secplus

Dashboard / 5.0 Security Program Management and Oversight

5.4 Summarize elements of effective security compliance

Official exam objective outline (4 topics)
  • Compliance reporting
    • Internal
    • External
  • Consequences of non-compliance
    • Fines
    • Sanctions
    • Reputational damage
    • Loss of license
    • Contractual impacts
  • Compliance monitoring
    • Due diligence/care
    • Attestation and acknowledgement
    • Internal and external
    • Automation
  • Privacy
    • Legal implications: Local/regional, National, Global
    • Data subject
    • Controller vs. processor
    • Ownership
    • Data inventory and retention
    • Right to be forgotten

Breakdown 1 — Compliance reporting

  • Internal — to management/board/audit committee: status of controls, exceptions, KRIs.
  • External — to regulators, customers, auditors: attestations (SOC 2), PCI reports, breach notifications within legal deadlines (GDPR: 72 hours).

Breakdown 2 — Consequences of non-compliance (class: know these)

ConsequenceExample
FinesGDPR up to 4% of global revenue; HIPAA per-record penalties
SanctionsRegulator restricts operations; individuals barred
Reputational damageCustomer loss after a public breach
Loss of licenseAbility to operate revoked (banking, healthcare)
Contractual impactsPCI: card brands raise fees or terminate processing; SLA penalties

Breakdown 3 — Compliance monitoring

ElementMeaning
Due diligence / due careDiligence = investigate and verify before (class: "do your part before"); care = act responsibly ongoing
Attestation and acknowledgementPeople sign that they read/follow policy (AUP acknowledgement); executives attest to controls (SOX)
Internal and external monitoringSelf-checks plus outside audits/assessments
AutomationCompliance dashboards, SCAP scans, continuous control monitoring instead of annual spreadsheets

Breakdown 4 — Privacy (class keywords: GDPR)

ConceptMeaning
Legal implications — local/regional, national, globalState laws (CCPA), federal (HIPAA/GLBA), global (GDPR) — apply the strictest that covers the data subject
Data subjectThe person the data is about
Controller vs. processorController decides purpose/means; processor acts on the controller's instructions (both have obligations under GDPR)
OwnershipWho owns/is accountable for the data (organizationally the data owner; legally the subject has rights over personal data)
Data inventory and retentionKnow what personal data you hold, where, why, and for how long; delete when no longer needed
Right to be forgottenSubject can request erasure (GDPR right to erasure)
Data sovereignty (class)Data subject to the laws of where it's stored

From class — regulations recap: SOX (financial reporting accuracy; separation of duties), HIPAA (health), GLBA (financial privacy), GDPR (EU personal data — sovereignty, right to be forgotten, controller/processor), PCI DSS (credit cards), FERPA (education — crossed out in class).

Exam tip: "Customer asks that all their data be deleted" → right to be forgotten. "Employees sign the AUP annually" → acknowledgement. "Company lost its ability to process cards" → contractual impact. "Which is the processor?" → the vendor doing the work for the controller.

Quick self-check

  • Name three consequences of non-compliance.
  • Due diligence vs. due care?
  • Who is the data subject?

Sources: 20260917_173216.jpg, 20260917_173221.jpg, 20260917_182502.jpg