Touchdown! Mount Must Read™ 7, Hometown 0

I knew the “newly fallen Must Read’s™” might accumulate a light dusting.  November nights are like that.  This single night’s accumulated information fall dumped the equivalent of two years of collected readings.  I tried to relax, telling myself the titles would melt off by halftime.  Nine years of paper grazing, web surfing, earned degrees, and professional collaboration built a library more than 2000 files high.  Timestamps alone attested my entire 21st century digital whereabouts.  How many titles could I miss? Halftime came and went with little to no melting.  900+ substantial regulations, frameworks, events and organizations remained firmly fallen aiding only height to the perilously high Mount Must Read™[42]?  I need a better defense, or at least to get within punting range.

Blame someone

I wish I’d been raised by wolves.  The cubs next door had it made; eating off the floor, playing in dirt, chasing mice for school credit and earning advanced degrees with nothing more than their instinct.  Their Dad has a seat in the Senate.  I’m the grown up child of Mr. and Mrs. Quality Management.  Mom’s name is ISO.  Her life is a standard.  Dad’s a complete perfectionist.  His name is TQM[43].  What would they say if they could see me?  Ivey League obedience school, private barking lessons and constant lectures; “there’s more to life than digging holes, chasing cars, HIPAA[44], SOX and GLBA[45]!”

Legal G-A-P

I had to turn this around quick.  First order of clean up was the legal G-A-P[46].  The investment in reading on the topics of the Sarbanes-Oxley Act (SOA or SOX) Public Law 107-204[47], Gramm-Leach Bliley Act of 1999 (GLBA) Public Law 106-102[48], and The Health Insurance Portability and Accountability Act of 1996 (“HIPAA” not HIPA) Public Law 104-191[49] exposed me to Securities Exchange Act of 1934[50], crimes involving computer abuse and fraud, and specific areas affecting records management in audit such as 17a-4 in final rule by the SEC.  Please don’t ask how I missed FISMA, FOIA[51], or that government regulated industries, use NIST[52] and FIPS as mandated by law.  The list of regulations affecting IT standard alone quickly jumped over one hundred.  Realizing there had to be a strategy to get arms around this task; I began rating laws based in immediate IT Audit requirement.  This still left over sixty regulations.  Relegating laws exclusive to Britain and Canada to the items with less immediate impact only lowered the list by two[53].  Even attempts to separate “critical” or “background” material, did not change that when I asked “how can not knowing this hurt me?” the answers were fairly substantial, and at the least, not to be ignored.  I settled on the following three dozen laws, spending time reviewing each, and keeping the summary in a database.  I eventually read all the laws, but there are still items from the recent blizzard that compel me as more threatening areas of my mental g-a-p.

What I don't know can't hurt me

Title Type

Regulation Primary Name

Date

Valid Copy in Public Domain:  Web Reference

United States of America Patriot Act of 2001

United States Federal Law P.L. 107-56, 115 Stat. 272

October 26, 2001

Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism (US Patriot Act) Act of 2001

United States Copyright Law, Title 17

United States Code 17 U.S.C.  §§ 101 – 810

October 19, 1976

Circular 92: Copyright Law of the United States of America and Related Laws Contained in Title 17 of the United States Code

Uniform Accountancy Act

State Board Uniform Accountancy Act

November, 2002

Uniform Accountancy Act, Third Edition, Revised, November, 2002

Title 21 Code of Federal Regulations (21 CFR Part 11) Electronic Records; Electronic Signatures

Code of Federal Regulation 21 CFR Part 11

August 2003

21 CFR Part 11: Electronic Records; Electronic Signatures

Securities Exchange Act of 1934

United States Code 15 U.S.C.  §§ 78

July 1934

Securities Exchange Act of 1934

Section 17a-4: Final Rule: Applicability of CFTC and SEC Customer Protection, Recordkeeping, Reporting, and Bankruptcy Rules and the Securities Investor Protection Act of 1970 to Accounts Holding Security Futures Products

United States Federal Law 15 U.S.C.  §§ 78 Rule 17a-4

1934

Final Rule: Applicability of CFTC and SEC Customer Protection, Recordkeeping, Reporting, and Bankruptcy Rules and the Securities Investor Protection Act of 1970 to Accounts Holding Security Futures Products

Sarbanes-Oxley Act of 2002

United States Federal Law P.L. 107-204

July 2002

Public Law 107–204—July 30, 2002—116 STAT.  745

Safe Harbor Privacy Framework

United States Code 15 U.S.C.  §§ 44-58 Section 5

July 21, 2000

Introduction to the Safe Harbor

Ronald W.  Reagan National Defense Authorization Act for Fiscal Year 2005

United States Federal Law P.L. 108-375

October 2004

Public Law 108–375 – October 28, 2004 - 118 STAT.  1811

Paperwork Reduction Act of 1995

United States Federal Law P.L. 104–13

May 1995

PUBLIC LAW 104–13

OMB Circular A-130: Management of Federal Information Resources

United States Office of Management and Budget Circular/Bulletin/Memorandum OMB Circular A-130

September 29, 1995

Circular A-130 -- Management of Federal Information Resources

OMB Circular A-119, Federal Participation in the Development and Use of Voluntary Consensus Standards and in Conformity Assessment Activities

United States Office of Management and Budget Circular/Bulletin/Memorandum OMB Circular A-119

Effective February 19, 1998

Revised OMB Circular A-119

National Technology Transfer and Advancement Act of 1995

United States Federal Law P.L. 104-113

March 7, 1996.

Public Law 104-113 3/7/96

National Archives and Records Administration

United States Code 44 U.S.C.  §§ 2101 to 2118

Founded in 1934

NARA

Homeland Security Act of 2002

United States Federal Law P.L. 107-296

2002

Homeland Security Act of 2002

Health Insurance Portability and Accountability Act of 1996

United States Federal Law P.L. 104-191

April 2003

Public Law 104-191

 

Gramm-Leach Bliley Act of 1999

United States Federal Law P.L. 106-102

November 12, 1999

Gramm-Leach Bliley Act

Freedom of Information Act

United States Code P.L. 104-231

1966, Amended in 2002

Freedom of Information Act

Foreign Corrupt Practices Act 1977

United States Federal Law P.L. 105-366

1977

Foreign Corrupt Practices Act 1977

FIPS Publication 201, Personal Identity Verification (PIV) for Federal Employees and Contractors

Federal Information Processing Standard FIPS 201

February 2005

FIPS Publication 201, Personal Identity Verification (PIV) for Federal Employees and Contractors

FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems

Federal Information Processing Standard FIPS 200

July 2005

FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems

FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems

Federal Information Processing Standard FIPS 199

February 2004

FIPS Publication 199: Standards for Security Categorization of Federal Information and Information Systems

Final Act of The 1986-1994 Uruguay Round Of Trade Negotiations Agreement On Technical Barriers To Trade

International Trade Agreement

P.L. 103-465, 108 Stat.  4809

April 15, 1994

WTO | legal texts - A Summary of the Final Act of the Uruguay Round

Federal Trade Commission (FTC) Act of 1914, amended in 1938

United States Code 15 U.S.C.  §§ 41-58

1914, Amended in 1938 and in 2000

Federal Trade Commission Act, Title 15 - Commerce and Trade

Federal Information Security Management Act of 2002

United States Federal Law P.L. 107-347, Title III

July 30, 2002

Federal Information Security Management Act of 2002, 44 USC 101 note

Fair Credit Reporting Act or Bank Secrecy Act

United States Federal Law P.L. 91-508

1970, Amended in 1996 and in 2003

Internal Revenue Manual - 4.26.5 Bank Secrecy Act History and Law

Fair and Accurate Credit Transactions Act of 2003

United States Federal Law P.L. 108-159

December 2003

PUBLIC LAW 108–159 - DEC.  4, 2003 - 117 STAT.  1952; 15 U.S.C.  § 1601

Executive Order 13103 of September 30, 1998 - Computer Software Piracy

Executive Order Executive Order 13103

September 30, 1998

Executive Order 13103: Computer Software Piracy

E-Government Act of 2002

United States Federal Law P.L. 107-347

December 2002

H. R.  2458: E-Government Act of 2002

DCI Directive 6/3, Protecting Sensitive Compartmented Information within Information Systems

Director of Central Intelligence Directive Central Intelligence Policy

June 1999

DCID 6/3 - Policy

Cyber Security Research and Development Act of 2002

United States Federal Law P.L. 107-305

February 7, 2002

Cyber Security Research and Development Act of 2002

National Institute of Standards and Technology Act formerly Computer Security Enhancement Act of 1997, amendment to Computer Security Act of 1987

United States Federal Law P.L. 100-418 was P.L. 100-235

October 1998

Computer Security Enhancement Act of 1997 (Reported in Senate); THOMAS -- U.S.  Congress on the Internet

Computer Fraud and Abuse Act of 1986

United States Code 18 U.S.C.  §§ 1030

October 11, 1996

Computer Fraud & Abuse Act

Clinger-Cohen Act of 1996

United States Federal Law P.L. 104-106

1996

Illinois Land Conservation Act, P.L. 104-106 S.1124

Chief Financial Officers Act of 1990, A Mandate for Federal Financial Management Reform

United States Federal Law P.L. 101-576

September 1991

GAO/AFMD-12.19.4 CFO Act

Main Menu