4.1 Business Law and Regulations

Information and cybersecurity are particularly sensitive areas in organizations. We may face many civil and criminal jeopardies, ranging from cyberintrusions to mishandling of information. While most of us are not lawyers, it is quite likely that you have heard the expression that “ignorance of the law is no defense.” Some knowledge of the law is important, particularly in knowing when to involve the corporate attorneys. In this chapter, we will cover some of the main concepts that technology managers and security professionals should know about. We will start with how organizations are typically structured. Why do you suppose knowing how corporations are formed as legal entities might matter to us in the field? ...

Get Information Security Management, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.