Touchdown! Mount Must Read™ 7, Hometown 0
I knew the “newly fallen Must Read’s™” might accumulate a light dusting. November nights are like that. This single night’s accumulated information fall dumped the equivalent of two years of collected readings. I tried to relax, telling myself the titles would melt off by halftime. Nine years of paper grazing, web surfing, earned degrees, and professional collaboration built a library more than 2000 files high. Timestamps alone attested my entire 21st century digital whereabouts. How many titles could I miss? Halftime came and went with little to no melting. 900+ substantial regulations, frameworks, events and organizations remained firmly fallen aiding only height to the perilously high Mount Must Read™[42]? I need a better defense, or at least to get within punting range.
Blame someone
I wish I’d been raised by wolves. The cubs next door had it made; eating off the floor, playing in dirt, chasing mice for school credit and earning advanced degrees with nothing more than their instinct. Their Dad has a seat in the Senate. I’m the grown up child of Mr. and Mrs. Quality Management. Mom’s name is ISO. Her life is a standard. Dad’s a complete perfectionist. His name is TQM[43]. What would they say if they could see me? Ivey League obedience school, private barking lessons and constant lectures; “there’s more to life than digging holes, chasing cars, HIPAA[44], SOX and GLBA[45]!”
Legal G-A-P
I had to turn this around quick. First order of clean up was the legal G-A-P[46]. The investment in reading on the topics of the Sarbanes-Oxley Act (SOA or SOX) Public Law 107-204[47], Gramm-Leach Bliley Act of 1999 (GLBA) Public Law 106-102[48], and The Health Insurance Portability and Accountability Act of 1996 (“HIPAA” not HIPA) Public Law 104-191[49] exposed me to Securities Exchange Act of 1934[50], crimes involving computer abuse and fraud, and specific areas affecting records management in audit such as 17a-4 in final rule by the SEC. Please don’t ask how I missed FISMA, FOIA[51], or that government regulated industries, use NIST[52] and FIPS as mandated by law. The list of regulations affecting IT standard alone quickly jumped over one hundred. Realizing there had to be a strategy to get arms around this task; I began rating laws based in immediate IT Audit requirement. This still left over sixty regulations. Relegating laws exclusive to Britain and Canada to the items with less immediate impact only lowered the list by two[53]. Even attempts to separate “critical” or “background” material, did not change that when I asked “how can not knowing this hurt me?” the answers were fairly substantial, and at the least, not to be ignored. I settled on the following three dozen laws, spending time reviewing each, and keeping the summary in a database. I eventually read all the laws, but there are still items from the recent blizzard that compel me as more threatening areas of my mental g-a-p.
What I don't know can't hurt me
|
Title Type |
Regulation Primary Name |
Date |
Valid Copy in Public Domain: Web Reference |
|
United States of America Patriot Act of 2001 |
United States Federal Law P.L. 107-56, 115 Stat. 272 |
October 26, 2001 |
|
|
United States Copyright Law, Title 17 |
United States Code 17 U.S.C. §§ 101 – 810 |
October 19, 1976 |
|
|
Uniform Accountancy Act |
State Board Uniform Accountancy Act |
November, 2002 |
Uniform Accountancy Act, Third Edition, Revised, November, 2002 |
|
Title 21 Code of Federal Regulations (21 CFR Part 11) Electronic Records; Electronic Signatures |
Code of Federal Regulation 21 CFR Part 11 |
August 2003 |
|
|
Securities Exchange Act of 1934 |
United States Code 15 U.S.C. §§ 78 |
July 1934 |
|
|
Section 17a-4: Final Rule: Applicability of CFTC and SEC Customer Protection, Recordkeeping, Reporting, and Bankruptcy Rules and the Securities Investor Protection Act of 1970 to Accounts Holding Security Futures Products |
United States Federal Law 15 U.S.C. §§ 78 Rule 17a-4 |
1934 |
|
|
Sarbanes-Oxley Act of 2002 |
United States Federal Law P.L. 107-204 |
July 2002 |
|
|
Safe Harbor Privacy Framework |
United States Code 15 U.S.C. §§ 44-58 Section 5 |
July 21, 2000 |
|
|
Ronald W. Reagan National Defense Authorization Act for Fiscal Year 2005 |
United States Federal Law P.L. 108-375 |
October 2004 |
|
|
Paperwork Reduction Act of 1995 |
United States Federal Law P.L. 104–13 |
May 1995 |
|
|
OMB Circular A-130: Management of Federal Information Resources |
United States Office of Management and Budget Circular/Bulletin/Memorandum OMB Circular A-130 |
September 29, 1995 |
Circular A-130 -- Management of Federal Information Resources |
|
OMB Circular A-119, Federal Participation in the Development and Use of Voluntary Consensus Standards and in Conformity Assessment Activities |
United States Office of Management and Budget Circular/Bulletin/Memorandum OMB Circular A-119 |
Effective February 19, 1998 |
|
|
National Technology Transfer and Advancement Act of 1995 |
United States Federal Law P.L. 104-113 |
March 7, 1996. |
|
|
National Archives and Records Administration |
United States Code 44 U.S.C. §§ 2101 to 2118 |
Founded in 1934 |
|
|
Homeland Security Act of 2002 |
United States Federal Law P.L. 107-296 |
2002 |
|
|
Health Insurance Portability and Accountability Act of 1996 |
United States Federal Law P.L. 104-191 |
April 2003 |
|
|
Gramm-Leach Bliley Act of 1999 |
United States Federal Law P.L. 106-102 |
November 12, 1999 |
|
|
Freedom of Information Act |
United States Code P.L. 104-231 |
1966, Amended in 2002 |
|
|
Foreign Corrupt Practices Act 1977 |
United States Federal Law P.L. 105-366 |
1977 |
|
|
FIPS Publication 201, Personal Identity Verification (PIV) for Federal Employees and Contractors |
Federal Information Processing Standard FIPS 201 |
February 2005 |
FIPS Publication 201, Personal Identity Verification (PIV) for Federal Employees and Contractors |
|
FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems |
Federal Information Processing Standard FIPS 200 |
July 2005 |
FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems |
|
FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems |
Federal Information Processing Standard FIPS 199 |
February 2004 |
|
|
Final Act of The 1986-1994 Uruguay Round Of Trade Negotiations Agreement On Technical Barriers To Trade International Trade Agreement |
P.L. 103-465, 108 Stat. 4809 |
April 15, 1994 |
WTO | legal texts - A Summary of the Final Act of the Uruguay Round |
|
Federal Trade Commission (FTC) Act of 1914, amended in 1938 |
United States Code 15 U.S.C. §§ 41-58 |
1914, Amended in 1938 and in 2000 |
|
|
Federal Information Security Management Act of 2002 |
United States Federal Law P.L. 107-347, Title III |
July 30, 2002 |
Federal Information Security Management Act of 2002, 44 USC 101 note |
|
Fair Credit Reporting Act or Bank Secrecy Act |
United States Federal Law P.L. 91-508 |
1970, Amended in 1996 and in 2003 |
Internal Revenue Manual - 4.26.5 Bank Secrecy Act History and Law |
|
Fair and Accurate Credit Transactions Act of 2003 |
United States Federal Law P.L. 108-159 |
December 2003 |
PUBLIC LAW 108–159 - DEC. 4, 2003 - 117 STAT. 1952; 15 U.S.C. § 1601 |
|
Executive Order 13103 of September 30, 1998 - Computer Software Piracy |
Executive Order Executive Order 13103 |
September 30, 1998 |
|
|
E-Government Act of 2002 |
United States Federal Law P.L. 107-347 |
December 2002 |
|
|
DCI Directive 6/3, Protecting Sensitive Compartmented Information within Information Systems |
Director of Central Intelligence Directive Central Intelligence Policy |
June 1999 |
|
|
Cyber Security Research and Development Act of 2002 |
United States Federal Law P.L. 107-305 |
February 7, 2002 |
|
|
National Institute of Standards and Technology Act formerly Computer Security Enhancement Act of 1997, amendment to Computer Security Act of 1987 |
United States Federal Law P.L. 100-418 was P.L. 100-235 |
October 1998 |
|
|
Computer Fraud and Abuse Act of 1986 |
United States Code 18 U.S.C. §§ 1030 |
October 11, 1996 |
|
|
Clinger-Cohen Act of 1996 |
United States Federal Law P.L. 104-106 |
1996 |
|
|
Chief Financial Officers Act of 1990, A Mandate for Federal Financial Management Reform |
United States Federal Law P.L. 101-576 |
September 1991 |
Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics