1
1

00:00:00,360  -->  00:00:02,250
<v Presenter>Legal requirements.</v>
2

2

00:00:02,250  -->  00:00:03,870
In this lesson, we're going to talk about
3

3

00:00:03,870  -->  00:00:06,960
some of the legal requirements around privacy.
4

4

00:00:06,960  -->  00:00:09,240
Now, any type of information or asset
5

5

00:00:09,240  -->  00:00:12,720
needs to consider how a compromise of that information
6

6

00:00:12,720  -->  00:00:15,300
can threaten the three core security attributes
7

7

00:00:15,300  -->  00:00:16,950
of the CIA triad,
8

8

00:00:16,950  -->  00:00:20,160
confidentiality, integrity and availability.
9

9

00:00:20,160  -->  00:00:22,020
And I mentioned this a lot in my courses
10

10

00:00:22,020  -->  00:00:23,430
but if you're thinking about CIA,
11

11

00:00:23,430  -->  00:00:25,290
I like to think about confidentiality
12

12

00:00:25,290  -->  00:00:27,120
usually has to do with encryption,
13

13

00:00:27,120  -->  00:00:30,090
integrity usually has to do something with hashing,
14

14

00:00:30,090  -->  00:00:31,890
and availability usually has to do
15

15

00:00:31,890  -->  00:00:33,300
something with redundancy.
16

16

00:00:33,300  -->  00:00:35,700
And so if you keep those three key words in mind,
17

17

00:00:35,700  -->  00:00:37,470
it'll help you figure out what the right answer is
18

18

00:00:37,470  -->  00:00:39,240
when you're dealing with CIA triad,
19

19

00:00:39,240  -->  00:00:41,100
and things associated with it.
20

20

00:00:41,100  -->  00:00:43,140
Now, what we're going to really focus on in this lesson
21

21

00:00:43,140  -->  00:00:46,230
is the difference between privacy and security.
22

22

00:00:46,230  -->  00:00:48,330
Now, when we talk about security controls,
23

23

00:00:48,330  -->  00:00:50,880
there is that focus on CIA attributes
24

24

00:00:50,880  -->  00:00:52,440
of the processing system.
25

25

00:00:52,440  -->  00:00:54,840
So if I say, "This data is encrypted."
26

26

00:00:54,840  -->  00:00:58,050
Well, that is a security control, that's confidentiality.
27

27

00:00:58,050  -->  00:00:59,760
If I say, "This data has been hashed
28

28

00:00:59,760  -->  00:01:01,350
so I have a digital fingerprint of it."
29

29

00:01:01,350  -->  00:01:03,450
That tells me we have integrity of it,
30

30

00:01:03,450  -->  00:01:04,530
but that's all security
31

31

00:01:04,530  -->  00:01:07,710
that doesn't tell me whether or not that data is private,
32

32

00:01:07,710  -->  00:01:09,840
if it's been kept private from other people.
33

33

00:01:09,840  -->  00:01:11,430
And so that's something we have to think about,
34

34

00:01:11,430  -->  00:01:13,170
when we talk about privacy
35

35

00:01:13,170  -->  00:01:15,600
we're really talking about a data governance requirement
36

36

00:01:15,600  -->  00:01:17,100
that arises when you're collecting
37

37

00:01:17,100  -->  00:01:18,870
and processing personal data
38

38

00:01:18,870  -->  00:01:21,240
to ensure the rights of the subject's data.
39

39

00:01:21,240  -->  00:01:22,830
So if I collect information from you
40

40

00:01:22,830  -->  00:01:24,030
when you sign up for my course,
41

41

00:01:24,030  -->  00:01:25,980
I get your name, your email,
42

42

00:01:25,980  -->  00:01:27,810
maybe your credit card information.
43

43

00:01:27,810  -->  00:01:30,240
I have to keep that information private.
44

44

00:01:30,240  -->  00:01:31,073
It doesn't necessarily mean
45

45

00:01:31,073  -->  00:01:33,090
that I have to have it encrypted in my database,
46

46

00:01:33,090  -->  00:01:34,620
although we do that,
47

47

00:01:34,620  -->  00:01:35,453
we just have to make sure
48

48

00:01:35,453  -->  00:01:36,990
that nobody else can get that data
49

49

00:01:36,990  -->  00:01:39,660
who doesn't have a need to know inside our organization.
50

50

00:01:39,660  -->  00:01:41,580
That's the idea of privacy.
51

51

00:01:41,580  -->  00:01:43,230
Now, one of the things that I think is unique
52

52

00:01:43,230  -->  00:01:46,110
is the way privacy is seen across the globe.
53

53

00:01:46,110  -->  00:01:48,180
Depending on where you are and where you live,
54

54

00:01:48,180  -->  00:01:50,880
privacy is either a bigger or less deal to you.
55

55

00:01:50,880  -->  00:01:52,770
For instance, when you go to a website
56

56

00:01:52,770  -->  00:01:54,450
and you look at the privacy policy,
57

57

00:01:54,450  -->  00:01:56,370
do you actually read through all of the pages
58

58

00:01:56,370  -->  00:01:58,200
of legalese to figure out what they're saying
59

59

00:01:58,200  -->  00:02:00,090
they can do with your private information?
60

60

00:02:00,090  -->  00:02:01,500
Most people don't.
61

61

00:02:01,500  -->  00:02:03,630
But if you're in someplace like Europe,
62

62

00:02:03,630  -->  00:02:06,120
they take privacy much more seriously
63

63

00:02:06,120  -->  00:02:08,250
and they have things like the right to be forgotten,
64

64

00:02:08,250  -->  00:02:09,270
and they have GDPR
65

65

00:02:09,270  -->  00:02:11,940
which says that you have to write your privacy policy
66

66

00:02:11,940  -->  00:02:14,130
in a very clear and easy-to-understand method,
67

67

00:02:14,130  -->  00:02:16,380
not legalese like we do here in the States.
68

68

00:02:16,380  -->  00:02:18,810
So even just the difference between European countries
69

69

00:02:18,810  -->  00:02:20,610
and the United States has a big difference
70

70

00:02:20,610  -->  00:02:22,530
in the way we view privacy.
71

71

00:02:22,530  -->  00:02:24,300
Now because of the cultural differences
72

72

00:02:24,300  -->  00:02:26,250
and the cultural pressure that's been applied,
73

73

00:02:26,250  -->  00:02:28,920
there are different legal requirements in different areas.
74

74

00:02:28,920  -->  00:02:29,940
There are legal requirements
75

75

00:02:29,940  -->  00:02:32,220
that will affect your corporate governance and policies
76

76

00:02:32,220  -->  00:02:35,310
in regards to privacy of your user's data.
77

77

00:02:35,310  -->  00:02:37,530
As a company that works worldwide with people,
78

78

00:02:37,530  -->  00:02:39,390
we have students all over the world,
79

79

00:02:39,390  -->  00:02:40,680
we have to be aware of that.
80

80

00:02:40,680  -->  00:02:42,960
And so we keep in mind what the legal requirements are
81

81

00:02:42,960  -->  00:02:45,270
in the different areas we're operating in.
82

82

00:02:45,270  -->  00:02:46,770
Now, one of the biggest requirements
83

83

00:02:46,770  -->  00:02:47,910
and one of the best requirements
84

84

00:02:47,910  -->  00:02:50,580
in terms of privacy is GDPR.
85

85

00:02:50,580  -->  00:02:53,130
This is the General Data Protection Regulation,
86

86

00:02:53,130  -->  00:02:55,860
and this says that personal data cannot be collected,
87

87

00:02:55,860  -->  00:02:57,240
processed or retained
88

88

00:02:57,240  -->  00:02:59,850
without the individual's informed consent.
89

89

00:02:59,850  -->  00:03:01,950
Now, when I talk about informed consent,
90

90

00:03:01,950  -->  00:03:04,050
this means that the data must be collected
91

91

00:03:04,050  -->  00:03:06,270
and processed only for the stated purpose,
92

92

00:03:06,270  -->  00:03:08,730
and that purpose must be clearly described
93

93

00:03:08,730  -->  00:03:12,030
to the user in plain language, not legalese.
94

94

00:03:12,030  -->  00:03:13,477
So if you go to a website and they say,
95

95

00:03:13,477  -->  00:03:15,870
"Give us your name, your email, and your home address,
96

96

00:03:15,870  -->  00:03:17,640
so that we can sell you this product
97

97

00:03:17,640  -->  00:03:19,260
and then deliver it to your house,"
98

98

00:03:19,260  -->  00:03:20,700
that's the state of purpose.
99

99

00:03:20,700  -->  00:03:22,080
That doesn't mean that they can now
100

100

00:03:22,080  -->  00:03:25,410
send you mailers every single week to your home address
101

101

00:03:25,410  -->  00:03:26,970
to try to get you to buy more stuff,
102

102

00:03:26,970  -->  00:03:29,040
unless that was part of their privacy policy
103

103

00:03:29,040  -->  00:03:30,270
that you accepted.
104

104

00:03:30,270  -->  00:03:33,000
So GDPR says they have to be upfront with this.
105

105

00:03:33,000  -->  00:03:35,520
Now, GDPR also provides the right for a user
106

106

00:03:35,520  -->  00:03:38,130
to withdraw consent at any time,
107

107

00:03:38,130  -->  00:03:39,870
it also gives 'em the ability to inspect,
108

108

00:03:39,870  -->  00:03:42,420
amend or erase data that's held about them.
109

109

00:03:42,420  -->  00:03:44,910
We like to call this the right to be forgot.
110

110

00:03:44,910  -->  00:03:47,760
If you're a resident and citizen of the European Union
111

111

00:03:47,760  -->  00:03:50,617
you can call up the company or fill out their form and say,
112

112

00:03:50,617  -->  00:03:51,660
"I want you to forget
113

113

00:03:51,660  -->  00:03:53,490
everything you've ever known about me."
114

114

00:03:53,490  -->  00:03:55,050
and they have to go into their database
115

115

00:03:55,050  -->  00:03:56,520
and scrub you out of it.
116

116

00:03:56,520  -->  00:03:58,020
That is part of that law,
117

117

00:03:58,020  -->  00:03:59,310
it gives you a lot of protections
118

118

00:03:59,310  -->  00:04:00,990
if you're a European citizen.
119

119

00:04:00,990  -->  00:04:02,670
Now, if you're an American citizen
120

120

00:04:02,670  -->  00:04:04,020
we don't have that right.
121

121

00:04:04,020  -->  00:04:07,230
So if I'm sitting in Maryland and I want to be forgotten,
122

122

00:04:07,230  -->  00:04:09,300
I can't do it, that's just not something
123

123

00:04:09,300  -->  00:04:10,590
that the companies have to do for me.
124

124

00:04:10,590  -->  00:04:12,000
I can request they do that
125

125

00:04:12,000  -->  00:04:14,400
but they are not by law required to do it.
126

126

00:04:14,400  -->  00:04:15,780
So there are different protections
127

127

00:04:15,780  -->  00:04:17,430
depending on where you live in the world,
128

128

00:04:17,430  -->  00:04:19,320
and as a company operating in different areas
129

129

00:04:19,320  -->  00:04:21,180
you need to be aware of this.
130

130

00:04:21,180  -->  00:04:23,520
Now, what happens if you have a data breach?
131

131

00:04:23,520  -->  00:04:26,040
Well, this depends, again, where you are
132

132

00:04:26,040  -->  00:04:27,810
and what laws you fall under.
133

133

00:04:27,810  -->  00:04:29,880
For instance, if you deal with GDPR
134

134

00:04:29,880  -->  00:04:31,410
you have responsibilities,
135

135

00:04:31,410  -->  00:04:34,260
within 72 hours, if you're doing business within Europe,
136

136

00:04:34,260  -->  00:04:36,780
you have to notify the regulators and the users
137

137

00:04:36,780  -->  00:04:38,370
that you had a data breach.
138

138

00:04:38,370  -->  00:04:40,020
So, once again, this is an area
139

139

00:04:40,020  -->  00:04:42,150
where the European citizens have better rights
140

140

00:04:42,150  -->  00:04:43,440
than the Americans do,
141

141

00:04:43,440  -->  00:04:45,330
based on the laws that are in each of those countries
142

142

00:04:45,330  -->  00:04:46,980
at the time of this filming.
143

143

00:04:46,980  -->  00:04:49,260
Now, let me give you a quick word of warning,
144

144

00:04:49,260  -->  00:04:51,930
data breaches can happen both accidentally
145

145

00:04:51,930  -->  00:04:53,880
and through malicious interference.
146

146

00:04:53,880  -->  00:04:55,440
Just because you had a data breach
147

147

00:04:55,440  -->  00:04:57,450
doesn't mean that some hacker got in,
148

148

00:04:57,450  -->  00:04:58,770
it could have been assistant (indistinct)
149

149

00:04:58,770  -->  00:04:59,940
did the wrong thing.
150

150

00:04:59,940  -->  00:05:01,590
They entered the wrong command in the database
151

151

00:05:01,590  -->  00:05:02,760
and they dumped it to the screen,
152

152

00:05:02,760  -->  00:05:03,810
and now people are able to see
153

153

00:05:03,810  -->  00:05:05,370
everybody's social security numbers,
154

154

00:05:05,370  -->  00:05:07,410
or their dates of birth or their names.
155

155

00:05:07,410  -->  00:05:09,690
This is all types of things that have happened in the past
156

156

00:05:09,690  -->  00:05:10,980
so just keep that in mind,
157

157

00:05:10,980  -->  00:05:13,950
it's not always a malicious actor, it's not always a hacker,
158

158

00:05:13,950  -->  00:05:16,980
sometimes it's our own internal staff who makes mistakes.
159

159

00:05:16,980  -->  00:05:18,780
Now, I've mentioned GDPR a couple of times
160

160

00:05:18,780  -->  00:05:20,160
here are already in this lesson,
161

161

00:05:20,160  -->  00:05:22,410
but I want you to remember when I'm talking about GDPR
162

162

00:05:22,410  -->  00:05:24,720
I'm talking about a law inside of Europe,
163

163

00:05:24,720  -->  00:05:27,150
and GDPR does provide stronger protections
164

164

00:05:27,150  -->  00:05:30,390
than most federal or state laws in the United States.
165

165

00:05:30,390  -->  00:05:32,040
Most of the laws here in the United States
166

166

00:05:32,040  -->  00:05:34,950
are very industry specific or state specific,
167

167

00:05:34,950  -->  00:05:37,530
so we might have laws that affect the financial industry
168

168

00:05:37,530  -->  00:05:39,870
or the healthcare industry, but we don't have ones
169

169

00:05:39,870  -->  00:05:42,660
that protect all of our citizens all of the time.
170

170

00:05:42,660  -->  00:05:44,910
And for the rest of this lesson we're really going to focus
171

171

00:05:44,910  -->  00:05:47,490
on those narrower definitions of personal data
172

172

00:05:47,490  -->  00:05:49,410
in industry specific areas.
173

173

00:05:49,410  -->  00:05:51,330
So the first one I want to talk about
174

174

00:05:51,330  -->  00:05:53,970
is SOX, or Sarbanes-Oxley.
175

175

00:05:53,970  -->  00:05:55,500
When we talk about Sarbanes-Oxley,
176

176

00:05:55,500  -->  00:05:56,850
this sets forth the requirement
177

177

00:05:56,850  -->  00:05:58,920
for the storage and retention of documents
178

178

00:05:58,920  -->  00:06:00,450
that are relating to an organization's
179

179

00:06:00,450  -->  00:06:02,400
financial and business operations,
180

180

00:06:02,400  -->  00:06:04,380
including the type of documents to be stored
181

181

00:06:04,380  -->  00:06:06,120
and their retention periods.
182

182

00:06:06,120  -->  00:06:08,220
This applies to publicly traded companies,
183

183

00:06:08,220  -->  00:06:10,200
companies listed on the stock exchange,
184

184

00:06:10,200  -->  00:06:13,560
and they have to have a value of at least $75 million
185

185

00:06:13,560  -->  00:06:15,720
to be required to follow SOX.
186

186

00:06:15,720  -->  00:06:18,900
SOX came out of all the scandals in the early 2000s,
187

187

00:06:18,900  -->  00:06:21,030
things like WorldCom and Enron.
188

188

00:06:21,030  -->  00:06:23,827
And so after that, Congress stepped in and said,
189

189

00:06:23,827  -->  00:06:26,430
"All these companies need to retain their documents.
190

190

00:06:26,430  -->  00:06:28,500
We want to be able to go back and look at those records,
191

191

00:06:28,500  -->  00:06:29,880
and see what they've been doing.
192

192

00:06:29,880  -->  00:06:32,190
And that way we could try to protect the people."
193

193

00:06:32,190  -->  00:06:34,830
Another law that came out of the '90s and early 2000s
194

194

00:06:34,830  -->  00:06:37,860
was GLBA, the Gramm-Leach-Bliley Act.
195

195

00:06:37,860  -->  00:06:39,210
Now, this sets forth requirements
196

196

00:06:39,210  -->  00:06:40,440
that will help protect the privacy
197

197

00:06:40,440  -->  00:06:42,780
of an individual's financial information
198

198

00:06:42,780  -->  00:06:45,540
that's held by financial institutions and others.
199

199

00:06:45,540  -->  00:06:47,670
When we talk here about financial institutions
200

200

00:06:47,670  -->  00:06:50,100
we're talking about stockbrokers, banks,
201

201

00:06:50,100  -->  00:06:51,270
and other things like that.
202

202

00:06:51,270  -->  00:06:53,100
So if you're dealing with a mortgage company,
203

203

00:06:53,100  -->  00:06:54,630
they fall under GLBA
204

204

00:06:54,630  -->  00:06:57,870
and they have to protect the privacy of your information.
205

205

00:06:57,870  -->  00:06:59,280
Next, we have FISMA,
206

206

00:06:59,280  -->  00:07:02,190
and FISMA applies to the government itself.
207

207

00:07:02,190  -->  00:07:05,310
FISMA is the Federal Information Security Management Act.
208

208

00:07:05,310  -->  00:07:07,980
It sets forth the requirements for federal organizations
209

209

00:07:07,980  -->  00:07:10,290
to adopt information assurance controls.
210

210

00:07:10,290  -->  00:07:12,330
So if we're talking about government organizations
211

211

00:07:12,330  -->  00:07:13,163
we're talking about things like
212

212

00:07:13,163  -->  00:07:15,030
the Social Security Administration,
213

213

00:07:15,030  -->  00:07:16,740
Health and Human Services,
214

214

00:07:16,740  -->  00:07:18,870
the Department of Housing and Urban Development,
215

215

00:07:18,870  -->  00:07:21,180
the Department of Defense, which is the military.
216

216

00:07:21,180  -->  00:07:23,250
All of these folks fall under FISMA,
217

217

00:07:23,250  -->  00:07:24,600
so if you work for the government
218

218

00:07:24,600  -->  00:07:27,540
or a government contractor, FISMA applies to you.
219

219

00:07:27,540  -->  00:07:29,970
And so a lot of folks in the cybersecurity world,
220

220

00:07:29,970  -->  00:07:31,440
we end up working for the government,
221

221

00:07:31,440  -->  00:07:34,020
for the military, or one of those type of organizations.
222

222

00:07:34,020  -->  00:07:35,100
So keep FISMA in mind
223

223

00:07:35,100  -->  00:07:36,900
because it probably applies to the place you work
224

224

00:07:36,900  -->  00:07:38,370
if you're in the United States.
225

225

00:07:38,370  -->  00:07:40,980
Next we have HIPAA, which is the Health Insurance
226

226

00:07:40,980  -->  00:07:43,290
Portability and Accountability Act.
227

227

00:07:43,290  -->  00:07:45,930
This sets forth the requirements to help protect the privacy
228

228

00:07:45,930  -->  00:07:47,760
of individual's health information
229

229

00:07:47,760  -->  00:07:49,260
that's held by healthcare providers,
230

230

00:07:49,260  -->  00:07:51,630
hospitals, and insurance companies.
231

231

00:07:51,630  -->  00:07:54,900
Now, again, HIPAA is going to deal with healthcare providers,
232

232

00:07:54,900  -->  00:07:57,810
hospitals, doctors and insurance companies.
233

233

00:07:57,810  -->  00:08:00,090
If they have information about your health records
234

234

00:08:00,090  -->  00:08:01,560
it's protected by HIPAA.
235

235

00:08:01,560  -->  00:08:04,110
And so if you work for one of those sectors of the economy,
236

236

00:08:04,110  -->  00:08:06,390
make sure you're familiar with HIPAA as well.
237

237

00:08:06,390  -->  00:08:09,150
Now all of those were reviewed for you from Security+
238

238

00:08:09,150  -->  00:08:12,990
but I do have one new one for you, and this is COSO,
239

239

00:08:12,990  -->  00:08:15,330
which is the Committee of Sponsoring Organizations
240

240

00:08:15,330  -->  00:08:16,980
of the Treadway Commission.
241

241

00:08:16,980  -->  00:08:18,030
This provides guidance
242

242

00:08:18,030  -->  00:08:20,130
on a variety of governance related topics,
243

243

00:08:20,130  -->  00:08:23,640
including fraud, controls, finance, and ethics,
244

244

00:08:23,640  -->  00:08:27,000
and it relies on COSO's ERM integrated Framework,
245

245

00:08:27,000  -->  00:08:29,550
which is Enterprise Risk Management Framework.
246

246

00:08:29,550  -->  00:08:32,490
Now, this essentially is a bunch of best practices
247

247

00:08:32,490  -->  00:08:33,810
and ways of working
248

248

00:08:33,810  -->  00:08:36,630
to deal with fraud and controls and finance and ethics
249

249

00:08:36,630  -->  00:08:37,860
inside your organizations.
250

250

00:08:37,860  -->  00:08:40,860
So it's not necessarily a regulation or law
251

251

00:08:40,860  -->  00:08:43,140
but it is a best practice way of doing things,
252

252

00:08:43,140  -->  00:08:45,540
and so it is something you could consider as well.
253

253

00:08:45,540  -->  00:08:48,390
Now, I know that was a lot of different laws and regulations
254

254

00:08:48,390  -->  00:08:50,610
that we talked about in terms of privacy,
255

255

00:08:50,610  -->  00:08:52,950
and there are countless other laws and regulations
256

256

00:08:52,950  -->  00:08:54,240
around the globe.
257

257

00:08:54,240  -->  00:08:57,000
We really did focus on really only two main areas,
258

258

00:08:57,000  -->  00:09:00,570
Europe with GDPR, and then America with all the rest.
259

259

00:09:00,570  -->  00:09:04,020
But if you're located in Canada or India, or someplace else,
260

260

00:09:04,020  -->  00:09:06,180
there are laws and regulations that apply to you
261

261

00:09:06,180  -->  00:09:07,830
based on your own countries.
262

262

00:09:07,830  -->  00:09:09,930
But if you know the ones I talked about in this lesson,
263

263

00:09:09,930  -->  00:09:11,190
you're going to do fine on the exam
264

264

00:09:11,190  -->  00:09:13,353
in terms of privacy and legal requirements.
