Legislators and regulators around the world take an interest in cybersecurity due to the potential impact of cybersecurity shortcomings on individuals, government, and society. Whereas the European Union (EU) has a broad-ranging data protection regulation, cybersecurity analysts in the United States are forced to deal with a patchwork of security regulations covering different industries and information categories.
### Common Compliance Requirements
Some of the major information security regulations facing organisations include the following:
- *The Health Insurance Portability and Accountability Act* (**HIPAA**) includes security and privacy rules that affect health-care providers, health insurers, and health information clearinghouses in the United States.
- *The Payment Card Industry Data Security Standard* (**PCI DSS)** provides detailed rules about the storage, processing, and transmission of credit and debit card information. PCI DSS is not a law but rather a contractual obligation that applies to credit card merchants and service providers worldwide.
- *The Gramm–Leach–Bliley Act* (**GLBA**) covers U.S. financial institutions, broadly defined. It requires that those institutions have a formal security program and designate an individual as having overall responsibility for that program.
- *The Sarbanes–Oxley* (**SOX**) Act applies to the financial records of U.S. publicly traded companies and requires that those companies have a strong degree of assurance for the IT systems that store and process those records.
- *The General Data Protection Regulation* (**GDPR**) implements security and privacy requirements for the personal information of European Union residents worldwide.
- *The Family Educational Rights and Privacy Act* (**FERPA**) requires that U.S. educational institutions implement security and privacy controls for student educational records.
- Various data breach notification laws describe the requirements that individual states place on organisations that suffer data breaches regarding notification of individuals affected by the breach.
### Compliance Reporting
Organisations need to engage in both *internal and external compliance reporting* to **ensure that they meet the regulatory requirements** and maintain transparency within the organisation and with external stakeholders.
**Internal compliance** reporting is a vital component in maintaining an organisation's security posture and ensuring adherence to various laws and regulations. Internal reporting typically involves *regular reports to the management or the board, highlighting the state of compliance, identifying gaps, and providing recommendations for improvement*. These reports are essential for decision-makers within the organisation to understand the compliance landscape, allocate resources effectively, and ensure that compliance objectives align with the organisation's strategic goals.
**External compliance** reporting, on the other hand, is mandated by regulatory bodies or as a part of contractual obligations. It involves *providing necessary documentation and evidence to external entities to demonstrate that the organisation is in compliance with relevant laws and regulations*. For instance, organisations handling credit card data might need to submit compliance reports to the Payment Card Industry Security Standards Council (PCI SSC), and those under GDPR must be ready to provide compliance evidence to data protection authorities. External compliance reporting is crucial for maintaining good standing with regulatory authorities, avoiding penalties, and building trust with customers and partners by demonstrating a commitment to security and privacy.
### Consequences of Noncompliance
One of the most immediate impacts of noncompliance is the *imposition of fines and sanctions*. Regulatory bodies have the authority to levy significant fines on organisations that fail to comply with the required standards. For instance, under the **GDPR**, companies can be fined up to 4 *percent of their annual global turnover, or €20 million*, whichever is higher, for serious infringements.
Additionally, noncompliance can lead to *non-financial sanctions*, which may include restrictions on business operations. In some cases, regulatory authorities might **suspend or revoke licenses** that are critical to the organisation's operations. For example, a financial institution that fails to comply with anti-money-laundering regulations could lose its banking license, which is essential for its core business activities.
**Reputational damage** is another critical consequence of noncompliance. When news of noncompliance, especially involving data breaches or privacy violations, becomes public, it can severely tarnish the image of the organisation. Customers and partners may lose trust in the organisation's ability to safeguard their information and might choose to take their business elsewhere.
**Loss of business and contractual impacts** are also significant consequences. Noncompliance can lead to the *termination of contracts*, especially when compliance with specific standards is a prerequisite for engaging in business relationships. This can result in lost revenue and additional costs associated with finding and establishing relationships with new partners.
In some cases, noncompliance can also lead to **legal action**. Individuals or entities affected by an organisation's noncompliance may *sue for damages*. This not only leads to potential monetary losses but also consumes time and resources, as the organisation has to deal with legal proceedings.
### Compliance Monitoring
Effective compliance monitoring is a cornerstone in ensuring that organisations adhere to the various laws, regulations, and contractual obligations. An essential aspect of this monitoring involves **due diligence**, which is the process of *continuously researching and understanding the legal and regulatory requirements that pertain to the organisation*. It is crucial to stay abreast of evolving laws and ensure that the organisation has the necessary policies and controls in place.
**Due care**, a complementary concept, refers to the ongoing efforts to *ensure that the implemented policies and controls are effective and continuously maintained*. This means regularly reviewing and updating policies and taking proactive steps to ensure compliance. Part of due care involves *attestation and acknowledgment*.
**Acknowledgment** means ensuring that *employees and business partners state that they are aware* of the compliance requirements. **Attestation** means that they are aware of these requirements but *have also confirmed that their practices adhere to these policies*.
Internal and external monitoring mechanisms play a pivotal role in compliance monitoring. Internal monitoring includes internal audits, reviews, and checks to ensure that the organisation follows its policies and meeting legal requirements. External monitoring, on the other hand, involves third-party audits and assessments, which provide an unbiased view of the organisation's compliance status.