WorksheetsCyber L&P CHP 6 contd....
Total questions: 56
Worksheet time: 1hrs 11mins
Program policies are ________ and program procedures are __________.
prescriptive, descriptive
descriptive, prescriptive
No cryptography algorithms shall be used unless the patent has either expired or the company maintains a valid license. License arrangement must meet the expected use of the product or service life as well as comply with export control guidelines
Encryption Personal Use Exemption
International Encryption Law Compliance
Cryptography Patent Infringement
Export Control Law
State Encryption Safe Harbor Provisions
Travel by employees to countries that do not extend personal use exemptions will require authorization by the legal department and the filing of an encryption import license
Encryption Personal Use Exemption
International Encryption Law Compliance
Cryptography Patent Infringement
Export Control Law
State Encryption Safe Harbor Provisions
Software or hardware products containing an encryption level higher than 512-bit key encryption will not be sent or used outside of the US.
Encryption Personal Use Exemption
International Encryption Law Compliance
Cryptography Patent Infringement
Export Control Law
State Encryption Safe Harbor Provisions
Personal healthcare information (PHI) of employees or customers, regardless of the Health Insurance Portability and Accountability Act (HIPAA) compliance requirements, will be encrypted with an algorithm and processes prescribed by the company’s PHI risk assessment
Encryption Personal Use Exemption
International Encryption Law Compliance
Healthcare Data Privacy
Import Control Law
State Encryption Safe Harbor Provisions
In the event travel or equipment deployment is required within an import restricted country, an appropriate license will be filed, and only after US Department of State approval will the activity proceed.
Encryption Personal Use Exemption
International Encryption Law Compliance
Healthcare Data Privacy
Import Control Law
State Encryption Safe Harbor Provisions
Data sent to and stored in foreign countries will comply with all local encryption laws. If local encryption law requires a lower level of key length than currently used, an application for an export license will be necessary.
Encryption Personal Use Exemption
International Encryption Law Compliance
Healthcare Data Privacy
Import Control Law
State Encryption Safe Harbor Provisions
Employees traveling to countries that require key disclosure will abide by all local encryption laws including providing the password to decrypt information requested by local authorities. Any time a request is made the employee will immediately notify the legal department
Key Disclosure Laws
International Encryption Law Compliance
Healthcare Data Privacy
Import Control Law
State Encryption Safe Harbor Provisions
Encryption of personal data at a level meeting or exceeding the highest-level key length of any state will be followed to ensure compliance with all state safe harbor provisions.
Key Disclosure Laws
International Encryption Law Compliance
Healthcare Data Privacy
Import Control Law
State Encryption Safe Harbor Provisions
Applications or systems that interact with minors (13 and under) will comply with the standards of the Internet Keep Safe Coalition (iKeepSafe) and its Safe Harbor program under the Children’s Online Privacy Protection Act (COPPA).
Federal Children’s Online Privacy Law
Privacy Law Library
State Minor’s Privacy Acts
A current library of state, federal, and international privacy laws will be maintained. A cross-mapping of security controls with legal requirements will be maintained to ensure alignment with the cybersecurity program.
Federal Children’s Online Privacy Law
Privacy Law Library
State Minor’s Privacy Acts
Applications or systems that interact with minors (17 and under) will abide by all provisions of any state’s child privacy law including prohibiting the sale of dangerous products and complying with requests to remove personal data
Federal Children’s Online Privacy Law
Privacy Law Library
State Minor’s Privacy Acts
Digital evidence will be gathered according to the Federal Rules of Evidence under the oversight of the legal department
Digital Best Evidence Rule
Digital Chain of Custody
Digital Data Spoliation
Preservation Order
Search and Seizure of Encrypted Data
To ensure evidence in a cybercrime investigation is admissible in a court of law, all evidence will be gathered according to the US Department of Justice’s Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations manual under the oversight of the legal department.
Digital Best Evidence Rule
Digital Chain of Custody
Digital Data Spoliation
Preservation Order
Search and Seizure of Encrypted Data
In the event of a pending lawsuit or issuance of a preservation order, no employee or contractor will destroy or alter in any way the data identified by the court order.
Digital Best Evidence Rule
Digital Chain of Custody
Digital Data Spoliation
Preservation Order
Search and Seizure of Encrypted Data
No action will be taken unless and until the direct oversight of the legal department has begun. All documents requested will be secured in a manner as to preserve them for plaintiff discovery.
Digital Best Evidence Rule
Digital Chain of Custody
Digital Data Spoliation
Preservation Order
Search and Seizure of Encrypted Data
If a discovery order is received to produce information, full cooperation will be provided to the plaintiff’s legal counsel and the data will be decrypted and submitted. This process can only occur under the direction of legal counsel.
Digital Best Evidence Rule
Digital Chain of Custody
Digital Data Spoliation
Preservation Order
Search and Seizure of Encrypted Data
The company will carry a cyber liability insurance policy for up to $5 million above the self-insurance loss pool of $1 million with a $100,000 per loss deductible for third party losses.
Cyber Liability Insurance Policy
Annual Coverage Assessment
Preservation Order
Search and Seizure of Encrypted Data
An annual assessment of cyber liability coverage will be performed considering the estimated loss exposure for a data breach based on the projected number of compromised records in the next physical year.
Cyber Liability Insurance Policy
Annual Coverage Assessment
Preservation Order
Search and Seizure of Encrypted Data
The ___________ standard is a set of practices for the ___________ which provides guidance on aligning information technology with the business.
(a)
Organizations that expect involvement in several data breach lawsuits need to consider a software product specifically designed to manage the litigation process and maintain legal holds This software is called:
(a)
What do eDiscovery software do?
What are the 3 advantages of eDiscovery Software?
Your program will require a significant quantity of documents that will need to be stored and easily accessed by program participants. For this, you will create a_________ library in Microsoft ________ where they can be_________ or _________. (use all lower-case letters and commas to separate them)
(a)
Is a way to flag a document with keywords so that anyone searching for that kind of information may locate it.
(a)
What are sample meta-tags in documents for each of the following: Category of law, program component, document attributes, geographical applicability, jurisdiction, document type.
Is a technology used to track websites and stream updates to a data repository, such as a spreadsheet or database. This makes keeping up with changes in the law more efficient.
RSS
ITIL
ITSM
Law and regulations library
Why would a company need to subscribe to Thomas Reuter's WestLaw or LexisNexis?
Are products and services available that can scan your network testing your cybersecurity and privacy controls to the policies you established to maintain compliance.
(a)
Policy scanners are available as a cloud-based service, meaning they're operated by 3rd parties, and as standalone products in which users can use first-hand.
True
False
When conducting data breach investigations, your organization will require a __________ to either identify evidence destroyed by employees or create evidence according to the best evidence rule.
Forensic Toolkit
Law Library
Network scanners
Preservation order
eDiscovery softwares
Explain how Forensic Toolkits work
Describe the process of mapping legal requirements to controls
This type of insurance covers non-fraudulent causes of failures or errors occurring in the performance of computer services. Technology companies offering cloud, software, or consulting services typically acquire this type of insurance.
Errors and Omissions
Media Liability
Network Security
Privacy
Network Security and Privacy Liability
This type of insurance covers customer injury claims resulting from intellectual property infringement, copyright or trademark infringement, libel, and slander. Coverage could also be extended to patents or trade secret violations. This coverage is important to organizations with sizable online presences.
Errors and Omissions
Media Liability
Network Security
Privacy
Network Security and Privacy Liability
This type of insurance covers network equipment failures or external attacks against your network including denial of service attacks. Network outages or breaches covered can include data breaches of consumer information, cyber extortion, data alteration or destruction, or malware infestations.
Errors and Omissions
Media Liability
Network Security
Privacy
Network Security and Privacy Liability
This type of insurance covers breach of physical records caused by theft, loss, or accidental disclosure. Other incidents that may be covered include improper disposal of equipment containing sensitive data and inadvertently collecting confidential information
Errors and Omissions
Media Liability
Network Security
Privacy
Network Security and Privacy Liability
This type of insurance is a hybrid policy that also provides coverage for both the insured company and their third-party service providers. It covers the costs for responding to and recovering from data breaches, including penalties assessed from a lawsuit.
Errors and Omissions
Media Liability
Network Security
Privacy
Network Security and Privacy Liability
What are first party losses that insurance companies can cover?
What are third party losses that insurance companies can cover?
Is an amount of insurance coverage available to cover a specific type of loss.
Sublimit
Residual Risk
Blanket Insurance
The risk that is left after you have applied all your security control
Sublimit
Residual Risk
Blanket Insurance
The 5 ways cyber liability insurance policy can help even when no claim exists by providing:
The cost of cyber liability insurance is based on the following factors:
_______ companies paid the highest premiums followed by _______ companies.
(a)
(a) companies paid the least in premium payments.
_________companies purchased the highest levels of coverage, followed by ________.
(a)
Define 4 examples where insurance companies would deny paying the claims
Difference between insured and uninsured risks
(a) : cyber-related losses stemming from insurance policies that were not specifically designed to cover cyber risk—meaning an insurer may have to pay claims for cyber losses under a policy not designed for that purpose.
Reviews the company's adherence to the policy provisions provided, or just anything they must stick to, in general
(a)
What are the elements included in the Compliance auditing model?
What is the difference between Internal and External Auditing?
Compliance with legal and regulatory standards and statutes is a prime focus of many external audit organizations today.
True
False
Verifying the financial statements and risk to the organization is the main focus of external auditors
True
False
Internal auditors________ controls, while external auditors ________ controls.
(a)
