D320 (C838) Laws, Regulations, and Organizations n n n n n
1. (ISC)2 - International Information System Security Certification Consortium-
n n n n n n n
: A security certification granting organization that has a long history of certifications that
n n n n n n n n n n n n n
were difficult to get. This difficulty has made their certificates seen as having higher
n n n n n n n n n n n n n n
value in the industry.
n n n n
2. (ISC)2 Cloud Secure Data Life Cycle: Based on CSA Guidance. 1. Create; 2. Store; 3.
n n n n n n n n n n n n n n
Use; 4. Share; 5. Archive; 6. Destroy.
n n n n n n n
3. (SAS) 70: n n was a recognized standard of the American Institute of Certified
n n n n n n n n n
Public Accountants (AICPA) in response to the issues that also lead to Sarbanes-Ox- ley
n n n n n n n n n n n n n n
(SOX). Deprecated in 2011 by the Statement on Standards for Attestation
n n n n n n n n n n n
Engagements (SSAE) No. 16.
n n n n
4. AICPA: established SAS 70 and later SAAE 16.
n n n n n n n
5. AICPA: American Institute of Certified Public Accountants
n n n n n n
6. Organizational Normative Framework (ONF): Concepts of ISO 27034.There is only n n n n n n n n n n
one
n n for an organization but potentially as many ANF's as applications.
n n n n n n n n n
7. ASHRAE - American Society of Heating, Refrigerating and Air-Conditioning
n n n n n n n n
n Engineers: a professional association seeking to advance heating, ventilation, air
n n n n n n n n n
conditioning and refrigeration systems design and construction.
n n n n n n n
1 n/ n24
,ONLYSTUDENTS
D320 (C838) Laws, Regulations, and Organizations n n n n n
8. Biba: an access control model designed to preserve data integrity. It has 3 goals
n n n n n n n n n n n n n
Maintain internal and external consistency; prevent unauthorized data modification
n n n n n n n n n
even by authorized parties; prevent data modification by unauthorized individuals.
n n n n n n n n n n
9. Capability Maturity Model (CMM): a development model where the maturity
n n n n n n n n n
relates to the formality and optimization of processes.When applied to cloud security it
n n n n n n n n n n n n n n
would focus on those aspects as they relate to cloud security.
n n n n n n n n n n n
10. Child Online Protection Act (COPA): An attempt to restrict access by minors to
n n n n n n n n n n n n
material defined as harmful to minors. A permanent injunction against the law in
n n n n n n n n n n n n n
2009.
n
11. Cloud Access Security Brokers (CASBs): monitors network activity between
n n n n n n n n
users and cloud applications and enforces security policy and blocking malware.
n n n n n n n n n n n
12. Cloud Security Alliance (CSA): publishes the Notorious Nine: 1) Data breach- es;2)
n n n n n n n n n n n n
Data Loss;3) Account service traffic hijacking;4) Insecure Interfaces and APIs;
n n n n n n n n n n n n
5) Denial of Service; 6) Malicious Insiders; 7) Abuse of Cloud Services; 8) Insufficient Due
n n n n n n n n n n n n n n
Diligence; 9) Shared technology Vulnerabilities. There are also implications and controls
n n n n n n n n n n n
associated with each.
n n n
13. CSA STAR - Cloud Security Alliance (CSA) Security, Trust, and Assurance
n n n n n n n n n n
n Registry (STAR): n n uses the Consensus Assessments Initiative Question-
n n n n n
naire (CAIQ), Cloud Controls Matrix (CCM), and GDPR Self-Assessment as inputs to
n n n n n n n n n n n n
2 n/ n24
, ONLYSTUDENTS
D320 (C838) Laws, Regulations, and Organizations
n n n n n
n certify an organization to Level 1.
n n n n n
Level 2 integrates the CSA Cloud Controls Matrix and the AICPA Trust Service
n n n n n n n n n n n n
3 n/ n24