StudyToCert

All certifications / CC / Lessons

ISC2 Certified in Cybersecurity 2026 outline · Domain 2: Security governance

Laws, regulations and contractual requirements (e.g. GDPR, HIPAA, PCI DSS)

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Organizations do not choose all of their security requirements. Many come from outside, and failing to meet them can bring fines, lawsuits, lost contracts or even criminal charges. The CC exam does not expect you to be a lawyer, but you should understand the kinds of requirements that exist and recognize a few well-known examples.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CC for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CC study plan