TechKnowSurge
NIST CSF GV.OC-03 ISC2 CC 1.3 NIST 800-53 PM-1 Cisco CCST Cybersecurity 5.3 NIST NICE K0678 NIST 800-53 PT-2 CompTIA Cloud+ 4.2
VideoSecurityFree

Administrative Controls - Laws and Regulations

Privacy laws and regulations like GDPR, HIPAA, and COPPA require organizations to protect customer and employee data, and non-compliance can result in significant fines and reputational damage. A well-structured security program treats regulatory compliance as a core component of risk management and business continuity.

Complete this video to capture a CTF flag worth 1 point.

About this video

Privacy is a foundational concept behind many of today's cybersecurity laws and regulations. When individuals share personal, financial, or medical information with a company, they are trusting that organization to act as a responsible steward of that data. Organizations that fail to protect this information expose individuals to serious harm and themselves to significant legal and financial consequences. Because many businesses tend to deprioritize security spending in favor of revenue generation, governments and regulatory bodies have enacted binding laws with substantial penalties to compel compliance. The regulatory landscape spans multiple jurisdictions and sectors. At the international level, GDPR protects the personal data of European residents and carries some of the steepest fines in the industry. In the United States, federal laws such as the Privacy Act of 1974 establish baseline requirements, while sector-specific regulations like HIPAA for health records, COPPA for data involving children under 13, and FERPA for educational records create additional layers of obligation. State-level laws add further complexity, and industry standards like PCI DSS govern organizations that process payment card data even when no specific statute applies. For security professionals, regulatory compliance provides a powerful business case when communicating with executive leadership and finance teams. Framing compliance as a mechanism for reducing financial risk, avoiding fines, and protecting company reputation bridges the gap between technical priorities and business objectives. Managing compliance across all applicable federal, state, and sector-specific requirements is a significant undertaking in its own right and must be treated as a structured, ongoing component of any comprehensive security program.

What you'll learn

What's covered

Laws & Regulations Compliance

Aligned to

NIST CSF
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
ISC2 CC
1.3 Understand governance concepts
NIST 800-53
PM-1 Information Security Program Plan
PT-2 Authority to Process Personally Identifiable Information
Cisco CCST Cybersecurity
5.3 Explain the impact of compliance frameworks on incident handling
NIST NICE
K0678 Knowledge of privacy laws and regulations
CompTIA Cloud+
4.2 Given a scenario, apply cloud compliance and governance.

Key terms

Privacy
The right of individuals to be free from unauthorized observation or disturbance, including the protection of personal data held by organizations.
Compliance
The act of adhering to the laws, regulations, standards, and internal policies that govern how an organization handles data and security. Compliance programs use audits and controls to demonstrate that requirements are being met.
General Data Protection Regulation
GDPR
A European Union regulation that establishes comprehensive data protection and privacy rights for individuals within the EU and EEA, and imposes obligations on organizations that process EU residents' personal data regardless of where the organization is located. GDPR introduced concepts such as data minimization, the right to erasure, and mandatory breach notification.
Health Insurance Portability and Accountability Act
HIPAA
A U.S. federal law that establishes national standards for protecting the privacy and security of patients' health information, known as Protected Health Information (PHI). HIPAA's Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards for electronic PHI.
Children's Online Privacy Act
COPPA
A U.S. federal law that imposes requirements on operators of websites and online services directed at children under 13, restricting the collection and use of personal information from minors. It requires verifiable parental consent before collecting children's data.
Family Educational Rights and Privacy Act
FERPA
A U.S. federal law that protects the privacy of student education records and gives parents and eligible students the right to access, review, and request corrections to those records. Schools that receive federal funding must comply with FERPA's privacy protections.
Payment Card Industry Data Security Standard
PCI DSS
A set of security requirements mandated by major credit card brands that organizations must follow to process, store, or transmit cardholder data. PCI DSS covers controls such as encryption, access restriction, and regular security testing.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.

Topics

Regulatory Compliance Privacy Law Gdpr Hipaa Administrative Controls Risk Management Cybersecurity

Transcript

Privacy and Why It Matters

One of the important parts of a security program is that we're going to be implementing things that help us comply with laws and regulations. Then we can avoid fees, we can avoid fines, we can avoid different issues in the future by complying with these laws and regulations.

A lot of laws and regulations have to do with privacy. Do all of them? No. But a lot of them do. So what is privacy? That's being free from being observed and/or disturbed. Essentially you have rights. You are a consumer. You buy products out there, you buy services out there. There are things that get shipped to your door. There are things that you subscribe to online. There are software as a service companies. There are people collecting data about you all the time.

Now, do you want them to abuse that data? Do you want them to lose that credit card information? Do you want them to have a confidentiality breach and other people see your medical records or your financial records, or be able to get into your bank account? No. The simple answer is that we are trusting other people to do the right thing to protect our data.

Well, for the organizations that we work for, we are holding other people's data. Maybe it's employees' data. Maybe it is data from users who are using our systems. Maybe it's partnerships' employees. In any case, we have some sort of data that will most likely fall under this privacy umbrella, and we need to protect that data. We are stewards of that data. We need to be able to control that data properly and make sure that we're handling it correctly. One of the ways we do this is we have policies and procedures, and we do the training, and we do compliance, and make sure that everybody is following through with what we want them to do.

Why Businesses Deprioritize It

Ultimately all of this does cost money. And because of that, a lot of times it gets deprioritized by maybe accounting or finance, maybe it's the CEOs, maybe it's the exec teams, maybe it's the board of directors. Often they're looking at the bottom line: are we making a profit? And as you come to them with projects of, hey, we want to create these policies and procedures, they ask, well, is that really what we should be doing? Is that really what we should be investing our money into?

The thing is that businesses are looking at revenue and expenses, and really they want to generate a profit. A business is there for generating profit. Now there are different entities out there, like organizations that are not-for-profit, where this isn't their bottom line. But for a big part of the businesses that are out there, for the most part what they're designed to do is create profit. And the only way that they can create profit is by reducing expenses or increasing revenue.

So really the goal of our security program should do exactly that. If you render it down, that's really what it gets to. But us as technical people, us as security professionals, we're not always thinking of that. We're thinking of the end customer. So we're speaking two different languages from the business, from the people who are in control of the business. Often — I'm not saying always, but often — we're speaking two different languages: the IT people are thinking what is the right thing and the best thing to do, and many times the business is thinking, well, we need to be profitable. And they should be thinking we need to be profitable. So we just need to keep that in mind when we're talking about this.

Why Laws and Regulations Are Necessary

But this is all to say that a lot of businesses don't put the proper security measures in place to protect their employees' data, to protect their employees' privacy, to protect the customer data and privacy. So what needs to happen there? We need laws and regulations that say no, you as a business are going to protect the privacy of your customers and of your employees, and you have to put this stuff in place. So laws and regulations are necessary, because a lot of businesses won't take the proper steps to protect their customer data, to protect privacy, unless they're forced to by the law and have some stiff penalties.

Here are some of the laws that are out there — these are different laws and regulations from different parts of the country. The US has the US Privacy Act of 1974, and GDPR is another one that's out there that protects the citizens of Europe. And there are some crazy fines with GDPR if you're not doing the right thing.

So us as a business, that's where we start talking to the business and say, well, yes, our goal as a company, as a security program, is that we will either increase revenue or decrease expenses, and this comes in the form of risk. I'm not going to get into all of how this mathematically plays out, but that's essentially what a security program is doing. One of the things is that we need to limit our risk by complying with laws and regulations.

Now we've got this strong argument that we can come and say, no, a security program is necessary, security awareness training is necessary, we need to have these things put into place to make sure that we're complying with the laws and regulations, and that we're going to stay in business here 5 years from now because we are doing the right things and we're not damaging our reputation and we're not racking up fines and that type of thing. So it's important that we comply with these laws and regulations. It's important that these laws and regulations are out there. There are a lot of different types of laws and regulations, but it's important that we have these to make sure that we're following the right thing and that we're doing the right thing.

Global, Federal, State, and Sector Specific

This is an example of some of those laws and regulations that happen at a global scale, depending on the country or the area that you live in, or the area that your clients are in. These are some of the ones that we might have to apply to.

These are some of the United States laws and regulations. You can see that there are quite a few here that we may need to be concerned with and may need to comply with.

Here are some state specific laws. The point here is that you have the federal laws, but you also have state specific laws, and so there might be many of these that we have to fall under.

There's also sector specific. If we have data from children under 13 in the United States, we've got to comply with COPPA. If there are health records, then we've got to comply with HIPAA. If there's educational records, we've got to comply with FERPA. And there are different — the financial institute has ones where we're processing data. Those aren't necessarily laws and regulations, but they are compliance that we have to do with the credit card companies in order to have the ability to process credit cards. So there are a lot of different sector specific regulations that we might have to fall under to make sure that we comply with what's expected of us as a company.

There's a whole management behind this as well, because there is so much federal, state, province, and sector specific regulation and law that we have to comply with that it becomes kind of something we have to manage in itself. This compliance that we have to manage is a component of our security program, and making sure that we have the right things in place as we move forward.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →