Summary
This chapter covered compliance, regulation, investigations, and the importance of protecting a user’s private information, such as their name, address, phone, and tax identification number. If such information is stolen during a breach, it exposes the individual to identification theft, which could cost them thousands of dollars in losses and inconvenience.
Laws and regulations are in place to protect citizens by making companies and businesses responsible for these losses, and information security professionals must be aware of the various laws and requirements. Some requirements come from contractual agreements such as PCI DSS, which requires businesses not to save the CVV code on the back of credit cards.
Federal institutions must abide by FISMA, stating that information security mitigations should be put in place to protect privacy records. ISO 27001 is an industry standard that provides similar requirements for businesses.
Companies doing business overseas...