Laws and Regulations Broad

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/68

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:11 AM on 10/3/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

69 Terms

1
New cards

When the question mentions U.S. government cybersecurity guidance / risk frameworks, think …

NIST. National Institute of Standards and Technology

2
New cards

A U.S. federal agency responsible for granting patents and registering trademarks = …

USPTO = U.S. Patent and Trademark Office.

Is an Agency/Organization

3
New cards

It's associated with validating cryptographic modules against FIPS 140 requirements = …

CMVP = Cryptographic Module Validation Program

4
New cards

A federal law that establishes requirements for information security in federal agencies and federal information systems = …

FISMA = Federal Information Systems Management Act

5
New cards

Trigger words:

  • web applications

  • application security

  • application vulnerabilities

  • secure coding

  • SQL injection

  • XSS

Think…

OWASP = Open Web Application Security Project

6
New cards

Trigger words:

  • electronic communications

  • emails

  • phone communications

  • stored communications

  • interception

  • unauthorized access to communications

Think…

ECPA = Electronic Communications Privacy Act

7
New cards

It's a set of privacy principles used to evaluate and manage how organizations handle personal information. = …

GAPP = Generally Accepted Privacy Principles

8
New cards

“What are children being exposed to online?” Think…

“What information is being collected about children?” Think…

COPA = Child Online Protection Act

COPPA = Children's Online Privacy Protection Act

9
New cards

It was aimed at restricting minors' access to harmful material online = …

COPA = Child Online Protection Act

10
New cards

It focuses on the online collection of personal information from children under 13, including requirements involving parental consent = …

COPPA = Children's Online Privacy Protection Act

11
New cards

Trigger words:

  • Canada

  • Canadian privacy

  • personal information

  • private-sector organizations

  • collection/use/disclosure of personal information

Think…

PIPEDA = Personal Information Protection and Electronic Documents Act

12
New cards

It's associated with data-center standards, infrastructure, and operational practices. = …

IDCA = International Data Center Authority

13
New cards

Trigger words:

  • data center

  • data-center infrastructure

  • data-center design

  • data-center operations

  • availability/reliability of data centers

Think…

IDCA = International Data Center Authority

14
New cards

It's a professional cybersecurity organization associated with certifications such as CISSP = …

(ISC)2 = International Information System Security Certification Consortium

15
New cards

ISO 31??? = “How do we manage risk?”
ISO 31??? = “How do we assess the risk?”

ISO 31000

ISO 31010

16
New cards

The overall principles and guidelines for MANAGING risk = …

ISO 31000

17
New cards

A cloud security transparency program. It gives customers information about a cloud provider's security practices = …

CSA STAR. Cloud Security Alliance Security, Trust, and Assurance Registry.

18
New cards

Self-assessment of cloud security by the cloud provider = …

CSA STAR Level 1

19
New cards

Third-party assessment/certification of cloud security of a cloud provider = …

CSA STAR Level 2

20
New cards

“A company wants a framework containing controls specifically addressing cloud security.”

Think…

“A U.S. federal agency needs a catalog of security and privacy controls for its information system.”

Think…

CSA CCM

NIST 800-53

21
New cards

A framework/catalog of cloud-specific security controls = …

CSA CCM (Cloud Controls Matrix).

22
New cards

“Questions I ask a cloud provider about their security.” = …

CAIQ = Consensus Assessments Initiative Questionnaire

23
New cards

Trigger words:

  • overseas data

  • cross-border

  • different jurisdictions

  • government access to electronic data

  • data stored outside the U.S.

  • conflicting laws between countries

Think …

CLOUD Act. Clarifying Lawful Overseas Use of Data.

24
New cards

The techniques/tools for risk assessment/measuring risk = …

ISO 31010

25
New cards

If you see:

  • Cloud computing terms/definitions

  • Cloud terminology

  • Overview of cloud computing

Think…

ISO 17788

26
New cards

Application security, application framework, ONF, ANF = …

ISO 27034-1

27
New cards

Common Criteria / EAL = …

ISO 15408-1

28
New cards

Old, depreciated auditing standards = …

SAS 70

29
New cards

"I want to see the report about the service provider's controls." = …

SOC

30
New cards

"Which international standard guides the examination of a service organization’s controls?" = ..

ISAE 3402. International Standard on Assurance Engagements

31
New cards

"Which U.S. standard guides the examination of a service organization’s controls?" = ..

SSAE 16. Statement on Standards for Attestation Engagements No. 16

32
New cards

Accounting, accountants = …

AICPA. American Institute of Certified Public Accountants

33
New cards

When a question mentions cryptography, think …

FIPS. Federal Information Processing Standards

34
New cards

When a question mentions international standards / management systems, think …

ISO. International Organization for Standardization.

35
New cards

When a question mentions publicly traded companies / financial reporting & controls think …

SOX. Sarbanes-Oxley Act

36
New cards

“What law requires public companies to have financial reporting/internal controls?” = …

SOX. Sarbanes-Oxley Act

37
New cards

A U.S. federal government agency that regulates securities markets and public companies = …

SEC = Securities and Exchange Commission

38
New cards

When a question mentions protecting customer financial information think …

GLBA. Gramm-Leach-Bliley Act

39
New cards

When a question mentions auditing / assurance reports think …

SOC / SSAE / ISAE

System and Organization Controls / Statement on Standards for Attestation Engagements / International Standard on Assurance Engagements

40
New cards

Federal cloud authorization, federal cloud approval = …

FedRAMP

41
New cards

Trigger words:

  • Evaluate a security product

  • IT product

  • EAL

  • Evaluation Assurance Level

  • EAL1–EAL7

Think … or …

Common Criteria, CC or ISO 15408-1

42
New cards

Security evaluation of IT products = …

Common Criteria, CC

43
New cards

When you see things like:

  • Risk assessment

  • Incident response

  • Federal cybersecurity guidance

  • CUI

  • Security frameworks

Think …

NIST. National Institute of Standards and Technology

44
New cards

If you see:

  • ISMS

  • Information security management

  • Cloud security

  • Privacy management

Think …

ISO. International Organization for Standardization.

45
New cards

Which standard provides an ISMS?

ISMS is Information Security Management System

Think Information Security Management → ISO

ISO 27001

46
New cards

Which publication provides a catalog of federal security controls?

NIST 800-53

47
New cards

Which organization develops cybersecurity standards and guidance?

NIST

48
New cards

NIST 800-145 and NIST 800-146 are both ___

Cloud

49
New cards

NIST 800-171 = _ _ _

NIST 800-171 = CUI

Remember there are only three NIST that have 3 digits after 800. 145-146 are cloud related. Just remember that the other 3 digit NIST (171) is CUI (also 3 letters).

CUI = Controlled Unclassified Information

50
New cards

RMF, Risk Management Framework, authorization, security lifecycle = …

NIST 800-37

51
New cards

ISMS = ___ ___

ISO 27001

52
New cards

How to implement controls/guidance = ___

List of privacy and security controls = ___

ISO 27002

NIST 800-53

53
New cards

Trigger words:

  • HSM

  • Cryptographic module

  • Encryption hardware

  • Cryptographic keys

  • Federal cryptography

  • Security requirements for cryptographic modules

Think …

FIPS 140-2 or FIPS 140-3 (newer)

Do not select 140-3 as an answer if 140-2 is there.

54
New cards

Logging, log management, security logs = …

NIST 800-92

55
New cards

Cloud computing, 5 essential characteristics, service/deployment models = …

NIST 800-145

56
New cards

Cloud business case = …

NIST 800-146

57
New cards

Privacy, privacy information management, PIMS = …

ISO 27701

58
New cards

Cloud security, cloud service security controls = …

ISO 27017

59
New cards

Cloud architecture, cloud computing reference architecture = …

ISO 17789

60
New cards

Acquire, preserve digital evidence = …

ISO 27037

61
New cards

Forensic methods, forensic tools, methodology = …

ISO 27041

62
New cards

Interpret digital evidence = …

ISO 27042

63
New cards

Investigation principles/process = …

ISO 27043

64
New cards

Electronically stored information, discovery process = …

ISO 27050-1

65
New cards

Private security operations, security operations management = …

ISO 18788

66
New cards

ISO 270??–270?? = Digital evidence/forensics family

ISO 27037-27043

67
New cards

How do I secure the cloud? Think…

ISO 27017

68
New cards

How is the cloud structured? Think…

ISO 17789

69
New cards

ISO 27037 = __ __ 41 =__ __ 42 = __ __ 43 = __ __

37 = Get it → 41 = Verify it → 42 = Analyze it → 43 = Investigate it

Get it (digital evidence)