CCSP · Domain 6
Legal, Risk and Compliance
About 13% of the exam
Legal concepts
- Jurisdiction
- whose courts and laws apply
- Data sovereignty
- storing country's law governs data
- Conflicting laws
- retention limit versus litigation hold
- Due care
- doing what a prudent party does
- Due diligence
- investigating before deciding
- Negligence
- failing reasonable safeguards, harm results
- Mutual legal assistance
- treaties for cross-border evidence
Regulations to recognize
Privacy
- GDPR: EU personal data, extraterritorial
- CCPA and CPRA: know, delete, opt out
- HIPAA: PHI, business associate agreement required
- GLBA: financial customer information
- COPPA: children under thirteen
Sector and industry
- PCI DSS: cardholder data, contractual not law
- SOX: financial reporting integrity
- FedRAMP: US federal cloud authorization
- Basel III: bank operational risk
- NIS2 and DORA in the EU
Cross-border transfer
- Adequacy decisions by the Commission
- Standard contractual clauses
- Binding corporate rules inside a group
- EU-US Data Privacy Framework self-certification
- Localization laws force data to stay
GDPR essentials
- Controller
- decides purpose and means
- Processor
- acts on controller instructions, the CSP
- Lawful basis
- consent, contract, legitimate interest, others
- Breach notice
- 72 hours to supervisory authority
- DPIA
- required when high risk to individuals
- DPO
- required for large-scale or public processing
- Rights
- access, erasure, portability, object, human review
- Fines
- 4% turnover or 20 million euros
Controller notifies the authority; the processor must tell the controller without undue delay
eDiscovery and evidence
- Identify, preserve, collect, process, review, produce
- Legal hold overrides retention deletion
- Chain of custody proves integrity
- Provider cooperation must be contractual
- Multitenancy limits what can be produced
- Metadata and logs are discoverable too
- ISO/IEC 27050 guides electronic discovery
- Forensic readiness planned before litigation
Audit reports and certifications
- SOC 1
- financial reporting controls, SSAE 18
- SOC 2
- trust services criteria, restricted
- SOC 3
- public summary of SOC 2
- Type I
- design at a point in time
- Type II
- operating effectiveness over a period
- ISO/IEC 27001
- certified ISMS
- ISO 27017, 27018
- cloud controls, PII in cloud
- CSA STAR
- self, attestation, continuous
- PCI ROC, AOC
- cardholder environment compliance
Type I says the controls exist; Type II says they worked for months. Ask for Type II
Audit planning and scope
- Define scope, objectives, criteria first
- Gap analysis before the formal audit
- Audit scope statements set boundaries
- Scope restrictions limit provider audits
- Right to audit clauses, or accept reports
- Internal, external, third-party assurance
- Auditor independence and qualifications
- Remediate findings, track to closure
Risk management program
- Frame
- Assess
- Respond
- Monitor
- Avoid
- stop the activity
- Mitigate
- controls reduce likelihood or impact
- Transfer
- insurance, contract, never accountability
- Accept
- within appetite, documented
- Residual risk
- what remains after controls
- Risk appetite
- how much leadership will bear
Contracts and SLAs
Contract terms to demand
- Data ownership stays with the customer
- Data location and transfer restrictions
- Subprocessor disclosure and approval
- Breach notification timelines
- Return and destruction at exit
- Right to audit or agreed reports
- Liability, indemnity, insurance
SLA elements
- Uptime with measurement method
- Performance and support response times
- Credits, penalties and their caps
- Exclusions: maintenance, force majeure
- Reporting and dispute process
- Exit terms and data portability
Service credits capped at monthly fees do not transfer your business risk; the contract is the only control you have over the provider
Vendor management
- Due diligence before signing
- Review audit reports every period
- Track fourth parties and subprocessors
- Financial viability and exit risk
- Supply chain of the provider matters
- Reassess on breach, merger, ownership change
- Provider risk is still your risk
Policies and the ISMS
- Policy states intent, standards set requirements
- Procedures say how, guidelines advise
- ISO/IEC 27001 structures the ISMS
- Map overlapping frameworks to one control set
- Cloud policy covers acceptable services
- Exceptions documented with expiry
- Management review closes the loop
Cloud-specific legal risks
- Loss of physical control over data
- Provider breach below its notice threshold
- National security letters bind provider secrecy
- Lock-in and lock-out at provider failure
- Subprocessor breaches you never saw
- Automated decisions need human review rights
- Unclear jurisdiction across replicated regions
- Certification-against-liability clauses shift blame
Privacy foundations
- FIPPs: notice, choice, minimization, accountability
- PII: identifies a person alone or combined
- Sensitive categories need stronger basis
- Purpose limitation and retention limitation
- Privacy by design and by default
- Data subject rights on a clock
- ISO 27701 extends ISMS to privacy
- Privacy impact assessment before high-risk processing
Key numbers
- GDPR breach notice
- 72 hours to authority
- GDPR top fine
- 4% or 20 million euros
- GDPR lower tier
- 2% or 10 million euros
- PCI DSS Requirement 12
- security policy for all personnel
- SOC period
- Type II covers six to twelve months
- COPPA age
- under 13
- HIPAA partner
- business associate agreement
Reference strip: law, audit, contract, risk
Law and privacy
- GDPR, CCPA, HIPAA, GLBA
- Controller, processor, DPO, DPIA
- SCCs, adequacy, DPF, BCRs
- Sovereignty, residency, localization
Audit
- SOC 1, 2, 3; Type I, II
- ISO 27001, 27017, 27018, 27701
- CSA STAR levels 1 to 3
- PCI ROC and AOC
Contract
- Ownership, location, subprocessors
- Breach notice, exit, destruction
- SLA metrics, credits, exclusions
- Right to audit
Risk
- Frame, assess, respond, monitor
- Avoid, mitigate, transfer, accept
- Appetite, tolerance, residual
- Vendor and fourth-party risk
Evidence
- eDiscovery six steps
- Legal hold beats retention
- Chain of custody
- ISO 27050, provider cooperation clause
Quick exam traps
- Trap: The cloud provider is the data controller for customer data
- Trap: A SOC 2 Type I proves controls operated effectively
- Trap: PCI DSS is a law
- Trap: The processor notifies the supervisory authority of a breach
- Trap: Transferring risk by contract transfers accountability
- Trap: A SOC 3 report contains the full detail of a SOC 2
- Trap: Data in another country stays under your home law
- Trap: Retention policy deletion continues during a legal hold
cybercertprep.com · original revision sheet written from the public body of knowledge