TechKnowSurge
CompTIA Security+ 5.4 ISC2 CISSP 1.4 NIST CSF GV.OC-03 ISC2 CISSP 2.6 CompTIA Security+ 5.5 CompTIA Security+ 5.3
InteractiveSecurityFree

Regulation Matcher

Match seven compliance scenarios to the regime that governs each, and separate the ones imposed by law from the one imposed by a contract and the one a customer simply asks for.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Seven scenarios, seven compliance regimes, one pairing each. The recall half is straightforward once you know what each acronym covers. The half worth carrying out of the activity is why any of them applied in the first place, because nothing about compliance is chosen — it is triggered, and the trigger is different every time. Four of these seven are laws. HIPAA reaches the hospital because of the industry it is in and the kind of data it holds: protected health information, guarded by a Security Rule that names administrative, physical and technical safeguards and attaches a breach-notification duty to failure. GLBA reaches the bank the same way, through its industry, and asks two separate things of it — an honest explanation to customers of how their private financial information is shared and protected, and a safeguards program that actually protects it. GDPR reaches the company selling European customer data even though the company sits outside Europe, and that is precisely the point of it: scope follows the data subject, not the head office. COPPA reaches the children's game through the age of its users, drawing a hard line at thirteen and requiring verifiable parental consent before any personal information is collected. CMMC is the odd one among the mandatory four, because it arrives through a contract rather than a statute — a Department of Defense supplier holding controlled unclassified information has to pass a third-party assessment at the required maturity tier before an award, which makes the customer, in this case, a government. PCI DSS is not a law at all. No legislature passed it; the card brands wrote it and enforce it as a condition of being allowed to process payments, which in practice makes it every bit as binding as one for a retailer who wants to stay in business. Its requirement to encrypt stored cardholder data is the one the plain-text order database breaks. And SOC 2 is not mandatory in any sense — the cloud vendor engages a CPA firm and pays for an attestation because a prospective enterprise customer asked for evidence that its controls work. A Type 1 report says the controls are in place; a Type 2 says they were actually followed over a period. Sorted by what compels them, the set reads: four regulations imposed by law, one imposed by contract, one imposed by an industry body, one requested by a customer. That is the shape of a real compliance landscape, and it is why an organization's obligations have to be worked out from its own facts — its location, its industry, its data, its customers — rather than looked up on a list.

What you'll learn

Aligned to

CompTIA Security+
5.4 Summarize elements of effective security compliance.
5.5 Explain types and purposes of audits and assessments.
5.3 Explain the processes associated with third-party risk assessment and management.
ISC2 CISSP
1.4 Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
2.6 Determine data security controls and compliance requirements
NIST CSF
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.

Key terms

Health Insurance Portability and Accountability Act
HIPAA
A U.S. federal law that establishes national standards for protecting the privacy and security of patients' health information, known as Protected Health Information (PHI). HIPAA's Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards for electronic PHI.
Payment Card Industry Data Security Standard
PCI DSS
A set of security requirements mandated by major credit card brands that organizations must follow to process, store, or transmit cardholder data. PCI DSS covers controls such as encryption, access restriction, and regular security testing.
General Data Protection Regulation
GDPR
A European Union regulation that establishes comprehensive data protection and privacy rights for individuals within the EU and EEA, and imposes obligations on organizations that process EU residents' personal data regardless of where the organization is located. GDPR introduced concepts such as data minimization, the right to erasure, and mandatory breach notification.
Cybersecurity Maturity Model Certification
CMMC
A U.S. Department of Defense program that establishes cybersecurity standards and a certification process for defense contractors to ensure they adequately protect sensitive unclassified information. It uses a tiered model requiring third-party assessments to verify compliance before award of DoD contracts.
Gramm-Leach-Bliley Act
GLBA
A U.S. federal law that requires financial institutions to explain how they share and protect customers' private financial information, and to implement security programs to safeguard that data. The GLBA Safeguards Rule mandates specific information security controls for financial institutions.
Children's Online Privacy Act
COPPA
A U.S. federal law that imposes requirements on operators of websites and online services directed at children under 13, restricting the collection and use of personal information from minors. It requires verifiable parental consent before collecting children's data.
System and Organization Controls 2
SOC 2
An auditing standard developed by the American Institute of Certified Public Accountants (AICPA) that evaluates the security, availability, processing integrity, confidentiality, and privacy controls of service organizations. SOC 2 reports are widely used by cloud service providers to demonstrate the effectiveness of their security controls to customers.
Regulation
A legally binding rule or requirement issued by a governing authority that organizations must follow.
Standard
A mandatory, specific requirement derived from a policy that defines how the policy is to be implemented.
Compliance
The act of adhering to the laws, regulations, standards, and internal policies that govern how an organization handles data and security. Compliance programs use audits and controls to demonstrate that requirements are being met.
Regulatory Compliance
The adherence to laws, government regulations, and industry standards that mandate how an organization must protect data and systems. Failure to meet regulatory requirements can result in fines, legal liability, and reputational damage.
Attestation
The process of providing evidence or formal certification that a set of standards is being followed, either through self-reported documentation or third-party verification.
Protected Health Information
PHI
Protected Health Information is individually identifiable health data covered under HIPAA that requires specific administrative, physical, and technical safeguards to protect its confidentiality, integrity, and availability.
Personally Identifiable Information
PII
Personally Identifiable Information is any data that can be used alone or in combination to identify, contact, or locate an individual, requiring protection under privacy laws and organizational security policies.
Non-Compliance
The failure of an organization to adhere to applicable regulatory standards, laws, or contractual requirements.

Topics

Interactive Matching

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →