Compliance and Regulations IT security has a variety of laws and regulations tha
ID: 669367 • Letter: C
Question
Compliance and Regulations
IT security has a variety of laws and regulations that one must be aware and adhere. Pick three items from the attached list. Give a brief history of the regulation or law and how it pertains to IT security. For the final part of this assignment, put yourself in the role of an IT Security Officer for a local Ohio hospital. List the laws and regulations that would pertain to an online breach of 10,000 patient records with identifiable data such as SSN and payment history.
List:
• HIPPA
• FERPA
• SOX
• PCI
• FISMA
• GLBA
• CIPA
• State Laws (pick 1 state of your choice)
Course Outcomes
Summarize compliance laws relevant to IT within a given industry.
Explanation / Answer
HIPPA: The Health Insurance Portabilityand Accountability Act.
This act is to improve portability and continuity of health insurance coverage in the
group and individual markets.
The rules for this HIPPA are
i) unique identifiers Rule
ii) The HIPPA Privact Rule
iii) The transactions and code sets Rule
iv) The HIPPA Security Rule.
v) The Enforcement Rule.
HIPPA security rule comprises three types of security safeguards: adminstrative, physical and techinical.
...>adminstrative comprises policies and procedures design
...>Physical safeguards is to controlling physical access to protect against inappropriate
access to protect data.
...>Technical reles comprises giving an protecting electronically.
-----------------------------------------------------------------------------
FERPA: Family Education Rights and Privacy Act
This is a federal law that ptotects the Privacy of student education records.
Rights are transferred to students when they reaches their age 18.
Parents or students(age>18) can inspect and review the srudent education records
maintained by school.
Two types of access will be available..
i) Access to public Records.
ii) Student Medical Records.
----------------------------------------------------------------------
FISMA: Federal Information Security Management Act.
This act recognises the importance of information security to the economic and national security
interest of the US. This Act bought attention to federal Govt. to cybersecurity and
emphasize a risk bases policy for cost effective security.
This act purpose is to implement policies and procedures to cost effectively reduce
information technology security risks upto acceptable level.
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.