Organizations operate under a web of legal and contractual obligations: privacy and data protection laws, financial reporting rules, sector regulations for health care, banking or critical infrastructure, breach notification laws, export controls, e-discovery and records retention rules, and industry standards such as the Payment Card Industry Data Security Standard (PCI DSS). An IS auditor must understand which of these apply, because they become the criteria against which controls are judged, and non-compliance can bring fines, lawsuits, loss of licenses or loss of the right to process card payments.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.