Regulations are often mandated– Security processes are usually a foundational consideration– Logging, data storage, data protection, and retention
Sarbanes-Oxley Act (SOX)– The Public Company Accounting Reform and – Investor Protection Act of 2002
The Health Insurance Portability and Accountability Act (HIPAA)– Extensive healthcare standards for storage, use, and transmission of health care information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
Legal
A
The security team is often tasked with legal responsibilities– Reporting illegal activities– Holding data required for legal proceedings
Security breach notifications– A legal requirement in many jurisdictions
Cloud computing can make this challenging– Data moves between jurisdictions without human intervention– The security team must follow legal guidelines
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
Industry
A
The industry may require specific security considerations– Every market is a bit different
Electrical power and public utilities– Isolated and protected system controls
Medical– Highly secure data storage and access logs– Data encryption and protection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
Geographical security
A
Local/regional– City and state government records– Uptime and availability of end-user services
National– Federal governments and national defense– Multi-state organizations– State secrets remain secret
Global– Large multinational companies– Global financial markets– Legal concerns will vary widely