Summarize elements of effective security compliance
Reporting, monitoring, consequences of non-compliance, and privacy regimes including data subject rights.
- Reading time
- 18 min read
- Flashcards
- 16 cards
- Practice questions
- 9 questions · 2 PBQs
Compliance is proving you meet an external requirement. This objective is short, and roughly half of it is privacy — where the terms overlap heavily with the data roles in 5.1.
Compliance reporting
Internal — to management and the board, showing where the organisation stands. External — to regulators, auditors, customers or certification bodies.
Consequences of non-compliance
CompTIA lists five, and they escalate:
- Fines — direct financial penalty
- Sanctions — restrictions imposed by a regulator
- Reputational damage — often the most expensive in the long run
- Loss of licence — the ability to operate in a market removed
- Contractual impacts — breach of customer contracts, lost business
Compliance monitoring
Due diligence
Investigating before acting — checking a vendor, assessing a control before relying on it.
Due care
Acting reasonably on an ongoing basis. Maintaining what due diligence established.
Attestation and acknowledgement
A formal statement that something is true — an executive signing that controls are in place, or a user acknowledging they have read a policy.
Internal and external monitoring — self-assessment versus independent verification, mirroring 5.3's audit distinction.
Automation — continuous compliance checking rather than a point-in-time audit. Links to SCAP and benchmarks in 4.4.
Check yourself
A company investigates a vendor's security thoroughly before signing, then never reviews it again across a five-year contract. Which concept has it failed?
Privacy
The larger half of the objective.
Legal implications by scope
Privacy law varies by local/regional, national and global scope. An organisation operating internationally may be subject to several regimes at once, with conflicting requirements — the reason data sovereignty matters.
The roles
These are the same roles as 5.1, and the exam tests them here too:
| Role | Meaning |
|---|---|
| Data subject | The individual the data is about |
| Data controller | Decides why and how data is processed; primary legal accountability |
| Data processor | Processes on the controller's instructions |
| Data owner | Internal accountability for a data set |
| Data custodian/steward | Day-to-day technical protection |
Data inventory and retention
You cannot protect or delete data whose location you do not know, so data inventory is a genuine control rather than paperwork. Retention defines how long data is kept — driven by regulation, and interacting with legal hold (4.8) and disposal (4.2).
Right to be forgotten
The right of a data subject to have their personal data erased. It is why retention and inventory matter operationally: you cannot honour a deletion request for data you cannot locate, including copies in backups and analytics systems.
Check yourself
A customer requests that a company erase all their personal data. Which capability determines whether the company can actually comply?
Ownership
Who owns the data — the organisation, the individual, or a partner — determines who may use, share and delete it. Contracts should state it explicitly, because assumptions differ between jurisdictions.