What must IT security professionals be aware of?
Regulations associated with their organization and the type of data collected
This includes both application-stored information and log files.
What is Sarbanes-Oxley abbreviated as?
SOX
Officially known as the Public Company Accounting Reform and Investor Protection Act of 2002.
What does Sarbanes-Oxley focus on?
The finances associated with an organization
What is HIPAA an abbreviation for?
Health Insurance Portability and Accountability Act
What does HIPAA ensure?
Protection of health care information
What are IT security professionals responsible for in terms of legal requirements?
Formal processes for reporting illegal activities
What is a legal hold?
Ensures data is available for future legal proceedings
True or False: Organizations must disclose security breaches within a mandated timeframe.
True
What is a challenge of cloud computing from a legal perspective?
Data may be stored anywhere in the world, subject to legal guidelines
What requirement might some countries have regarding data collected from their citizens?
Data must stay within that country’s borders
What might vary between different industries regarding IT security?
Security considerations and access requirements
How are power-generating technologies often secured?
Air-gapped from other parts of the network
What security measures are common in medical environments?
Extensive data encryption and protection technologies
What influences the security considerations of an organization?
The scope of the organization
Fill in the blank: A city or state government may collect records to help manage a _______.
city or county
What issues arise at the national level for data security?
Confidentiality and communication between states
What additional concerns do global companies face?
Different data protection and security laws in various countries