Skip to main content

Command Palette

Search for a command to run...

CISSP Laws & Regulations — Practical Domain 1.4 Guide

Updated
•22 min read•View as Markdown
S
I like breaking things that are supposed to be secure. When I’m not hunting vulnerabilities, I’m exploring systems, architectures, and the assumptions behind them.

A Practical, Exam-Focused Guide to Laws, Regulations, Intellectual Property & Compliance

The CISSP (Certified Information Systems Security Professional) exam does not expect you to become a lawyer.

However, a security professional must understand how laws, regulations, contracts, industry standards, privacy requirements, and intellectual-property rights affect information security.

The important skill is scenario recognition.

When you see a CISSP question, ask:

What is being protected?

Then:

What legal, regulatory, contractual, or compliance requirement applies?

This guide focuses on the concepts useful for CISSP Domain 1 — Security and Risk Management, particularly the legal, regulatory, and compliance topics in Domain 1.4.


1. The CISSP Legal & Regulatory Mental Model

                    CISSP LEGAL & REGULATORY
                              │
       ┌──────────────────────┼──────────────────────┐
       │                      │                      │
 Intellectual Property     Privacy                Cybercrime
       │                      │                      │
 Copyright                GDPR                   CFAA
 DMCA                     CCPA/CPRA              ITADA
 Patent                   HIPAA                  ECPA
 Trademark                FERPA
 Trade Secret             COPPA
 Licensing
       │                      │                      │
       └──────────────────────┼──────────────────────┘
                              │
              ┌───────────────┼────────────────┐
              │               │                │
       Cross-Border        Contracts        Industry /
          Issues                           Regulatory
              │               │                │
      Transborder Data    Security         PCI DSS
      Flow                obligations
      Import/Export       Liability
      Controls

The goal is not to memorize hundreds of laws.

The goal is to recognize:

Information
    ↓
Security / Legal Issue
    ↓
Applicable Requirement
    ↓
Security / Compliance Action

2. Intellectual Property

What is Intellectual Property?

Intellectual Property (IP) refers to creations of the human mind that can receive legal protection.

For CISSP, know these major categories:

Copyright    → Creative work
Patent       → Invention
Trademark    → Brand
Trade Secret → Confidential business information

3. Copyright

Copyright protects original creative works.

Examples:

  • Software source code

  • Documentation

  • Books

  • Music

  • Videos

  • Images

Practical Security Example

A company develops a proprietary application.

An employee copies the company's source code and publishes it online without authorization.

The organization may have copyright and intellectual-property concerns.

CISSP Perspective

When the question says:

"Original work"

Think:

Copyright

Memory Point

Copyright = CREATE


4. DMCA — Digital Millennium Copyright Act

Full Form

DMCA = Digital Millennium Copyright Act

DMCA is a U.S. law dealing with copyright protection in the digital environment.

For CISSP, the most important concept is:

Digital copyrighted content + technological protection measures


What is DRM?

DRM = Digital Rights Management

DRM refers to technologies used to control access to or use of digital content.

Examples:

  • Streaming-video copy protection

  • E-book restrictions

  • Software activation

  • Digital music protection

  • Encryption-based content controls

Simple Example

Streaming Service
       ↓
Encrypted Movie
       ↓
DRM Protection
       ↓
Authorized User

DRM may help prevent:

  • Unauthorized copying

  • Unauthorized playback

  • Redistribution

  • Circumvention


DMCA + DRM Example

A streaming company uses DRM to prevent unauthorized copying of copyrighted movies.

An attacker develops a tool specifically designed to bypass the DRM and then distributes the protected content.

The situation raises:

DMCA / digital copyright concerns

For CISSP, understand the relationship:

DMCA can address circumvention of technological measures protecting copyrighted digital material.


When is DMCA relevant?

Think about DMCA when a scenario involves:

  • Digital copyrighted material

  • Unauthorized copying

  • Copyright protection technology

  • Circumvention of technological protection

  • DRM

  • Digital content distribution

Memory Point

DMCA = DIGITAL COPYRIGHT

And:

DRM = TECHNOLOGY USED TO CONTROL ACCESS/USE OF DIGITAL CONTENT

CISSP Exam Trap

Don't think:

❌ DMCA = cybersecurity law

Think:

✅ DMCA = copyright law with important digital-security implications


5. Patent

A patent provides legal protection for qualifying inventions.

Examples:

  • New encryption mechanism

  • Novel hardware technology

  • New technical process

Practical Example

A company invents a new hardware-based security mechanism and seeks legal protection for the invention.

CISSP Memory Point

Patent = INVENT


6. Trademark

A trademark protects brand identifiers.

Examples:

  • Company name

  • Logo

  • Brand name

  • Symbol

  • Certain slogans

Practical Example

An attacker creates a fake website using a company's logo and brand name to deceive customers.

This can involve:

  • Trademark issues

  • Brand abuse

  • Phishing

  • Fraud

CISSP Memory Point

Trademark = BRAND


7. Trade Secret

A trade secret is valuable business information that derives value from being kept secret.

Examples:

  • Proprietary algorithms

  • Source code

  • Secret formulas

  • Customer lists

  • Manufacturing processes

  • Business strategies

Practical Security Example

A company has a proprietary AI algorithm.

Instead of publishing it or seeking patent protection, it:

  • Restricts access

  • Uses NDAs

  • Encrypts the source code

  • Monitors access

  • Uses DLP

  • Applies least privilege

This supports maintaining the information as a trade secret.

CISSP Insight

Security controls can help maintain trade-secret protection.

Trade Secret
     ↓
Must remain confidential
     ↓
Security Controls
     ↓
Access Control
Encryption
DLP
Least Privilege
Monitoring
NDA

Memory Point

Trade Secret = KEEP SECRET


8. Intellectual Property — Ultimate Map

Copyright    → CREATE
Patent       → INVENT
Trademark    → BRAND
Trade Secret → KEEP SECRET
DMCA         → DIGITAL COPYRIGHT

9. Software Licensing

A software license defines how software may legally be:

  • Used

  • Copied

  • Modified

  • Distributed

Examples:

  • Commercial licenses

  • Proprietary licenses

  • Open-source licenses

  • Subscription licenses

Practical Example

A developer downloads a commercial security library and integrates it into a product.

Before doing so, the organization should verify:

  • Is commercial use permitted?

  • Can it be modified?

  • Can it be redistributed?

  • Are attribution requirements applicable?

  • Are there license restrictions?

CISSP Perspective

This can become:

Legal + contractual + intellectual-property compliance

Memory Point

License = PERMISSION TO USE


10. Privacy

Privacy is a major CISSP concept.

Think about:

  • Personal data

  • Personally identifiable information

  • Collection

  • Processing

  • Storage

  • Sharing

  • Retention

  • Deletion

  • Data subject rights

  • Breach notification


11. GDPR

Full Form

GDPR = General Data Protection Regulation

GDPR is the European Union's major data-protection regulation.

For CISSP, understand:

  • Personal data

  • Data protection

  • Data minimization

  • Purpose limitation

  • Accountability

  • Data subject rights

  • Controllers

  • Processors

  • Breach obligations

Practical Example

A company collects:

Name
Email
IP Address
Location
Customer ID

The organization needs to consider:

  • Why is the data being collected?

  • Is the collection necessary?

  • How is it protected?

  • Who can access it?

  • How long is it retained?

  • What rights do individuals have?

  • What happens if it is breached?

CISSP Memory Point

GDPR = PERSONAL DATA


12. CCPA / CPRA

Full Forms

CCPA = California Consumer Privacy Act

CPRA = California Privacy Rights Act

For CISSP, think:

Consumer privacy

Practical Example

A company collects personal information from consumers in California.

The company needs to understand applicable consumer privacy requirements concerning collection, use, sharing, and consumer rights.

Memory Point

CCPA/CPRA = CONSUMER PRIVACY


13. HIPAA

Full Form

HIPAA = Health Insurance Portability and Accountability Act

For CISSP, the most important concept is:

PHI = Protected Health Information

Practical Example

A hospital stores:

Patient Name
Medical History
Diagnosis
Treatment
Insurance Information

Security controls may include:

  • Access control

  • Encryption

  • Audit logging

  • Authentication

  • Physical safeguards

  • Technical safeguards

Memory Point

HIPAA = HEALTHCARE / PHI


14. FERPA

Full Form

FERPA = Family Educational Rights and Privacy Act

FERPA concerns privacy of certain student education records in the U.S.

Practical Example

A university stores:

  • Student grades

  • Academic records

  • Student identification information

Memory Point

FERPA = EDUCATION RECORDS


15. COPPA

Full Form

COPPA = Children's Online Privacy Protection Act

It addresses online privacy protections for children under 13 in the U.S. context.

Practical Example

A website directed toward young children collects personal information.

The organization must consider applicable COPPA requirements.

Memory Point

COPPA = CHILDREN


16. Privacy Memorize Map

GDPR       → PERSONAL DATA
CCPA/CPRA  → CONSUMER PRIVACY
HIPAA      → HEALTHCARE / PHI
FERPA      → EDUCATION RECORDS
COPPA      → CHILDREN

17. Financial Regulations

GLBA

Full Form

GLBA = Gramm-Leach-Bliley Act

GLBA is associated with protecting the privacy and security of customer financial information held by financial institutions.

Practical Example

A bank stores:

Account Numbers
Transaction History
Loan Information
Customer Financial Information

The bank needs appropriate privacy and security safeguards.

CISSP Memory Point

GLBA = CUSTOMER FINANCIAL INFORMATION


18. SOX

Full Form

SOX = Sarbanes-Oxley Act

SOX is strongly associated with:

  • Corporate financial reporting

  • Internal controls

  • Accountability

  • Integrity of financial information

Practical Example

A publicly traded company maintains financial records in a database.

An administrator can modify financial records without proper authorization or auditability.

This creates concerns involving:

  • Internal controls

  • Accountability

  • Integrity

  • Financial reporting

CISSP Memory Point

SOX = CORPORATE FINANCIAL REPORTING


19. FCRA

Full Form

FCRA = Fair Credit Reporting Act

FCRA concerns consumer reporting and credit information.

Practical Example

A credit-reporting organization maintains consumer credit information.

Accuracy, privacy, and proper handling of that information become important.

Memory Point

FCRA = CREDIT REPORTING


20. FACTA

Full Form

FACTA = Fair and Accurate Credit Transactions Act

FACTA amended FCRA and includes provisions related to consumer information and identity theft.

Memory Point

FACTA = CREDIT + IDENTITY THEFT


21. PCI DSS

Full Form

PCI DSS = Payment Card Industry Data Security Standard

PCI DSS focuses on protecting payment-card data.

Practical Example

An e-commerce company processes credit-card payments.

Security controls may include:

  • Network segmentation

  • Access control

  • Encryption

  • Logging

  • Vulnerability management

  • Secure configuration

  • Monitoring

VERY IMPORTANT

PCI DSS is:

An industry security standard, NOT a law.

It can nevertheless become a business requirement through contracts, payment networks, or other obligations.

Memory Point

PCI DSS = PAYMENT CARDS


22. Financial Memorize Map

GLBA    → CUSTOMER FINANCIAL INFORMATION
SOX     → CORPORATE FINANCIAL REPORTING
FCRA    → CREDIT REPORTING
FACTA   → CREDIT + IDENTITY THEFT
PCI DSS → PAYMENT CARDS

23. Cybercrime & Computer Misuse

Cybercrime involves illegal activity involving computers, networks, systems, or data.

Examples:

  • Unauthorized access

  • Computer fraud

  • Credential theft

  • Malware

  • Data theft

  • Destruction of systems

For CISSP, recognize that a cyber incident can have technical, legal, regulatory, and contractual consequences.


24. CFAA

Full Form

CFAA = Computer Fraud and Abuse Act

The CFAA is a U.S. federal law associated with certain forms of unauthorized access and misuse of computers.

Practical Example

An attacker obtains credentials and accesses a corporate server without authorization.

The security issue is:

Unauthorized computer access

Memory Point

CFAA = COMPUTER ACCESS


25. ITADA

Full Form

ITADA = Illinois Computer Crime Act / Illinois computer-related criminal law is an example of U.S. state-level legislation addressing computer-related offenses and unauthorized use/access.

For CISSP, the important point is not the detailed Illinois statute.

The important concept is:

State-level computer crime laws can also apply to unauthorized computer access or misuse.

Practical Example

A person intentionally accesses a computer system without authorization or misuses computer resources in violation of applicable state law.

This can create:

  • Criminal liability

  • Civil consequences

  • Organizational incident-response obligations

  • Evidence-preservation requirements

CISSP Memory Point

ITADA → STATE-LEVEL COMPUTER CRIME

Important CISSP Perspective

Don't spend significant study time memorizing ITADA's specific sections or penalties.

Understand the broader concept:

Federal Computer Crime
        ↓
CFAA

State Computer Crime
        ↓
State-specific laws
        ↓
Example: ITADA / Illinois

The exam value is the computer-crime concept, not Illinois statutory details.


26. ECPA

Full Form

ECPA = Electronic Communications Privacy Act

ECPA addresses privacy protections involving electronic communications.

Practical Example

An organization wants to monitor employee electronic communications.

The security team should consider:

  • Applicable laws

  • Organizational policy

  • Consent

  • Contracts

  • Jurisdiction

  • Privacy requirements

Memory Point

ECPA = ELECTRONIC COMMUNICATIONS


27. Cybercrime Memorize Map

CFAA
→ UNAUTHORIZED COMPUTER ACCESS
→ U.S. FEDERAL COMPUTER CRIME

ITADA
→ STATE-LEVEL COMPUTER CRIME
→ Example: Illinois

ECPA
→ ELECTRONIC COMMUNICATIONS
→ PRIVACY

Important CISSP Study Tip

CFAA and ITADA are not two laws you need to memorize in equal depth.

For CISSP:

CFAA → Know the federal computer-crime concept

ITADA → Recognize that state-level computer-crime laws also exist

ECPA → Know electronic-communication privacy


28. Data Breach — CISSP Perspective

A data breach is not simply a technical incident.

It can create:

  • Legal obligations

  • Regulatory obligations

  • Contractual obligations

  • Notification requirements

  • Privacy obligations

  • Evidence-preservation requirements

Practical Example

A company discovers that an attacker accessed a database containing customer personal information.

The security team should ask:

What data?
    ↓
Whose data?
    ↓
Which jurisdictions?
    ↓
Which laws apply?
    ↓
Is notification required?
    ↓
Who must be notified?
    ↓
What contractual obligations exist?

CISSP Memory Point

BREACH = TECHNICAL + LEGAL + REGULATORY + CONTRACTUAL


29. Transborder Data Flow

What does it mean?

Transborder data flow means data is transferred or processed across national or jurisdictional boundaries.

Practical Example

Customer
Germany
   ↓
Application
India
   ↓
Cloud
United States

The organization needs to consider:

  • Privacy laws

  • Data-transfer requirements

  • Data residency

  • Contractual restrictions

  • Regulatory requirements

  • Jurisdiction

CISSP Memory Point

Transborder Data Flow = DATA CROSSING JURISDICTIONS


30. Import / Export Controls

Certain technologies may be subject to restrictions when transferred across borders.

For CISSP, think particularly about:

  • Encryption technology

  • Security technologies

  • Sensitive hardware/software

  • Controlled technologies

Practical Example

A company wants to export a product containing advanced cryptographic functionality.

Before exporting, the organization should determine whether applicable export-control requirements apply.

Memory Point

Import/Export Controls = TECHNOLOGY CROSSING BORDERS


31. Contracts

Security requirements don't always come from laws.

They can come from contracts.

Examples:

  • NDA — Non-Disclosure Agreement

  • SLA — Service Level Agreement

  • DPA — Data Processing Agreement

  • Security addendum

  • Vendor agreement

  • Cloud service agreement

Practical Example

A cloud provider contract requires:

Security incidents involving customer data must be reported within 24 hours.

Even if a specific law doesn't impose that exact contractual deadline, the organization may still have a contractual obligation to comply.

CISSP Memory Point

Contract = LEGAL OBLIGATION BETWEEN PARTIES


32. Industry Standards vs Laws

A CISSP question may deliberately distinguish between these.

LAW
↓
Government requirement

REGULATION
↓
Government / regulatory requirement

CONTRACT
↓
Agreement between parties

INDUSTRY STANDARD
↓
Industry-defined requirement

Examples

HIPAA   → U.S. healthcare law/regulatory framework
GDPR    → European data-protection regulation
PCI DSS → Industry standard
NDA     → Contract

Don't automatically assume that every security requirement is a law.


33. Due Care vs Due Diligence

These are very important CISSP concepts.

Due Care

Taking reasonable actions to protect the organization.

Examples:

  • Establish policies

  • Implement security controls

  • Protect sensitive information

  • Establish procedures

Memory Point

Due Care = DO


34. Due Diligence

Due diligence means investigating, evaluating, and verifying that security measures are appropriate and effective.

Examples:

  • Security assessments

  • Vulnerability assessments

  • Vendor assessments

  • Reviewing controls

  • Monitoring compliance

Memory Point

Due Diligence = CHECK


Easy Trick

Due Care
   ↓
DO

Due Diligence
   ↓
CHECK

35. Data Owner vs Data Custodian

Data Owner

The person/business function responsible for determining:

  • Classification

  • Access requirements

  • Protection requirements

  • Retention requirements

Owner = DECIDES

Data Custodian

The party responsible for implementing and maintaining the required controls.

Examples:

  • IT administrators

  • Cloud administrators

  • Database administrators

Custodian = IMPLEMENTS

Memory Map

OWNER
  ↓
DECIDES

CUSTODIAN
  ↓
IMPLEMENTS

36. Jurisdiction

What is Jurisdiction?

Jurisdiction is the authority of a particular legal system to govern or adjudicate a matter.

Practical Example

A company is headquartered in India.

Its customers are in Europe.

Its cloud infrastructure is in the United States.

A security incident exposes customer data.

The organization may need to consider multiple jurisdictions.

CISSP Memory Point

Jurisdiction = WHO HAS LEGAL AUTHORITY?


37. Civil vs Criminal Law

Civil Law

Generally concerns disputes between parties.

Examples:

  • Contract disputes

  • Damages

  • Injunctions

Memory Point

Civil = DISPUTE


Criminal Law

Concerns offenses prosecuted by the government.

Examples:

  • Certain forms of unauthorized access

  • Fraud

  • Theft

  • Destruction of systems

Memory Point

Criminal = OFFENSE


38. CISSP Real-World Scenario

Consider a global financial company:

Customer
   ↓
Germany
   ↓
Personal Data
   ↓
Application
   ↓
India
   ↓
Cloud Infrastructure
   ↓
United States

Now suppose an attacker compromises the application.

A CISSP should think:

Personal Data
     ↓
Privacy Requirements

Multiple Countries
     ↓
Jurisdiction

Data Crossing Countries
     ↓
Transborder Data Flow

Security Incident
     ↓
Breach Requirements

Cloud Provider
     ↓
Contractual Requirements

Financial Institution
     ↓
Applicable Financial Regulations

Proprietary Software
     ↓
Intellectual Property

Unauthorized Access
     ↓
Cybercrime Requirements

This is the holistic security-management mindset CISSP is looking for.


39. CISSP Practice Questions

Question 1 — DMCA

A streaming company uses DRM to prevent unauthorized copying of copyrighted movies. An attacker develops a tool specifically designed to bypass the DRM protection.

Which legal concept is MOST relevant?

A. SOX

B. DMCA

C. HIPAA

D. FCRA

Answer: B — DMCA

The scenario involves:

  • Digital copyrighted material

  • DRM

  • Circumvention of technological protection

Memory Point

DMCA = DIGITAL COPYRIGHT + ANTI-CIRCUMVENTION


Question 2 — DRM

What is the primary purpose of Digital Rights Management (DRM)?

A. Detect network intrusions

B. Control access to and use of digital content

C. Encrypt network traffic

D. Manage security vulnerabilities

Answer: B

DRM is a technology used to control how digital content is accessed, copied, used, or distributed.

Memory Point

DRM = CONTROL DIGITAL CONTENT USE


Question 3 — Intellectual Property

A company develops a novel encryption mechanism and wants legal protection for the invention.

Which is MOST appropriate?

A. Copyright

B. Trademark

C. Patent

D. Trade secret

Answer: C — Patent

Patent = INVENT


Question 4 — Trade Secret

A company protects its proprietary algorithm by restricting access, using encryption, and requiring employees to sign NDAs.

Which IP concept is MOST relevant?

A. Trademark

B. Trade secret

C. Copyright

D. Patent

Answer: B

The organization is attempting to maintain the information as secret and confidential.

Trade Secret = KEEP SECRET


Question 5 — GLBA

A bank needs to protect customer financial information.

Which regulation is MOST directly relevant?

A. GLBA

B. DMCA

C. FERPA

D. CFAA

Answer: A — GLBA

GLBA = CUSTOMER FINANCIAL INFORMATION


Question 6 — SOX

A publicly traded company needs strong controls over the integrity and accountability of corporate financial reporting.

Which regulation is MOST relevant?

A. HIPAA

B. SOX

C. GDPR

D. DMCA

Answer: B — SOX

SOX = CORPORATE FINANCIAL REPORTING


Question 7 — Privacy

An organization processes personal data of individuals covered by GDPR.

What should the security professional primarily consider?

A. Copyright protection

B. Personal-data protection and privacy requirements

C. Payment-card requirements

D. Software licensing

Answer: B

GDPR = PERSONAL DATA


Question 8 — Cybercrime

An attacker accesses a company's server without authorization.

Which U.S. federal law is most closely associated with unauthorized computer access?

A. CFAA

B. HIPAA

C. FERPA

D. DMCA

Answer: A — CFAA

CFAA = COMPUTER ACCESS


Question 9 — State Computer Crime

A security professional is investigating unauthorized computer access and discovers that the incident may also violate applicable state computer-crime legislation.

Which concept should the security professional understand?

A. Only federal law can apply to computer crime

B. State computer-crime laws may also apply

C. Copyright law automatically applies

D. PCI DSS determines criminal liability

Answer: B

State-level computer-crime laws can apply in addition to applicable federal laws.

Memory Point

ITADA → STATE-LEVEL COMPUTER CRIME


Question 10 — Transborder Data Flow

A company stores customer data in the United States while processing the data in India.

Which concept should the security professional consider?

A. Trademark

B. Transborder data flow

C. Copyright

D. Patent

Answer: B

Transborder Data Flow = DATA CROSSING JURISDICTIONS


Question 11 — Due Care

An organization establishes security policies and implements appropriate security controls.

What does this BEST represent?

A. Due diligence

B. Due care

C. Jurisdiction

D. Liability

Answer: B — Due Care

Due Care = DO


Question 12 — Due Diligence

An organization regularly evaluates its security controls and performs security assessments to determine whether they remain effective.

What does this BEST represent?

A. Due care

B. Due diligence

C. Data ownership

D. Licensing

Answer: B — Due Diligence

Due Diligence = CHECK


Question 13 — Industry Standard

An organization accepts payment cards and must follow requirements established by the payment-card industry.

What is MOST relevant?

A. PCI DSS

B. DMCA

C. CFAA

D. FERPA

Answer: A — PCI DSS

Important:

PCI DSS is an industry standard, NOT a law.


40. The Ultimate CISSP Laws & Regulations Memorize Map

╔════════════════════════════════════════════════════╗
║       CISSP LAWS & REGULATIONS — MEMORIZE MAP    ║
╚════════════════════════════════════════════════════╝


INTELLECTUAL PROPERTY
────────────────────────────────────────────────────
Copyright
→ CREATE / Creative Work

DMCA
→ DIGITAL COPYRIGHT
→ DRM / Anti-Circumvention

Patent
→ INVENT

Trademark
→ BRAND

Trade Secret
→ KEEP SECRET

Licensing
→ PERMISSION TO USE


PRIVACY
────────────────────────────────────────────────────
GDPR
→ PERSONAL DATA

CCPA / CPRA
→ CONSUMER PRIVACY

HIPAA
→ HEALTHCARE / PHI

FERPA
→ EDUCATION RECORDS

COPPA
→ CHILDREN


FINANCIAL
────────────────────────────────────────────────────
GLBA
→ CUSTOMER FINANCIAL INFORMATION

SOX
→ CORPORATE FINANCIAL REPORTING

FCRA
→ CREDIT REPORTING

FACTA
→ CREDIT + IDENTITY THEFT

PCI DSS
→ PAYMENT CARDS
→ INDUSTRY STANDARD, NOT LAW


CYBERCRIME / COMPUTER MISUSE
────────────────────────────────────────────────────
CFAA
→ UNAUTHORIZED COMPUTER ACCESS
→ U.S. FEDERAL COMPUTER CRIME

ITADA
→ STATE-LEVEL COMPUTER CRIME
→ ILLINOIS EXAMPLE

ECPA
→ ELECTRONIC COMMUNICATIONS
→ PRIVACY


CROSS-BORDER
────────────────────────────────────────────────────
Transborder Data Flow
→ DATA CROSSING JURISDICTIONS

Import / Export Controls
→ TECHNOLOGY CROSSING BORDERS


LEGAL / GOVERNANCE
────────────────────────────────────────────────────
Contracts
→ LEGAL OBLIGATIONS BETWEEN PARTIES

Jurisdiction
→ WHO HAS LEGAL AUTHORITY?

Civil
→ DISPUTE

Criminal
→ OFFENSE

Due Care
→ DO

Due Diligence
→ CHECK

Data Owner
→ DECIDES

Data Custodian
→ IMPLEMENTS

41. The 30-Second CISSP Revision

If you have only 30 seconds before the exam, remember:

DMCA       = DIGITAL COPYRIGHT
GLBA       = FINANCIAL INFORMATION
SOX        = FINANCIAL REPORTING
GDPR       = PERSONAL DATA
HIPAA      = HEALTHCARE / PHI
CFAA       = COMPUTER ACCESS
ITADA      = STATE COMPUTER CRIME
ECPA       = ELECTRONIC COMMUNICATIONS
PCI DSS    = PAYMENT CARDS

Copyright  = CREATE
Patent     = INVENT
Trademark  = BRAND
Trade Secret = KEEP SECRET
License    = PERMISSION TO USE

Transborder Data Flow
           = DATA CROSSING JURISDICTIONS

Import/Export
           = TECHNOLOGY CROSSING BORDERS

Due Care      = DO
Due Diligence = CHECK

Owner         = DECIDES
Custodian     = IMPLEMENTS

Civil         = DISPUTE
Criminal      = OFFENSE

Jurisdiction  = LEGAL AUTHORITY

42. Final CISSP Exam Strategy

Don't memorize laws as isolated facts.

Train yourself to recognize the scenario.

             CISSP SCENARIO
                   │
                   ▼
          What is being protected?
                   │
        ┌──────────┼──────────┐
        ▼          ▼          ▼
       Data        IP       System
        │          │          │
        ▼          ▼          ▼
     Privacy    Copyright   Cybercrime
     GDPR       Patent      CFAA
     HIPAA      Trademark   ITADA
                Trade Secret ECPA
        │
        ▼
   Which jurisdiction?
        │
        ▼
   Which law / regulation /
   contract / standard?
        │
        ▼
   What security obligation?

The CISSP mindset is:

Identify the asset → identify the legal issue → identify the applicable requirement → determine the security obligation.

You are not expected to practice law.

You are expected to understand how legal and regulatory requirements affect information-security decisions.


Final Memory Formula

IP
→ Create / Invent / Brand / Secret

PRIVACY
→ Personal / Health / Education / Children

FINANCE
→ Customer Finance / Financial Reporting / Credit / Cards

CYBERCRIME
→ Unauthorized Access / Communications

CROSS-BORDER
→ Data / Technology Crossing Borders

GOVERNANCE
→ Contract / Jurisdiction / Due Care / Due Diligence

OWNER
→ DECIDES

CUSTODIAN
→ IMPLEMENTS

CISSP Golden Rule

Don't memorize the law. Understand the security scenario that makes the law relevant.