Cyberstudy
PDF p.378 In progress

Legal Environment

Open PDF at p.378 7 flashcards

Summary

PDF p.378

Governance committees ensure organizations comply with cybersecurity laws and regulations to avoid legal liability. They manage legal risks, interpret legal requirements, and implement operational controls to protect the organization.

In plain words

Supplementary — not from your PDF

Governance committees keep the organization compliant to avoid legal liability, managing risks such as regulatory compliance, contracts, breach liability and privacy law. Due diligence means responsible people haven't been negligent; laws such as Sarbanes-Oxley, the Computer Security Act and FISMA criminalize negligence. Frameworks like NIST and ISO 27K help demonstrate compliance.

Detailed explanation

PDF p.378
  • Governance Committees
    • Role: Ensure compliance with laws and regulations.
    • Legal Risks: Regulatory compliance, contractual obligations, public disclosure, breach liability, privacy laws, intellectual property protection, licensing agreements.
  • Due Diligence
    • Definition: Legal term indicating responsible persons have not been negligent.
    • Legislation: Criminalizes negligence in information management (e.g., Sarbanes-Oxley Act, Computer Security Act, FISMA).
  • Frameworks and Benchmarks
    • Purpose: Demonstrate compliance with legal/regulatory requirements.
    • Examples: NIST, ISO 27K.

Important terms

taken from the text above
Legal Risks
Regulatory compliance, contractual obligations, public disclosure, breach liability, privacy laws, intellectual property protection, licensing agreements.
Due Diligence
Legal term indicating responsible persons have not been negligent.
Legislation
Criminalizes negligence in information management (e.g., Sarbanes-Oxley Act, Computer Security Act, FISMA).

Examples & real-world scenarios

Supplementary — not from your PDF
  • A governance committee reviewing regulatory obligations.
  • Documenting due diligence to show reasonable care.
  • Using a NIST framework as evidence of compliance.

Scenario

After a breach, regulators ask whether the company took reasonable care. Documented due diligence and adherence to a recognized framework help show it wasn't negligent.

Common mistakes

Supplementary — not from your PDF
  • Assuming compliance is only IT's job.
  • Having no evidence of due diligence.

Practical skills

Supplementary — not from your PDF
  • Explain due diligence in a security context.

What I should remember

Key Points PDF p.378
  • Governance Committees: Ensure compliance and manage legal risks.
  • Due Diligence: Prevent negligence and legal liabilities.
  • Frameworks: Demonstrate compliance.