TechKnowSurge
NIST CSF GV.OC-03 ISC2 CISSP 1.4 CompTIA Security+ 5.4 CompTIA SecurityX 1.4 ISC2 CISSP 2.6
VideoSecurityFree

Compliance Factors

Organizations must navigate a complex web of laws, regulations, industry standards, and relationship-driven requirements that govern how they collect, store, and process data. Compliance obligations vary based on geographic location, industry, services offered, customer base, and the types of data handled.

Complete this video to capture a CTF flag worth 1 point.

About this video

Compliance in cybersecurity and IT governance is not a single requirement but a layered set of obligations driven by law, business relationships, industry standards, and internal risk decisions. Governments at every level — municipal, state, federal, and international — establish legally binding rules that organizations must follow or face significant penalties. Beyond government mandates, customers, partners, and vendors frequently impose their own security and data handling requirements as conditions of doing business, and a failure to honor those commitments can escalate into civil litigation. Geography plays a major role in determining which rules apply. A single organization may be legally incorporated in one country, store data in another, serve customers in a third, and rely on service providers in a fourth — each jurisdiction potentially triggering its own set of regulations. Laws such as the U.S. Privacy Act, the EU's GDPR, Brazil's General Data Protection Law, and Australia's Privacy Act of 1988 may all apply simultaneously depending on where data flows. Industry affiliation adds another layer: financial institutions must comply with the Gramm-Leach-Bliley Act, organizations processing payment cards must meet PCI DSS standards, and companies offering services to children are subject to COPPA. Mergers and acquisitions further complicate compliance when two companies operating under different regulatory frameworks must reconcile their obligations. The type of data an organization collects is equally consequential. Health records fall under HIPAA, financial transaction data carries its own regulatory requirements, and categories such as personally identifiable information, educational records, and intellectual property each come with applicable standards and guidelines. Across nearly all of these frameworks, the central concern is the protection of consumer data and the rights of the individuals to whom it belongs, making data governance and compliance deeply interconnected disciplines that any security-conscious organization must address together.

What you'll learn

What's covered

Compliance Factors

Aligned to

NIST CSF
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
ISC2 CISSP
1.4 Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
2.6 Determine data security controls and compliance requirements
CompTIA Security+
5.4 Summarize elements of effective security compliance.
CompTIA SecurityX
1.4 Explain how privacy and data sensitivity impact security and business requirements.

Key terms

General Data Protection Regulation
GDPR
A European Union regulation that establishes comprehensive data protection and privacy rights for individuals within the EU and EEA, and imposes obligations on organizations that process EU residents' personal data regardless of where the organization is located. GDPR introduced concepts such as data minimization, the right to erasure, and mandatory breach notification.
Health Insurance Portability and Accountability Act
HIPAA
A U.S. federal law that establishes national standards for protecting the privacy and security of patients' health information, known as Protected Health Information (PHI). HIPAA's Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards for electronic PHI.
Payment Card Industry Data Security Standard
PCI DSS
A set of security requirements mandated by major credit card brands that organizations must follow to process, store, or transmit cardholder data. PCI DSS covers controls such as encryption, access restriction, and regular security testing.
Gramm-Leach-Bliley Act
GLBA
A U.S. federal law that requires financial institutions to explain how they share and protect customers' private financial information, and to implement security programs to safeguard that data. The GLBA Safeguards Rule mandates specific information security controls for financial institutions.
Children's Online Privacy Act
COPPA
A U.S. federal law that imposes requirements on operators of websites and online services directed at children under 13, restricting the collection and use of personal information from minors. It requires verifiable parental consent before collecting children's data.
Regulatory Compliance
The adherence to laws, government regulations, and industry standards that mandate how an organization must protect data and systems. Failure to meet regulatory requirements can result in fines, legal liability, and reputational damage.
Personally Identifiable Information
PII
Personally Identifiable Information is any data that can be used alone or in combination to identify, contact, or locate an individual, requiring protection under privacy laws and organizational security policies.

Topics

Regulatory Compliance Gdpr Hipaa Pci Dss Data Privacy Compliance Frameworks Cybersecurity Governance

Transcript

One of the questions that a company needs to ask itself is what laws, regulations and standards it needs to comply with. Let's talk about what we have to comply with. What are the standards? What's setting the compelling reason that we have to implement a certain set of standards?

Why we have to comply

One of those reasons is because we're legally bound to it. Out of those, laws and regulations are a big one. So we've got laws and regulatory compliance that we have to comply with, that we have to follow, otherwise it could be really bad for the company. There is a difference between what a law is and what a regulation is, but it's not important for the purpose of this lesson, so we're just going to say it's laws and regulations.

Then we have the customers. The customers don't necessarily — well, they may demand something, but we don't necessarily have to follow it. But we might lose them as a customer. So they may make certain demands on us. One example of this is I was working on a state deal, helping the company land the state deal, and the state required us to implement all of these different security measures. They had this set of standards that we wanted to comply with, and they set it out there, and now we either choose not to do business with them, or we have to go and meet those standards.

Same thing with partners and vendors. Really, we could just categorize these two as relationships. Anytime we establish a relationship, there is a certain understanding that we are going to go through before we do business, as if we have to get on the same page before we do that. We're either going to lose them as a customer, partner or vendor, or we're going to comply with what their demands are.

Then if we say we're going to comply with that and then don't comply with that, now it becomes a legal issue and they can take us to court. So now we have a lawsuit or some sort of legal action, and we have to comply with those legal actions.

One other thing I'll throw in here is that sometimes it just comes internally, that we are mitigating risk, and so we want to comply with a certain set of standards because we chose to comply to that certain set of standards because it's best for the business, it mitigates risk. So there is some internal compliance that we might have, as well as external compliance.

What determines which laws apply

Why we have to follow certain laws and regulations might depend on several different factors:

  • Geographical location: where we're located at, or where the data is being collected from, or where we're storing the data. It could actually be for several different reasons.
  • The different industries that we're in. Certain industries require us to comply with certain laws and certain regulations.
  • The services that we're providing.
  • The customers that we're retaining. Just to retain the customer, we have to comply with it.
  • The data that we're collecting, the type of data that we're collecting.
  • Or it could be just that we're implementing standards based off of risk.

Geographical location

When it comes to geographical locations, there could be some that no matter where you're at in the world you have to comply with. Or perhaps it's if you're in a certain country you have to comply with it. Or maybe it is a grouping of countries, or perhaps it's a certain region, maybe a county, or perhaps it's a city, or perhaps it's a state.

Here are some of the list of the laws and regulations that are out there. We have the US Privacy Act of 1974, or GDPR, or there's the General Data Protection Law over in Brazil, or the Privacy Act of 1988 in Australia. So there are these different laws and regulations out there that we might have to comply to — not only one, but many of these.

Each one of those countries might have a lot of different laws and regulations. For instance, I mentioned the US has the US Privacy Act of 1974, but they have a lot of other federal laws in place that have to deal with privacy and other compliance that we would have to fall under. And within the United States we have 50 different states, and each one of them has their own set of laws, so now we have to comply with a lot of different state level laws.

And I hate to say this, but it's not just where we're doing business at. We have a business that's operating out of a certain country, but perhaps we have data that's being collected from users in another country, and the data is being stored in yet another country, and then we have service providers that we work with that have access to that data.

Let's give a little scenario here. Let's say our business is operating out of Australia over here, we're storing data in the cloud at a cloud provider that's over in the United States, we have clients that are in the European Union, and we also have a service provider that's in maybe Singapore that's offering some services and doing some data processing for us. So now we have to take into consideration all of these different locations and the rules that govern each of those locations. We may have to comply with several different locations based off of where our data is being stored, and our users and where they're from, and where our company is based out of, and that service provider that we're using.

Let's say we work for a company that's looking at opening up a new branch office, and that branch office we want to open up in Brazil. One of the considerations is what are the laws and regulations in Brazil, and are we going to be storing data over there? Is it going to be data from other countries, that maybe users from this will be stored over in this new location? We have to think about all of the pros and cons and all the laws and regulations of opening this branch office in this new location.

Industry

One example of laws and regulations that are driven by industry is the Gramm-Leach-Bliley Act. The Gramm-Leach-Bliley Act really is about financial institutes, so if you're selling financial products, like a bank or some other financial institution, then you have to comply with this Gramm-Leach-Bliley Act.

This also brings up the point of mergers and acquisitions. When we start merging together two different companies, that can be problematic, because now we have to take those security laws and regulations and standards and merge them together for that company. This can be especially difficult if we're talking about two different types of companies. For instance, GE was an energy company that started picking up more financial stuff and trying to merge that into the company, and now that causes some problems with these different laws and regulations, and how are you going to follow everything that you need to follow. So it's going to be a lot of extra work to make sure that you can merge those two together successfully from a compliance standpoint.

Services, customers and data

It could also be based off of those services. An example of this, that's actually not a law or regulation but is something that's set by the credit card industry, is the Payment Card Industry Data Security Standard, or PCI DSS. This one right here requires that if you're processing credit cards, then you're going to need to comply by a certain set of standards.

A good example of a law or regulation that you may have to follow if you're targeting a certain customer is COPPA, the Children's Online Privacy Protection Act. So if you have children that you're targeting as far as your services that you're offering, then you're going to need to comply with COPPA.

A good example of laws and regulations you have to comply with if you're collecting certain data would be HIPAA. HIPAA is the health information portability and accountability act, so if you're collecting health information, then what you're going to have to do is comply with HIPAA.

There are also different data types, so what we have to comply with may have to do with the type of data that we're collecting. Is it personal identifiable information? I already mentioned healthcare records. Or is it financial transactions, or is it educational records, or is it intellectual property? These are some data types that we may have to follow under certain standards and guidelines, based off of what data we're collecting or storing.

Compliance and data management

I'm going to do just a quick call-out here. Notice that a lot of what we're working with really has to do with data. A lot of our laws and regulations are about protecting consumer data and their rights. So really, when it comes to compliance, a lot of it will revolve around how we treat their data and manage their data. There's a big connection between this compliance and also data management. I'm going to get more deep into data management in a whole other module. I'm not going to get deep into it here — I just want to call that out so we understand the correlation.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →