🇺🇸 Certified Information Security Manager (CISM) · subject
Certified Information Security Manager (CISM) Legal, Regulatory, and Compliance Management Syllabus
Every chapter and topic of Legal, Regulatory, and Compliance Management examined in Certified Information Security Manager (CISM) — 3 chapters, 9 topics and 18 sub-topics, plus 51 flashcards written against it.
Legal, Regulatory, and Compliance Management syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Legal, Regulatory, and Compliance Management in Certified Information Security Manager (CISM), not a summary of it.
-
Legal and Regulatory Landscape
3 topics- U.S. Federal and State Requirements
- HIPAA, GLBA, and SOX security obligations
- State breach notification and privacy laws (e.g., CCPA/CPRA)
- Industry and Sector Regulations
- PCI DSS and payment card requirements
- FedRAMP and government cloud requirements
- Cross-Border and Privacy Considerations
- GDPR applicability to U.S. organizations
- Data residency and transfer mechanisms
- U.S. Federal and State Requirements
-
Compliance Frameworks and Standards
3 topics- Control Frameworks
- NIST SP 800-53 control families
- ISO/IEC 27001 Annex A controls
- Attestation and Certification
- SOC 2 and trust services criteria
- Certification scope and maintenance
- Mapping and Harmonizing Requirements
- Crosswalking overlapping frameworks
- Reducing redundant control efforts
- Control Frameworks
-
Compliance Operations and Ethics
3 topics- Compliance Monitoring and Auditing
- Evidence management and control testing
- Managing audit findings and remediation
- Contracts, SLAs, and Third Parties
- Security clauses in vendor contracts
- Right-to-audit and assurance reports
- Professional Ethics and Conduct
- ISACA Code of Professional Ethics
- Whistleblowing and ethical escalation
- Compliance Monitoring and Auditing
Legal, Regulatory, and Compliance Management flashcards for Certified Information Security Manager (CISM)
23 of 51 cards from the Legal, Regulatory, and Compliance Management deck — real questions with worked answers.
What is the difference between a law, a regulation, and a standard in compliance terms?
A law is legislation passed by a legislative body (mandatory); a regulation is a rule issued by a government agency to implement a law (mandatory); a standard is a documented set of requirements (e.g., ISO 27001) that may be voluntary or made mandatory by contract or regulation.
Which U.S. federal law governs the protection of electronic protected health information (ePHI) and what is its Security Rule about?
HIPAA (Health Insurance Portability and Accountability Act). The HIPAA Security Rule mandates administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI.
What does the Gramm-Leach-Bliley Act (GLBA) require of financial institutions?
GLBA requires financial institutions to protect the security and confidentiality of customer nonpublic personal information through a written information security program, including the Safeguards Rule and Privacy Rule, and to provide privacy notices.
What is the Sarbanes-Oxley Act (SOX) and which sections matter most to information security?
SOX is a U.S. law on corporate financial reporting integrity. Section 302 requires executive certification of financial reports, and Section 404 requires management and auditors to assess internal controls over financial reporting (ICFR), which depend on IT general controls.
What does FISMA require of U.S. federal agencies?
The Federal Information Security Modernization Act (FISMA) requires federal agencies to implement risk-based information security programs and to follow NIST standards (FIPS 199/200, NIST SP 800-53) to protect federal information and systems.
What is the California Consumer Privacy Act (CCPA), as amended by the CPRA, designed to protect?
CCPA/CPRA grants California residents rights over their personal information, including the rights to know, delete, correct, opt out of sale/sharing, and limit use of sensitive personal information, and imposes obligations on covered businesses.
What is a U.S. state data breach notification law's core requirement?
It requires organizations to notify affected individuals (and often regulators) when personal information is compromised. All 50 states have such laws, with varying timelines, definitions of personal information, and harm thresholds.
What does PCI DSS govern, and is it a law?
PCI DSS (Payment Card Industry Data Security Standard) is a contractual industry standard, not a law, that governs the protection of cardholder data for any entity that stores, processes, or transmits payment card information.
What is NERC CIP and which sector does it regulate?
NERC CIP (Critical Infrastructure Protection) standards regulate the cybersecurity of the bulk electric power system in North America, mandating controls for critical cyber assets in the energy/utility sector.
What does FERPA protect?
FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records and gives parents/eligible students rights to access and control disclosure of those records.
What is the EU General Data Protection Regulation (GDPR) and its territorial scope?
GDPR is the EU's comprehensive data protection regulation. It applies extraterritorially to any organization that processes the personal data of EU data subjects when offering goods/services to them or monitoring their behavior, regardless of the organization's location.
What are the maximum administrative fines under GDPR?
Up to the greater of EUR 20 million or 4% of total worldwide annual turnover for the most serious violations; up to EUR 10 million or 2% for lesser violations.
Under GDPR, what is the breach notification timeline to the supervisory authority?
A controller must notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach.
What is the difference between a data controller and a data processor under GDPR?
A controller determines the purposes and means of processing personal data; a processor processes personal data on behalf of the controller. Controllers bear primary accountability; processors must act only on documented instructions.
What legal mechanisms allow cross-border transfers of EU personal data to countries without adequacy?
Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), approved codes of conduct/certifications, and specific derogations (e.g., explicit consent). An adequacy decision removes the need for these.
What is data localization (data residency)?
A legal requirement that certain data be stored and/or processed within a specific country's geographic borders, often imposed for privacy, sovereignty, or national security reasons.
What is the purpose of a Data Protection Impact Assessment (DPIA) under GDPR?
A DPIA assesses the privacy risks of processing that is likely to result in high risk to individuals' rights, identifying and mitigating those risks before processing begins.
What is Privacy by Design and Privacy by Default?
Privacy by Design embeds privacy protections into systems and processes from the outset; Privacy by Default ensures the most privacy-protective settings apply automatically without user action. Both are GDPR requirements.
What distinguishes a control framework from a control?
A control is a specific safeguard or countermeasure (e.g., MFA); a control framework is a structured, comprehensive catalog of controls and guidance (e.g., NIST SP 800-53, ISO 27001) organized to manage risk systematically.
What is the ISO/IEC 27001 standard and what can be certified against it?
ISO/IEC 27001 specifies the requirements for an Information Security Management System (ISMS). Organizations can obtain accredited certification of their ISMS against it; Annex A lists reference controls (detailed in ISO 27002).
What does the NIST Cybersecurity Framework (CSF) provide and what are its core functions?
The NIST CSF provides a voluntary, risk-based framework of outcomes. CSF 2.0 core functions are: Govern, Identify, Protect, Detect, Respond, and Recover.
What is NIST SP 800-53 used for?
NIST SP 800-53 is a catalog of security and privacy controls for federal information systems and organizations, used to implement FISMA and to support the Risk Management Framework (RMF).
What is COBIT and what is it primarily used for?
COBIT (Control Objectives for Information and Related Technologies), from ISACA, is a framework for the governance and management of enterprise IT, aligning IT goals with business objectives and supporting control assurance.
See more Legal, Regulatory, and Compliance Management flashcards →
Planning Legal, Regulatory, and Compliance Management for Certified Information Security Manager (CISM)
Legal, Regulatory, and Compliance Management is about 13% of the Certified Information Security Manager (CISM) syllabus by topic count — 9 of 68 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 10 hours.
The heaviest chapters are Legal and Regulatory Landscape (3 topics), Compliance Frameworks and Standards (3 topics), Compliance Operations and Ethics (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Legal, Regulatory, and Compliance Management (Certified Information Security Manager (CISM)) FAQ
What is in the Certified Information Security Manager (CISM) Legal, Regulatory, and Compliance Management syllabus?
Legal, Regulatory, and Compliance Management is split into 3 chapters — Legal and Regulatory Landscape, Compliance Frameworks and Standards and Compliance Operations and Ethics, containing 9 topics and 18 sub-topics in total.
How many chapters are there in Legal, Regulatory, and Compliance Management for Certified Information Security Manager (CISM)?
3 chapters. Legal, Regulatory, and Compliance Management accounts for about 13% of the topics in the whole Certified Information Security Manager (CISM) syllabus (9 of 68).
How long should I spend on Legal, Regulatory, and Compliance Management for Certified Information Security Manager (CISM)?
Budget around 10 hours for a first pass through Legal, Regulatory, and Compliance Management — about 45 minutes per topic plus 12 minutes per sub-topic across its 9 topics. Add revision cycles on top.
Are there flashcards for Certified Information Security Manager (CISM) Legal, Regulatory, and Compliance Management?
Yes — a 51-card Legal, Regulatory, and Compliance Management deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.