- Encryption
- Integrity
- Classification
- Segmentation
- Access Control
- Impact of Laws and Regulations
- Records Management
- Data Loss Prevention (DLP)
- Cloud Access Security Broker (CASB)
- What Next?
Impact of Laws and Regulations
As previously mentioned, many laws and regulations govern how data is treated in an organization. They will vary depending on where your data is located. For example, the laws that govern data in the United States are different from the laws that govern data in the European Union (EU).
The laws and rules are numerous and vary based on the industry of your organization. For example, if your company is a retailer and you accept credit card payments, you will likely need to follow PCI Security Standards when dealing with credit card data. If your organization is a hospital, you will need to follow HIPAA regulations when dealing with patient data.
For the certification exam, it likely is not worthwhile to memorize a bunch of laws and regulations. Many organizations have full-time staff devoted to ensuring these laws are followed. Being aware of the impact of these laws is most critical for the exam.
Legal Hold
Organizations cannot just delete information whenever they want. Some information, such as employee records, must be maintained for specific periods of time in the event of investigations or litigation. The term legal hold is used by an organization’s legal department to indicate how long specific data must be stored and how it should be made available in the event it is needed.