Start Here
Five review stations, each a different way to practice Chapter 15. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.
What this chapter asked you to be able to do
- Place a statement in the governance hierarchy of policy, standard, procedure, guideline, and baseline, and explain how each level adds specificity.
- Apply the major regulatory frameworks (GDPR, HIPAA, PCI DSS, SOX, FISMA) to a scenario and state what each one requires.
- Explain the difference between compliance (meeting requirements) and security (actual protection), and why an organization can be compliant but insecure.
- Communicate a technical finding as business risk by quantifying financial impact and matching the message to the stakeholder.
- Describe third-party risk management, service level agreements, supply chain security, and responsible disclosure.
Your progress this session
These counters update as you check answers on each station. They reset when you reload the page.
Key Terms Flashcards
Select a card to reveal its definition, then select again to flip it back. Try to state the definition before you flip. The counter tracks how many distinct cards you have opened.
Placing Statements in the Governance Hierarchy
Security governance runs from broad to specific: policy, standard, procedure, guideline, and baseline. Read each statement and choose the level it belongs to, then check your answer.
Matching Scenarios to Regulatory Frameworks
Each framework governs a different kind of data, industry, or organization. Read each scenario and choose the framework that applies, then check your answer.
Reference: regulatory frameworks at a glance
| Framework | Who it covers | Signature requirement |
|---|---|---|
| GDPR | Any organization processing EU residents' data | Report a personal data breach within 72 hours |
| HIPAA | Healthcare organizations and their business associates | Administrative, physical, and technical safeguards plus business associate agreements |
| PCI DSS | Organizations that process, store, or transmit card data | Encrypt cardholder data and run regular scans and penetration tests |
| SOX | Publicly traded companies and their auditors | Document and test internal controls over financial reporting |
| FISMA | U.S. federal agencies and their contractors | Implement NIST-based controls and obtain an authority to operate |
A single organization can fall under several frameworks at once, for example a hospital that also takes card payments and processes data of EU patients.
Matching the Message to the Stakeholder
The same finding is framed differently for different audiences. Read each description of what an audience needs, then choose the stakeholder it fits.
Knowledge Check
Ten multiple-choice questions across the whole chapter. Answer them all, then select Score my answers for feedback and a final total.