

SAS 70

Statement on Auditing Standards No. 70. A recognized standard of the American Institute of Certified Public Accountants in response to issues that also led to Sarbanes-Oxley. It was deprecated in 2011 by Statement on Standards for Attestation Engagements No. 16.

4
New cards

AICPA

American Institute of Certified Public Accountants. The organization that established SAS 70 and later SSAE 16.

5
New cards

COPA

Child Online Protection Act. An attempt to restrict access by minors to material defined as harmful to minors. A permanent injunction against the law was issued in 2009.

6
New cards

Cloud Security Alliance Notorious Nine

Nine cloud security threats published by the Cloud Security Alliance:

Data Breaches

Data Loss

Account or Service Traffic Hijacking

Insecure Interfaces and APIs

Denial of Service

Malicious Insiders

Abuse of Cloud Services

Insufficient Due Diligence

Shared Technology Vulnerabilities.


7
New cards

CSA

Cloud Security Alliance. An organization associated with cloud security frameworks and programs such as STAR, CAIQ, and the Cloud Controls Matrix.

8
New cards

CSA STAR

Cloud Security Alliance Security, Trust, and Assurance Registry. A cloud security assurance program that uses tools such as the Consensus Assessments Initiative Questionnaire, Cloud Controls Matrix, and GDPR Self-Assessment.

9
New cards

CSA STAR Level 1

Uses the Consensus Assessments Initiative Questionnaire, Cloud Controls Matrix, and GDPR Self-Assessment as inputs to certify an organization to Level 1.

10
New cards

CSA STAR Level 2

Integrates the CSA Cloud Controls Matrix and AICPA Trust Service Principles for STAR attestation.

11
New cards

CSA STAR Certification

Uses the CSA Cloud Controls Matrix and the requirements of the ISO/IEC 27001 management system standard. Certification certificates follow normal ISO/IEC 27001 protocol for a third-party assessment.

12
New cards

CSA CCM

Cloud Security Alliance Cloud Controls Matrix. Composed of 17 domains covering key elements of cloud security and containing 170 objectives within those domains. It integrates with the STAR program.

13
New cards

COBIT

Control Objectives for Information and Related Technologies. A framework for IT governance and management. Initially used to achieve compliance with Sarbanes-Oxley and focused on IT controls. Since 2019, the emphasis has shifted to information governance.

14
New cards

COBIT's Five Principles

Meeting Stakeholder Needs; Covering the Enterprise End-to-End; Applying a Single Integrated Framework; Enabling a Holistic Approach; and Separating Governance from Management.

15
New cards

Common Criteria

A standard used to evaluate IT products. Products are evaluated by an independent laboratory and assigned an Evaluation Assurance Level based on the degree and type of testing.

16
New cards

EAL

Evaluation Assurance Level. A rating assigned to an IT product after it has been evaluated by an independent laboratory. Level 1 is the least and Level 7 is the most.

17
New cards

Common Criteria Functional Requirements

Common Criteria contains 60 functional requirements in 11 classes and is an accepted standard among military organizations of the United States and many allies.

18
New cards

CAIQ

Consensus Assessments Initiative Questionnaire. A Cloud Security Alliance initiative that provides industry-accepted documentation of security controls and, as of 2020, is combined with the Cloud Controls Matrix. It can be used as evidence for entry to the CSA STAR registry.

19
New cards

CLOUD Act

Clarifying Lawful Overseas Use of Data. U.S. law that allows law enforcement and courts to compel U.S. companies to provide data stored in foreign data centers under applicable legal authority.

20
New cards

DMCA

Digital Millennium Copyright Act. An act intended to align U.S. copyright law with the requirements of treaties and the World Intellectual Property Organization.

21
New cards

ENISA

European Union Agency for Cybersecurity. An organization that provides support, information, and collaboration on cybersecurity issues. It also publishes a list of major threats each year.

22
New cards

EU Data Directive

Regulates the processing of PII in the European Union. Because it is a directive, each country must pass laws establishing how it will enforce the directive. It includes seven principles governing the OECD's recommendations for protection of personal data.

23
New cards

ESAC

Eurocloud Star Audit Certification. A nonprofit organization that maintains information security standards or best practices and provides assessments and certification of compliance.

24
New cards

EAR

Export Administration Regulations. U.S. Department of Commerce regulations that restrict exports of certain dual-use technologies that can have both commercial and military applications.

25
New cards

ECPA

Electronic Communications Privacy Act. U.S. laws that restrict government wiretapping of telephone calls and electronic communications.

26
New cards

FERPA

Family Educational Rights and Privacy Act. A federal law that protects the privacy of student education records. It applies to schools that receive funds under an applicable program of the U.S. Department of Education.

27
New cards

FedRAMP

A U.S. federal program that standardizes security assessments, authorization, and continuous monitoring for cloud products and services used by federal agencies and contractors.

28
New cards

FIPS 140-2

Federal Information Processing Standard 140-2. A standard used for protecting sensitive but unclassified information and validating cryptographic modules. It provides four increasing qualitative levels of security, with Level 1 being the lowest and Level 4 the highest.

29
New cards

FIPS 140-3

The successor to FIPS 140-2.

30
New cards

CMVP

Cryptographic Module Validation Program. A joint effort between NIST and the Communications Security Establishment of the Government of Canada that validates cryptographic modules to FIPS 140-2 and other cryptography-based standards.

31
New cards

FISMA

Federal Information Systems Management Act. A U.S. law requiring federal agencies to develop, document, and implement cybersecurity management programs. NIST plays a major role in implementing FISMA and has promulgated numerous security standards and guidelines.

32
New cards

OMB's Role in FISMA

The Office of Management and Budget monitors compliance with NIST programs related to FISMA.

33
New cards

GDPR

General Data Protection Regulation. A European Union privacy regulation that gives individuals control over their personal data and requires all member states to comply with a single regulation. It specifies rights of data subjects and requirements for data controllers and data processors.

34
New cards

GDPR Data Subject Rights

Rights include access, rectification, erasure, and the ability to object to the use of personal information.

35
New cards

GAPP

Generally Accepted Privacy Principles described by the AICPA. Principles and practices agreed upon by 23 countries in response to investor and regulator concerns about transparency, independence, and governance of the accounting industry.

36
New cards

GLBA

Gramm-Leach-Bliley Act. Requires companies that offer financial products or services to safeguard sensitive customer data and inform customers of those requirements.

37
New cards

HIPAA

Health Insurance Portability and Accountability Act. Modernized healthcare information and stipulated how personally identifiable information kept by healthcare and healthcare insurance industries should be protected.

38
New cards

HITECH

An act that motivated the implementation of electronic health records and supporting technology. It increased some penalties for HIPAA noncompliance and established breach notification requirements for impacted patients.

39
New cards

IDCA

International Data Center Authority. An organization attempting to be a standardization, education, and certification body for the application ecosystem and supporting digital infrastructure. IDCA-certified auditors assess cloud providers for compliance with IDCA Grade Levels.

40
New cards

ITAR

International Traffic in Arms Regulations. U.S. State Department regulations that restrict exports of defense-related items and technologies, including certain cryptographic systems.

41
New cards

ISO

International Standards Organization. An international standards body composed of representatives from various standards organizations.

42
New cards

ISO/IEC 20000-1

Information Technology – Service Management. A standard defining operational controls and standards for managing IT services, including approaches associated with ITIL and COBIT.

43
New cards

ISO/IEC 27001

A standard on managing information security. It includes requirements for establishing, implementing, maintaining, and continually improving information management.

44
New cards

ISO/IEC 27002

Provides best practices for information security controls for organizations attempting to comply with ISO/IEC 27001.

45
New cards

ISO/IEC 27017

A standard created to supplement ISO/IEC 27002 by providing additional security controls for cloud environments.

46
New cards

ISO/IEC 27018

An IT security standard and code of practice for the protection of personally identifiable information in public clouds.

47
New cards

ISO/IEC 27034-1

A standard that mandates a framework for application security within an organization. Each organization should have an Organizational Normative Framework, and each application should have its own Application Normative Framework.

48
New cards

ISO/IEC 27037:2012

An ISO standard providing guidance for identifying, collecting, and preserving electronic evidence.

49
New cards

ISO/IEC 27041:2015

An ISO standard providing guidance for incident investigation.

50
New cards

ISO/IEC 27042:2015

An ISO standard providing guidance for the analysis and interpretation of digital evidence.

51
New cards

ISO/IEC 27043:2015

An ISO standard describing principles and processes for incident investigation.

52
New cards

ISO/IEC 27050-1:2016

An ISO standard providing an overview and principles for electronic discovery.

53
New cards

ISO/IEC 28000:2007

A standard for ensuring security assurance in the supply chain.

54
New cards

ISO/IEC 31000:2009

A standard providing industry-independent principles and guidelines for risk management. It does not attempt to achieve uniformity but instead supports the most appropriate risk management for each organization's objectives, context, structure, operations, processes, functions, services, or assets.

55
New cards

ISO/IEC 31010:2009

An international standard providing techniques and guidance for risk assessment and risk management.

56
New cards

ISO/IEC 17788

An international standard providing an overview of cloud computing along with cloud computing terms and definitions.

57
New cards

ISO/IEC 15408-1:2009

Common Criteria Assurance Framework. A framework for providing assurance that security products meet stated security requirements and have been thoroughly evaluated by independent third-party testers.

58
New cards

NFPA

National Fire Protection Association. A nonprofit organization attempting to eliminate death, injury, property loss, and economic loss due to fire, electrical, and related hazards.

59
New cards

NIST

National Institute of Standards and Technology. An agency of the Department of Commerce whose mission is to promote innovation and industrial competitiveness. It also creates numerous standards and requirements for the Department of Defense, federal government, and government contractors relating to cybersecurity.

60
New cards

NIST SP 800-37

Establishes the Risk Management Framework using a life-cycle approach for security and privacy. The RMF provides a disciplined, structured, and flexible process for managing security and privacy risk, including categorization, control selection, implementation, assessment, authorization, and continuous monitoring.

61
New cards

NIST SP 800-53

Provides security and privacy controls for information systems and organizations.

62
New cards

NIST SP 800-92

Guide to Computer Security Log Management. Provides practical guidance on developing, implementing, and maintaining effective log management practices throughout an enterprise, including log management infrastructure, processes, and logging technologies.

63
New cards

NIST 800-145

The NIST publication that defines cloud computing as convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or provider interaction.

64
New cards

NIST 800-146

A NIST document describing cloud computing benefits, open issues, major cloud technologies, and guidelines for evaluating cloud opportunities and risks.

65
New cards

OWASP

Open Web Application Security Project. A nonprofit organization working to improve software security. It is known for publishing the Top 10 most critical security concerns for web application security.

66
New cards

OECD and 7 Principles

Organization for Economic Cooperation and Development. Produced seven principles governing the protection of personal data.

1.    Notice—data subjects should be given notice when their data is being collected;

2.    Purpose—data should only be used for the purpose stated and not for any other purposes;

3.    Consent—data should not be disclosed without the data subject’s consent;

4.    Security—collected data should be kept secure from any potential abuses;

5.    Disclosure—data subjects should be informed as to who is collecting their data;

6.    Access—data subjects should be allowed to access their data and make corrections to any inaccurate data

7.    Accountability—data subjects should have a method available to them to hold data collectors accountable for not following the above principles.

-

PANDASC? Sounds like Pandas See?

67
New cards

PIPEDA

Personal Information Protection and Electronic Documents Act. A Canadian data privacy law that protects the PII of individuals. It allows individuals to inspect data held by an organization and challenge its accuracy and requires organizations to obtain consent when collecting, using, and disclosing PII.

68
New cards

PLA

Privacy Level Agreement. An agreement that contracts how a third-party provider will ensure the confidentiality of information an organization permits the provider to access.

69
New cards

RMF and Steps

Risk Management Framework. A set of standards and guidelines used to develop a risk-based approach to information security.

Prepare for risk management

Categorize systems and information based on impact studies

Select appropriate controls based on risk assessments

Implement and document the controls

Assess how well the controls work

Authorize the system to operate

Monitor controls and changes to system risks.


70
New cards

SABSA

Sherwood Applied Business Security Architecture. A framework for enterprise security architecture and service management.

71
New cards

SOX

Sarbanes-Oxley Act. A law passed to increase independence in audit practices and require the retention and accuracy of financial records as a result of financial and stock scandals associated with Enron.

72
New cards

SEC

U.S. Securities and Exchange Commission. Its primary purpose is to combat market manipulation, and it also enforces the Sarbanes-Oxley Act.

73
New cards

SRE

Site Reliability Engineering. A set of practices and principles intended to produce scalable and highly reliable software systems.

74
New cards

DevOps

Practices that combine software development and IT operations. DevOps is closely related to Site Reliability Engineering.

75
New cards

SSAE 16

Statement on Standards for Attestation Engagements No. 16. An auditing standard that succeeded SAS 70 and led to subsequent SOC reports.

76
New cards

SOC Reports

System and Organization Controls reports. Reports that help companies establish trust and confidence in service delivery and controls. They are produced by third-party certified public accountants.

77
New cards

OMB

U.S. Office of Management and Budget. A component of the Executive Branch that manages FedRAMP and directs its use for the federal government's use of cloud computing.

78
New cards

Uptime Institute

An organization that created and promotes the Tier Standard, which guides the design, construction, and operation of sites worldwide.

79
New cards

Uptime Institute Tier Ratings

Data centers can be rated from Tier 1, the lowest, to Tier 4 based on built-in redundancy, distribution paths, concurrent maintenance, fault tolerance, compartmentalization, and cooling.

80
New cards

USPTO

U.S. Patent and Trademark Office. The government office that registers patents and tra