Often laws and regulations have an immediate impact on IT professionals and the
ID: 3914518 • Letter: O
Question
Often laws and regulations have an immediate impact on IT professionals and the security position of an organization. These laws seek to establish and implement controls; maintain, protect, and assess compliance issues; identify and remediate vulnerability and deviations; and provide a reporting mechanism that can prove an organization is in compliance. However, confusion about these laws and regulations can leave organizations unsure of how to implement policies and procedures to comply with the guidelines. Choose a law or regulation (new or revised version) and list three immediate impacts that may be felt by IT and require organization compliance.
Explanation / Answer
Answer)
In today's world Information security and compliance is a very important thing. Most of the times compliance are to be invoked by the governments on the companies and organizations. This does have an immediate impact on the IT professionals and the security position of an organization, as they many-a-times don't have enough time to react to it. The laws do seek to restrict and apply controls immediately and identify and remediate vulnerability and deviations and also asks the companies for the reports as the proof of the compliance systems. Thus new laws do take a toll on the companies and the infrastructure of the company and the operations. Confusion regarding these laws can leave companies in non-compliance and unsure of how to implement policies and procedures to comply with the guidelines. For example, one such recent law which did the same was:
Cybersecurity Information Sharing Act (CISA) where in the companies were to share information regarding the cybersecurity threats and their details with the US Government.
This had immediate effects in companies trying to comply to this rule:
a) Changing of the infrastructure was a huge problem and setting up the means to sharing Internet information U.S. government and technology and manufacturing companies.
b) Specialized personnel appointment was required in a short time and also understanding the law and how it worked and what the company needed to do to comply to that.
c) Risks and problems of sharing the information if it is intercepted and also setting up a secured network or connecting to the same.
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.