By Fatskills Exam Guides Team — the exam nerds behind 28,500+ quizzes and 2.1M practice questions across 500+ global exams.
Legal, regulatory, and compliance (LRC) frameworks ensure organizations protect sensitive data, avoid fines, and maintain trust. These rules (like GDPR, HIPAA, PCI-DSS, and SOX) define how data must be handled, stored, and secured. Failure to comply can lead to massive penalties, lawsuits, or breaches—like the 2017 Equifax breach (PCI-DSS violation, $700M+ in fines) or Uber’s 2016 GDPR fine (€10M for hiding a data leak). Security professionals must know these laws to design controls, respond to incidents, and pass audits.
GDPR (General Data Protection Regulation): EU law (2018) protecting personal data of EU citizens. Key rights: Right to erasure, data portability, breach notification within 72 hours. Fines: Up to 4% of global revenue or €20M (whichever is higher). Tools: OneTrust, TrustArc (privacy management).
HIPAA (Health Insurance Portability and Accountability Act): U.S. law protecting PHI (Protected Health Information). Key rules: Privacy Rule (patient rights), Security Rule (technical safeguards), Breach Notification Rule (60-day reporting). Fines: Up to $1.5M/year per violation. Tools: Epic, Cerner (HIPAA-compliant EHRs).
PCI-DSS (Payment Card Industry Data Security Standard): Global standard for securing cardholder data (CHD). 12 requirements (e.g., encrypt transmission, restrict access). Fines: $5K–$100K/month for non-compliance. SAQ (Self-Assessment Questionnaire) determines compliance level. Tools: Qualys, Trustwave (PCI scanning).
SOX (Sarbanes-Oxley Act): U.S. law (2002) for financial reporting integrity (post-Enron). Key sections: 302 (CEO/CFO certification), 404 (internal controls), 802 (document retention). Fines: Up to $5M + 20 years prison for fraud. Tools: SAP GRC, RSA Archer.
PII (Personally Identifiable Information): Data that can identify an individual (e.g., SSN, email, biometrics). GDPR/HIPAA protect PII; PCI-DSS protects CHD (a subset of PII).
PHI (Protected Health Information): HIPAA term for health-related PII (e.g., medical records, lab results). De-identified PHI (removed identifiers) is not covered.
Data Controller vs. Data Processor (GDPR):
Processor: Handles data on behalf of the controller (e.g., cloud provider). Both are liable under GDPR.
DPO (Data Protection Officer): Mandatory under GDPR (for public authorities or large-scale processing). Role: Ensures compliance, reports to highest management, acts as contact for supervisory authorities (e.g., CNIL in France).
Breach Notification:
PCI-DSS: Immediate reporting to payment brands (Visa, Mastercard).
Audit vs. Assessment:
Assessment: Internal review (e.g., HIPAA Security Risk Assessment).
Safe Harbor vs. Privacy Shield:
Privacy Shield (2016–2020): Replacement (invalidated by Schrems II). Now use SCCs (Standard Contractual Clauses) or BCRs (Binding Corporate Rules).
NIST CSF (Cybersecurity Framework): Voluntary framework (Identify, Protect, Detect, Respond, Recover) to align security with business risks. Not a law, but often referenced in compliance (e.g., HIPAA, SOX).
Tool: Compliance mapping matrix (e.g., NIST SP 800-66 for HIPAA).
Conduct a Gap Analysis
Tool: Nessus, OpenVAS (vulnerability scanning), Drata, Vanta (automated compliance).
Implement Controls
Example: HIPAA Security Rule → Access controls (45 CFR § 164.310).
Document Everything
Example: SOX Section 404 → Document internal controls (e.g., change management logs).
Train Employees & Monitor Compliance
Tool: KnowBe4 (phishing tests), Splunk (log analysis).
Prepare for Audits & Respond to Incidents
D) PCI-DSS + SOX ✅ Correct Answer: C Explanation: HIPAA applies to U.S. health data; GDPR applies because data is stored in the EU.
A company suffers a ransomware attack encrypting credit card data. What’s the first compliance step?
D) Conduct a forensic investigation ✅ Correct Answer: C Explanation: PCI-DSS requires immediate reporting to payment brands (even before notifying customers).
Which SOX section requires CEOs/CFOs to certify financial reports?
Final Tip: Memorize the "big 4" (GDPR, HIPAA, PCI-DSS, SOX) + their key deadlines/fines. Most exam questions test which law applies in a scenario. Good luck! ?
Join 4M+ learners. Unlock unlimited quizzes, wrong-answer tracking, flashcards + reminders, study guides, and 1-on-1 challenges.