Security Consideration (Regulatory, Legal, Industry, Geographic)
- •
def
- •
the various external factors that shape an organization's security requirements
- •
- •
categories
- •
regulatory — mandated requirements around logging, data storage, protection, and retention (e.g., Sarbanes-Oxley/SOX, HIPAA)
- •
legal — reporting illegal activity, retaining data for legal proceedings, breach notification laws (which vary by jurisdiction, and get more complex as cloud data crosses borders)
- •
industry — different markets have different needs (e.g., isolated utility control systems, highly secure medical data storage)
- •
geographical — local/regional, national, and global scope, each with different legal requirements
- •
- •
related