★ Starred in your notes: regulatory compliance (SOX, HIPAA, GLBA, GDPR, PCI DSS) · key escrow (external) vs. recovery agent (internal).
Breakdown 1 — The document hierarchy
| Document | What it is | Binding? | Example |
|---|---|---|---|
| Policy | High-level what and why, approved by management | Mandatory | "All remote access requires MFA" |
| Standard | Specific requirements that implement a policy | Mandatory | "Passwords ≥ 14 chars; AES-256 for data at rest" |
| Procedure | Step-by-step how | Mandatory | "How to onboard a new hire" |
| Guideline | Recommended practices | Optional | "Tips for choosing a passphrase" |
| Playbook | Procedure for a specific scenario (incident type) | "Ransomware playbook" |
From class — security documentation: framework (NIST CSF, ISO 27001, CIS) → policy. Typical policies: AUP (acceptable use policy), BCP (business continuity policy/plan), change management policy; credential/password policies (key escrow → external holds the private key; recovery agent → internal); asset management; secure personnel policy: clean desk (keep information away from others' eyes), separation of duties (no single person controls a whole process — SOX compliance).
Policies the exam lists: AUP · Information security policies · Business continuity · Disaster recovery · Incident response · SDLC (secure development lifecycle) · Change management. Standards: password · access control · physical security · encryption. Procedures: change management · onboarding/offboarding · playbooks.
Breakdown 2 — External considerations
| Driver | Examples |
|---|---|
| Regulatory | HIPAA (health), SOX (public-company financial reporting), GLBA (financial privacy), PCI DSS (card data — contractual, not law), GDPR (EU personal data), FERPA (student records) |
| Legal | Contracts, breach-notification laws, e-discovery |
| Industry | PCI DSS, NERC CIP (utilities), sector ISAC guidance |
| Local/regional · National · Global | State privacy laws (CCPA) · federal (HIPAA) · GDPR — the strictest applicable one usually wins |
From class: SOX → accurate financial reporting; GLBA → finance; GDPR → EU person protected wherever the data goes (keywords: data sovereignty, right to be forgotten, data controller, data processor); PCI DSS → credit cards ("don't worry about the full compliance list"); HIPAA → health. Due diligence → do your part before (investigate/verify); due care → act responsibly on an ongoing basis.
Breakdown 3 — Monitoring, revision, and governance structures
- Monitoring and revision: policies are reviewed on a schedule and after incidents, audits, new laws, or major changes; version-controlled with owners.
- Governance structures: Boards (directors — ultimate accountability), committees (steering/security committees that set direction), government entities (regulators), centralized (one security org sets rules) vs. decentralized (business units own their security within a framework).
Breakdown 4 — Roles and responsibilities for systems and data
| Role | Responsibility | GDPR-speak |
|---|---|---|
| Owner | Accountable for the asset/data: classification, access approval, risk acceptance (usually a business executive) | |
| Controller | Decides why and how personal data is processed | The company collecting customer data |
| Processor | Processes data on behalf of the controller | The cloud/payroll vendor |
| Custodian / steward | Day-to-day handling: backups, permissions, integrity (IT/DBA) |
Exam tip: "Who classifies the data?" → owner. "Who implements backups per the owner's rules?" → custodian. "SaaS vendor processing your customer records" → processor; you are the controller. "Mandatory document with specific settings" → standard; "recommended" → guideline; "step-by-step" → procedure.
Quick self-check
- Policy vs. standard vs. procedure vs. guideline?
- Controller vs. processor?
- Which law covers public-company financial reporting? (SOX.)
Sources: 20260917_173216.jpg, 20260917_173221.jpg, 20260917_173259.jpg, 20260917_173307.jpg