An enterprise compliance officer is updating the organization's regulatory tracking matrix to align with global legal mandates and industry-specific security requirements. Match each regulatory framework or legal mandate on the left with its corresponding compliance scope or operational requirement on the right.
- Children's Online Privacy Protection Act (COPPA)Mandates verifiable parental consent prior to collecting, using, or disclosing personal information online from children under 13 years of age.
- International Traffic in Arms Regulations (ITAR)Controls export and import restrictions on defense-related technical data, military technologies, and space-related items to foreign persons or destinations.
- Federal Information Security Modernization Act (FISMA)Requires United States federal agencies and their contractors to implement security controls according to NIST guidelines and maintain ongoing system risk assessments.
- Digital Operational Resilience Act (DORA)Establishes European Union cybersecurity resilience requirements, mandatory threat-led penetration testing, and ICT third-party risk oversight for financial entities.
Cevap
COPPA matches the mandate for verifiable parental consent before collecting data from children under 13; ITAR matches export restrictions on defense-related technical data; FISMA matches US federal agency security control requirements following NIST guidelines; DORA matches EU financial sector digital operational resilience and ICT vendor oversight requirements.
Each regulation is paired accurately with its legal jurisdiction and operational focus: COPPA protects children's online data privacy; ITAR controls defense technical data exports; FISMA enforces US federal agency information security controls via NIST standards; and DORA establishes EU financial sector ICT operational resilience standards.
Adım Adım Çözüm
Anahtar Kavram
Regulatory Compliance and Legal Requirements Management