Regulations, Standards, and Legislation
Regulations, standards, and legislation are put in place to ensure that compliance has been achieved, and most are legally enforceable. From these regulations and standards, we derive our policies to ensure compliance and prevent crime; if companies do not abide by these regulations, they will be fined. Other industry frameworks are only best practices and are not legally enforceable, but vendors will not support any product that has not been set up according to such best practices. In this section, we are going to look at regulations, standards, and legislation followed by a look at key frameworks, benchmarks, and secure configuration guides. Let's start with General Data Protection Regulation (GDPR):
- General Data Protection Regulation (GDPR): The European Union's (EU's) GDPR came into force on 25th May 2018, as a framework for data protection law. It is enforced by the EU Information Commissioner's Office (ICO)...