Compliance standards and controls
Having taken a look at the basic concepts of security, it is now time that we take a look at compliance standards that are used in the industry and how some of the controls are implemented.
The compliance requirements can be for a particular industry, for example HIPAA for Healthcare, PCI for the payment card industry, and so on, or compliance requirements for a region, for example, the European Union has General Data Protection Regulation (GDPR).Â
These standards have several aspects, including IT, process, and even documentation standards.
In the next section, we will take a look at the IT controls that need to be implemented for one of the compliance standards. I think HIPAA will be good as an example, due to its fairly comprehensive coverage and requirements.Â
HIPAA compliance standards
HIPAA is a standard for healthcare organizations in the US; however, most other healthcare institutions around the world are also influenced by the standards. While the standards...