TechKnowSurge
VideoSecurityFree

Requirements: Regulation and Compliance

Regulatory compliance is a foundational driver of security design, requiring IT professionals to align their implementations with applicable laws based on industry, geography, and data handling practices. Understanding these obligations is essential for protecting consumer data and meeting organizational security standards.

Complete this video to capture a CTF flag worth 1 point.

About this video

Regulatory compliance is one of the most significant drivers behind security architecture decisions, translating legal obligations into concrete technical and operational requirements. Many small and medium-sized businesses have historically underinvested in security, prioritizing revenue growth and cost reduction over data protection. As breaches increased and consumer data was repeatedly exposed, governments and industry regulators responded by establishing enforceable standards that require organizations to take security seriously regardless of size or budget constraints. For IT and security professionals, this regulatory expansion means compliance can no longer be treated as optional or secondary. Applicable law is not limited to the jurisdiction where a business is physically located — it extends to wherever customers reside and wherever data is stored or processed. An organization based in the United States that serves customers in the European Union, for example, must comply with GDPR in addition to domestic requirements. Beyond geographic considerations, sector-specific regulations introduce additional layers of obligation. Organizations operating in healthcare, financial services, or education must meet the requirements of frameworks and statutes specific to those industries. Security architects and IT professionals are responsible for understanding this full compliance picture and embedding its requirements into every layer of their organization's security posture.

What you'll learn

What's covered

Regulations & Compliance

Key terms

Compliance
The act of adhering to the laws, regulations, standards, and internal policies that govern how an organization handles data and security. Compliance programs use audits and controls to demonstrate that requirements are being met.
General Data Protection Regulation
GDPR
A European Union regulation that establishes comprehensive data protection and privacy rights for individuals within the EU and EEA, and imposes obligations on organizations that process EU residents' personal data regardless of where the organization is located. GDPR introduced concepts such as data minimization, the right to erasure, and mandatory breach notification.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Data Loss Prevention
DLP
A set of tools and processes designed to detect and prevent unauthorized access, use, or transmission of sensitive data.
Security Architecture
SA
The discipline and practice of designing security controls, frameworks, and structures that protect an organization's systems and data from threats. As a workforce practice area, Security Architecture encompasses the strategic design of security systems and the evaluation of security solutions against organizational requirements.

Topics

Regulatory Compliance Security Architecture Data Privacy Compliance Frameworks Cybersecurity Jurisdiction Requirements

Transcript

One of our big drivers for the requirements of anything that we're designing, and security that we're implementing, is the laws and regulations and compliance.

The Business Pressure

Small and medium-sized businesses have a bit of a problem, in that a lot of times they have tight budgets and they're trying to make ends meet to make their company profitable. What are they trying to do? They're trying to increase the revenue, so they have increased revenue. They're trying to decrease costs and expenses so they can increase their profit.

And then we as security professionals come along and tell them all these things that they need to do, all this money that they need to spend in order to increase security. This is problematic for that company. They don't want to do it because it costs a lot of money.

This is problematic because we are the customers that are going to these businesses and utilizing these services, handing over our data, handing over our credit cards, handing over information to them. We are entrusting them with this, and they're not willing to spend money on security. This has been a big problem with certain companies, that they won't spend it, yet they are housing our information and our data. And this becomes problematic.

Why Laws and Regulations Appeared

What's happened is that the amount of attacks has gone up. In response to that, government agencies and different credit card processing companies and different things have been put into place that said to these companies, no, you've got to do something different. You've got to put in laws and regulations.

So that's what's happened. We see more laws and regulations that are out there helping protect the consumer and making sure businesses are putting in the proper time and attention into security to make things happen. So now there's more and more laws and regulations that are being put into place to help protect us as consumers, but us as IT professionals have to now implement that into the organizations that we work for. We need to make sure that they're secure.

Which Regulations Apply to You

There's more and more laws and regulations that we have to comply with, based off of maybe where we're doing business. For instance, I'm in the United States, so then I have to make sure that I'm complying to those laws. If I'm selling to people, for instance, over in the European Union, I have to follow GDPR. So I don't just follow my laws and regulations where I live, but wherever my data is being stored at, wherever my customers are at, I have to follow all of that as well.

There's also sector specific regulations that I have to follow. If I'm in some sort of health care, or maybe I'm in finance, or maybe I'm in education, then there are laws and regulations that I have to follow in accordance to those as well.

So there are different laws and regulations that I need to make sure are incorporated into my security architecture and how I roll things out.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →