Security+
5.4Security Program Management and Oversight · 20% of exam

Summarize elements of effective security compliance

Reporting, monitoring, consequences of non-compliance, and privacy regimes including data subject rights.

Reading time
18 min read
Flashcards
16 cards
Practice questions
9 questions · 2 PBQs

Compliance is proving you meet an external requirement. This objective is short, and roughly half of it is privacy — where the terms overlap heavily with the data roles in 5.1.

Compliance reporting

Internal — to management and the board, showing where the organisation stands. External — to regulators, auditors, customers or certification bodies.

Consequences of non-compliance

CompTIA lists five, and they escalate:

  • Fines — direct financial penalty
  • Sanctions — restrictions imposed by a regulator
  • Reputational damage — often the most expensive in the long run
  • Loss of licence — the ability to operate in a market removed
  • Contractual impacts — breach of customer contracts, lost business

Compliance monitoring

Due diligence

Investigating before acting — checking a vendor, assessing a control before relying on it.

Due care

Acting reasonably on an ongoing basis. Maintaining what due diligence established.

Attestation and acknowledgement

A formal statement that something is true — an executive signing that controls are in place, or a user acknowledging they have read a policy.

Internal and external monitoring — self-assessment versus independent verification, mirroring 5.3's audit distinction.

Automation — continuous compliance checking rather than a point-in-time audit. Links to SCAP and benchmarks in 4.4.

Check yourself

A company investigates a vendor's security thoroughly before signing, then never reviews it again across a five-year contract. Which concept has it failed?

Privacy

The larger half of the objective.

Legal implications by scope

Privacy law varies by local/regional, national and global scope. An organisation operating internationally may be subject to several regimes at once, with conflicting requirements — the reason data sovereignty matters.

The roles

These are the same roles as 5.1, and the exam tests them here too:

RoleMeaning
Data subjectThe individual the data is about
Data controllerDecides why and how data is processed; primary legal accountability
Data processorProcesses on the controller's instructions
Data ownerInternal accountability for a data set
Data custodian/stewardDay-to-day technical protection

Data inventory and retention

You cannot protect or delete data whose location you do not know, so data inventory is a genuine control rather than paperwork. Retention defines how long data is kept — driven by regulation, and interacting with legal hold (4.8) and disposal (4.2).

Right to be forgotten

The right of a data subject to have their personal data erased. It is why retention and inventory matter operationally: you cannot honour a deletion request for data you cannot locate, including copies in backups and analytics systems.

Check yourself

A customer requests that a company erase all their personal data. Which capability determines whether the company can actually comply?

Ownership

Who owns the data — the organisation, the individual, or a partner — determines who may use, share and delete it. Contracts should state it explicitly, because assumptions differ between jurisdictions.