Chapter 10. Legal and Regulatory Considerations
Topics covered in this chapter include:
-
Data privacy regulations
-
Service Level Agreements (SLAs)
-
Vendor management
-
Legal compliance
-
Digital investigations
In the last chapter, we discussed compliance. This is where we need to make sure the business is in compliance with regulations and frameworks to demonstrate that it has a functional security program. Compliance may be legal or regulatory, but that doesn’t mean that all legal and regulatory issues are related to compliance. There are many laws that apply to businesses and other organizations, including privacy considerations, for a start. The more the world moves to networks being online, the more information is stored with businesses. This includes all manner of personal data, as well as business data. Many regions and countries are introducing their own data privacy laws. This brings up significant jurisdictional issues, which need to be factored into business decisions and information security controls.
Contractual issues also need to be factored in. This relates not only to the contracts you have with your cloud service providers, but also to any contracts you have with your customers. Security clauses are becoming more essential, especially with more guidance, frameworks, and regulations related to how information security programs are managed. This creates an interesting intersection between lawyers and security practitioners, where they need to work together. ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access