In this chapter, we looked at three frameworks detailing the minimum expected standards for maintaining data, and the types of data that must be protected.
PCI-DSS covers card holder detail and authentication data for any organization that handles payment card processing, even if this is outsourced.
HIPAA covers electronic protected health information (ePHI) for any organization that is involved with transmitting, generating, or accessing health information in electronic form.
SOX covers the safeguarding of information related to auditing and accounting, focusing on the integrity of the information held.
While these three legislative and regulatory frameworks are created specifically with the USA in mind, other countries will have frameworks of their own, and international countries will often have to comply with a number of different frameworks simultaneously. Frameworks...