C838 ISO/IEC And NIST Standards -
Exam 9 Questions with 100% Correct
Answers.
Sarbanes-Oxley Act
An act passed into law by Congress in 2002 to establish strict accounting and reporting rules
in order to make senior managers more accountable and to improve and maintain investor
confidence.
Health Insurance Portability and Accountability Act (HIPAA)
Protect patient records and data, known as electronic protected health information (ePHI).
Family Educational Rights and Privacy Act (FERPA)
A federal law that governs student confidentiality in schools. It requires that schools not divulge,
reveal or share any personally identifiable information about a student or his/her family, unless
it is with another school employee who needs the information to work with the student. An
exception is the publishing of student directory information.
EU Data Protection Directive 95/46 EC
First major EU data privacy law. Describes the appropriate handling of personal and
private information of all EU citizens.
Data Directive
The Data Directive addresses individual personal privacy by codifying these seven principles:
Notice: The individual must be informed that personal information about them is being
gathered or created.
Choice: Every individual can choose whether to disclose their personal information. No entity
can gather or create personal information about an individual without that individual's explicit
agreement.
Purpose: The individual must be told the specific use the information will be put to. This
includes whether the data will be shared with any other entity.
, Access: The individual is allowed to get copies of any of their own information held by any
entity.
Integrity: The individual must be allowed to correct any of their own information if it is
inaccurate.
Security: Any entity holding an individual's personal information is responsible for protecting
that information and is ultimately liable for any unauthorized disclosure of that data.
Enforcement: All entities that have any personal data of any EU citizen understand that they
are subject to enforcement actions by EU authorities.
Data Subject
The individual whom the PII refers to. A specific human being.
Data Controller
Any entity collecting or creating PII. In the cloud motif, the data controller is the cloud customer.
Data Processor
Any entity acting on behalf or at the behest of the data controller, performing any
manipulation, storage, or transmission of the PII. In the cloud motif, the data processor is the
cloud service provider.
Create (DSL)
Creation is the generation of new digital content, or the alteration/updating/modifying of
existing content.
Store (DSL)
Storing is the act committing the digital data to some sort of storage repository and typically
occurs nearly simultaneously with creation.
Use (DSL)
Data is viewed, processed, or otherwise used in some sort of activity, not including modification.
Share (DSL)
Inofrmation is made accessible to others, such as between users, to customers, and to partners
Exam 9 Questions with 100% Correct
Answers.
Sarbanes-Oxley Act
An act passed into law by Congress in 2002 to establish strict accounting and reporting rules
in order to make senior managers more accountable and to improve and maintain investor
confidence.
Health Insurance Portability and Accountability Act (HIPAA)
Protect patient records and data, known as electronic protected health information (ePHI).
Family Educational Rights and Privacy Act (FERPA)
A federal law that governs student confidentiality in schools. It requires that schools not divulge,
reveal or share any personally identifiable information about a student or his/her family, unless
it is with another school employee who needs the information to work with the student. An
exception is the publishing of student directory information.
EU Data Protection Directive 95/46 EC
First major EU data privacy law. Describes the appropriate handling of personal and
private information of all EU citizens.
Data Directive
The Data Directive addresses individual personal privacy by codifying these seven principles:
Notice: The individual must be informed that personal information about them is being
gathered or created.
Choice: Every individual can choose whether to disclose their personal information. No entity
can gather or create personal information about an individual without that individual's explicit
agreement.
Purpose: The individual must be told the specific use the information will be put to. This
includes whether the data will be shared with any other entity.
, Access: The individual is allowed to get copies of any of their own information held by any
entity.
Integrity: The individual must be allowed to correct any of their own information if it is
inaccurate.
Security: Any entity holding an individual's personal information is responsible for protecting
that information and is ultimately liable for any unauthorized disclosure of that data.
Enforcement: All entities that have any personal data of any EU citizen understand that they
are subject to enforcement actions by EU authorities.
Data Subject
The individual whom the PII refers to. A specific human being.
Data Controller
Any entity collecting or creating PII. In the cloud motif, the data controller is the cloud customer.
Data Processor
Any entity acting on behalf or at the behest of the data controller, performing any
manipulation, storage, or transmission of the PII. In the cloud motif, the data processor is the
cloud service provider.
Create (DSL)
Creation is the generation of new digital content, or the alteration/updating/modifying of
existing content.
Store (DSL)
Storing is the act committing the digital data to some sort of storage repository and typically
occurs nearly simultaneously with creation.
Use (DSL)
Data is viewed, processed, or otherwise used in some sort of activity, not including modification.
Share (DSL)
Inofrmation is made accessible to others, such as between users, to customers, and to partners