Match each regulatory compliance framework or legal mandate on the left with its primary governing scope or regulatory requirement on the right.
- Children's Online Privacy Protection Act (COPPA)Mandates verifiable parental consent prior to collecting personal data online from individuals under 13 years of age.
- NYDFS Cybersecurity Regulation (23 NYCRR 500)Requires covered financial institutions to designate a qualified CISO and submit an annual compliance certification.
- Federal Information Security Modernization Act (FISMA)Requires US federal government agencies and contractors to secure information systems using NIST risk management frameworks.
- Digital Operational Resilience Act (DORA)Enforces a unified ICT risk management and operational resilience framework with strict incident reporting timelines for European financial entities.
Answer
COPPA matches verifiable parental consent for children under 13; NYDFS Cybersecurity Regulation matches designating a qualified CISO and submitting annual compliance certification; FISMA matches federal agency security controls aligned with NIST frameworks; DORA matches European ICT risk management and operational resilience requirements.
Each regulatory framework is accurately paired with its legal scope. COPPA targets online services collecting data from children under 13; NYDFS Cybersecurity Regulation targets state-regulated financial entities by requiring a designated CISO and annual attestation; FISMA governs federal agency information systems via NIST standards; and DORA establishes European Union operational resilience and ICT incident reporting rules.
Step-by-Step Solution
Key Concept
Scope and technical obligations of international, federal, state, and sector-specific regulatory compliance frameworks.
Estimated Time:1m 30s