Determining Compliance and Other Requirements
Organizations do not operate on internal missions, goals, and standards only; they also have external drivers that limit and dictate how they should work with employees, contractors, clients, suppliers, and affiliates. Organizations follow their imposed regulations and must comply with contracts, industry standards, and specific laws of their city, state, province, or country.
This section will cover compliance, which is when an organization follows specific directives or ordinances. There are specific tools, processes, and documentation to demonstrate adherence to these directives and ordinances that verify and validate compliance according to law, industry standards, and so on.
Important directives to understand in the CISSP exam are those that protect personal privacy, such as personally identifiable information (PII) and protected health information (PHI). The general term for this category is privacy, and the individual ultimately...