In my case, I choose Microsoft and it’s very interesting because of the number of laws and
regulations they carry with them but it’s also interesting because the laws and rules are vital
to ensuring public safety and company property. I know that certain companies sell users'
information but never private information, this comes into a privacy act where companies
cannot share sensitive user information and only things like pages visited or things you like.
This is how targeted ads work which are major moneymakers for Microsoft and companies
like google. There can be huge impacts on a company that violates any rules or laws in
place, which includes areas such as the cyber domain, lawsuits, and other legal issues that
could lead to bigger problems can happen if a company violates any of these rules set or
does not adhere to them. There have been many different laws passed in the U.S. and around
the world that affect the cyber domain and cybersecurity. One of these laws is the Sarbanes-
Oxley Act. This law ensures that companies that house personal data should make sure the
validity of the financial information and should not share the financial information of
anyone. This law also states that for a company to stay SOX complient, they must have
adequite standards and security controls in place to ensure the confidentiality, integrity, and
avalibility of their financial information. This law affects all different businesses that store
financial information so that they may not sell the information or lack security protocols to
protect that information. Another law that affects the cyber domain is the Electronic Funds
Transfer Act. This law states that anyone electronically transferring funds are protected
against errors and fraud. This can include any company that is electronically transferring
funds to or from an account. This can include ATM's, telephone bill payements, and POS
terminals. Another law that affects the cyber domain is Health Information Technology for
Economic and Clinical Health Act. This law is a direct modification to the HIPAA law that
while on it's own is directly targeted at the medical community but with this brings major
modifications to the way that patients information is stored and accessed. It states that
patient information stored must be secured in a reasonable way and helps to expand the
scope of the patient confidentiality of HIPAA. After doing extensive research on the laws
and regulations provided in this discussion I have come to the conclusion that the law that
impacts information security professionals the most in my opinion would be the Health
Insurance Portability and Accountability Act (HIPAA). This law basically protects the
patient’s personal information from anyone beside the person who is treating them. Their
caregiver is not allowed to share any of the information they receive without consent from
the patient. This law gives reassurance to both parties. The type of information this
regulation protects includes, but is not limited to, your payment information, address, health
information, and phone number. I have had many experiences with HIPAA myself over the
past couple years. I got into a car crash and was severely hurt. I went through five shoulder
surgeries to try to save the function of my arm. My mom was not allowed to get any
information about the accident or my condition until I was conscious and gave consent. She
was extremely upset about this, but I totally understood the situation because of this law.
Even though she was my mom, someone could have acted like that just to get my
information. There is a lot of information that a hospital receives when your being cared for,
and you do not want to let anyone get into your personal information. Not everyone has this
security, but I am glad I know my information is safe when I am being cared for. The law
that affects my organization the most is the Fair and Accurate Credit Transaction Act
(FACTA). This is because my organization often deals with credit applications and this
helps those customers avoid identity theft. If we follow this law as a company, we will not
have any issues. Not all nations have the same rules, but I am relatively familiar with the
laws I need to be following. The three laws and regulations that I see that fit to the company
I chose are Sarbanes-Sarbanes-Oxley Act, Federal Rules of Civil Procedure and also, one
that originated in the EU that affects us here in the states as well, the General Data
Protection Regulation. The Sarbanes-Sarbanes-Oxley Act is a 2002 law was a response to
corporate fraud and is designed to improve corporate disclosures and transparency. For IT
and security folks, that means information control and integrity, business continuity and
disaster recovery, and protecting information (and financial performance) from the impact of
a data breach or loss. The FRCP discovery rules govern court procedures for civil lawsuits It
makes clear that electronically stored information is discoverable, and they detail what, how
and when electronic data must be produced. As a result, companies must know what data
they are storing and where it is; they need policies in place to manage electronic data; they
need to follow these policies; and they need to be able to prove compliance with these
policies, in order to avoid unfavorable rulings resulting from failing to produce data that is
relevant to a case. Company’s that would be affected by this would be any company that is
— or could be — involved in a civil lawsuit within the federal courts. In addition, because
states have adopted FRCP-like rules, companies involved in litigation within a state court
system are also affected. The EU's General Data Protection Regulation (GDPR) took effect
on May 25, 2018. The GDPR is designed to protect the personal data of EU citizens, and to
do so it regulates how such data is collected, stored, processed, and destroyed. The definition
of "personal data" is extremely broad: It includes names, addresses, and bank details, but
also data related to religion, race, mental or physical characteristics, and even IP addresses,
web cookies, contacts, and mobile device IDs, if they identify an individual.
I haven’t had to deal with these first hand, other than being the person who collects data and
since I’m on the front lines, I make sure that I do not give out any data of anyone to any
person without following the proper channels to verify the person whom I’m talking with.
The laws and regulation that are evolved with the cyber domain can be very convoluted as
these laws are evolving to match society expectations of the cyber domain to governed and
not free game for threats to linger unchecked. The ethics of the cyber domain especially
across the world multiple governments and countries with each their own ethics and laws
driven from their culture is very enticing to threats as the perception of exploiting and
committing crime with minimal risk to the threat. The company I chose in week one was
Apple and they have a cross functional approach to conduct business on the cyber domain.
Meaning they have their own set of ethics and principles of how their customers should be
treated in person and in the cyber domain. They also have expectation to security and
privacy as we trust them with much of our personal information and financial information.
The ethics and principles Apple has from what I can tell developed from most of society in
the United States even though they have customers across the world. Their legal, principles
and ethic are remarkably similar from country to country only changing what is mandatory
to be a legal corporation in that country. This allows them to keep many of their core
principles to their worldwide customers and the ethical dilemmas of the cyber domain in
check for their small portion. I feel as though all laws and regulations impact security
professionals equally because in today’s society most sensitive personal or financial data is
stored somewhere on an information system. These laws and regulations give security
professionals boundaries to work within which helps them to understand to what level
information needs to be protected. There are different types of information being handled
depending on the service that a company may provide. Companies that deal with electronic
transactions have to comply with regulations like payment card industry data security
Standard (PCI DSS) and the Electronic Fund Transfer Act. Both of these regulations keep
consumers electronically stored information safe. PCI DSS provides an enhanced security
level when it comes to a customer’s payment account data. This set of requirements include
things like security management, policies, and other protective measures. Electronic Fund
Transfer Act protects consumers from errors and fraud while conducting electronic fund
transfers (EFT). This Act covers things like ATM transfers and POS terminal transfers in
stores. In 2010, a new provision was added to keep companies from charging inactivity or
service fees on pre-paid purchases like gift cards. CACI is impacted by these laws and
regulations on many fronts as they try to protect their own data from threats but they also
purchase things like gift cards for their employees. In that realm they have to make sure they
purchase from law abiding companies as their employees can be susceptible to illegal
practices. The company also operates in Nevada and Massachusetts so they have to follow
those states regulations in reference to collecting resident’s information. In Nevada, they
enacted a data security law to encrypt customers’ personal information if it is to be stored or
transported. The state of Massachusetts requires that companies that store or uses residents’
personal information develop a regular audit plan to protect that information. I have been a
victim of identity theft back before many of these policies were put into place. Nowadays
these policies keep us protected as electronic consumers so our data is better protected. The
roles and responsibilities of those upholding the laws likely include, regularly testing the
security of their systems to ensure they cannot be breached. Also, updating whatever
security measures or software they need to. This probably can be applied to all of the laws
researched. The law that stood out to me the most in regard to the organization I chose was
the PCI DSS law. It requires policies and protective measures to keep customers account
information safe. It is a requirement to be implemented with PCI DSS if you accept credit
cards no matter the size of your business. While being implemented is a requirement being
compliant is not, but it reduces the risk of credit card fraud if you are. If your business is not
complaint with PCI DSS and you experience a security breach you may have to pay fines.
From what I have been able to find it seems Europe uses PCI DSS however, I wasn’t able to
find a full list of countries it is used in. I don’t know that I have ever had any direct
experience with any of the laws, HIPPA is the law I am most familiar with though. I feel
that the Federal Information Security Management Act (FISMA) mostly impact
professionals. Professionals are responsible for providing security programs for information
systems and are required to perform assessments. Some of the main roles for the
professionals that are held responsible for upholding this law includes testing and evaluating
how effective the information security policies are. After researching through the
international laws and regulations, they focus mainly on protecting disclosure of personal
information from businesses and organizations. My experience with the laws and regulations
would most likely relate to the Fair and Accurate Credit Transaction Act (FACTA),
including Red Flags Rule. I work in an office building that receives applications from
consumers who would like to repair or retire their vehicle. In order to determine if they
qualify for our program, they have to be income eligible and provide proof of their income.
By law, we are responsible for upholding the consumers confidentiality and properly dispose
of their personal information after processing them in our database. I am one of the few
employees responsible for properly disposing the consumers application after scanning and
processing them into our database. With the PCI DSS law the company obtaining the card
date for what ever process, is responsible for the data. the IT guy is responsible for maintain
the systems and logging vulnerabilities along with testing and monitoring, and if I
understand correctly PCI security standard council is responsible for enforcing the standard.
This affects System76 by the way they collect payment for customers purchases, they do
practice some transference of liability by allowing customers the option to finance their
purchase, which at that point the creditor carries the responsibility of maintaining the data.
This process is well practiced across the board all over, it seems to me like most every
retailer online has a very similar way they process payments and many offer a third party
credit line possibly, which in turn transfers the responsibility. I understand the PCI DSS
standards, again, simply because it is just that a standard that most every retailer follows
both here in the U.S. and abroad. I think the transference of responsibility is becoming more
of the option the retailers would prefer since most major retailers offer some kind of credit
card with perks attached to them. Cyber security is the practice of defending computers,
servers, mobile devices, electronic systems, networks, and data from malicious attacks. It's
also known as information technology security or electronic information security. Today,
there is no consensus on who is responsible for data privacy. Some consumers agree that the
responsibility lies with them, but others think governments or businesses are better equipped
to deal with this complex issue. Data breaches have become both more common and more
severe. Cyber attacks that were previously considered large-scale are today seen as normal.
Hackers are more agile, The threats are becoming more sophisticated; hackers are
increasingly agile and are using advanced technology to launch attacks. In recent years,
numerous issues have arisen around the way enterprises treat their users’ information.
Personal data is processed for political and economic reasons without users’ consent. In the
US, device privacy laws vary depending on the sector, state or data type. Recently,
California implemented a new law that governs IoT security on a state level. Technology
leaders, meanwhile, are pushing for federal privacy laws, and are beginning to see privacy as
a human right. After doing some research on the laws and regulations that most impacts
information security professionals there was one that stood out to me and that is the Health
Insurance Portability and Accountability Act (HIPAA). The Health Insurance Portability and
Accountability At is intended to improve the efficiency and effectiveness of the health care
system. It does so by protecting the patient identifiable health information and by protecting
the confidentiality, and availability of patients information. I know about this act from
experience because I am HIPAA certified. So I am a medical assistant and we are one of the
people who has to follow the the rule of HIPAA. This is very important for the patient
because it gives you a piece of mind knowing that your personal information such as your
payment information, you address, phone number, Health condition etc. is not being
broadcasted to the world because of HIPPA. This is also important because a lot of
information is located on an EMR which is an Electronic Medical Record and if its digital
the there has to be some sort of cyber security of else all of those patients information can be
stolen is the system is hacked. When it comes to the cyber domain, all employees are
responsible for upholding the law, but the information security professional has the biggest
role dealing with the responsibility and liability for privacy and security risks. The
professional must maintain up to date with laws and regulations, in doing so they can
educate management and employees on legal and ethical obligations. The company
Advanced1 has to make sure to follow the Federal Rules of Civil Procedure (FRCP) and
Federal Information Security Management Act (FISMA) since they are dealing with
electronic data produced for their clients in order to reduce risk of civil lawsuits.
International privacy and information security can become complex within a company due to
laws and ethics not being the same internationally. In the U.K, some laws have similarities
to the U.S, such as the Computer Misuse Act 1990, Privacy and Electronic Communications
(EC Directive) Regulations 2003, and Police and Justice Act 2006. In Europe, the council of
Europe adopted Convention on Cybercrime in 2001 creating an international task force
overseeing security functions in internet activities and standardized technology laws across
international borders. In Asian culture, computer technology ethics conflict western cultures.
Asian traditions of collective ownership clashes with the protection of intellectual property
allowing software infringement, illicit use and misuse of corporate resources without any
lawful consequences. I have not had any personal experience with any of the laws and
regulations that deal with the cyber domain.