What's changed: Initial version
5.3The impact of compliance frameworks
Covers the correspondence of "which data each major regulation protects"—PCI-DSS (card data), HIPAA (health information), GDPR (EU personal data), FERPA (education records), and FISMA (US federal systems)—and how the reporting/notification requirements (whom to inform, and by when, in a breach) shape incident-response procedures, at an introductory level.
Incident response is not complete with technology alone, because the type of data you handle determines "whom you must notify, and by when, if it is breached," as set by law or industry rules. This section covers, at an introductory level, the correspondence of which data each major compliance framework governs—PCI-DSS (card data), HIPAA (health information), GDPR (EU personal data), FERPA (education records), and FISMA (US federal systems)—and how the reporting/notification requirements in a breach shape incident-response procedures.
5.3.1Major frameworks and the data they govern
- PCI-DSS is an industry standard (set by the card brands) that protects credit card holder data. HIPAA is the US rule protecting health information (protected health information). Because exams ask you to match by data type, nail "card = PCI-DSS / health = HIPAA."
- GDPR is the EU law protecting personal data, reaching even organizations outside the EU if they handle EU residents' data. FERPA is the US law protecting the privacy of students' education records. Remember "EU personal data = GDPR / education records = FERPA."
- FISMA is the US law that mandates security management for federal government information systems; it covers federal agencies and their related systems. "US federal systems = FISMA." These five govern different data and domains, so the knack is to choose by "what data" appears in the situation.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

