Compliance, Regulation, and Investigations
Having a Certified Information Systems Security Professional (CISSP) certification carries the responsibility of complying with laws and regulations and understanding the different types of investigations. Organizations that comply with regulated standards do a better job of securing customer data. Standards also help organizations consistently compare results.
In the exam, you are tested on your understanding of contracts that allow merchants to accept credit cards, security regulations that protect hospital patient records, and other private data. You must also understand which investigatory process to follow when an organization’s information systems are compromised.
By the end of this chapter, you will be able to answer questions on the following:
- The difference between contractual requirements, legal requirements, and industry standards
- Important user privacy principles
- The nature of cybercrimes and other...