Every organization operates under external obligations. Laws and regulations, such as data protection laws, sector rules for health or finance, and breach notification requirements, set minimum expectations and carry penalties. Contracts with customers, partners and card brands add more, for example the Payment Card Industry Data Security Standard (PCI DSS) for anyone who stores, processes or transmits payment card data. The information security manager must know which obligations apply and make sure the program addresses them, working closely with legal counsel and compliance rather than interpreting the law alone.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.