Cybersecurity Requirements for Specific Industries

Jeff Kosseff · 2019

In addition to the general data security requirements, companies that handle particularly sensitive information or operate in industries that carry particularly high national security risks face more stringent requirements. This chapter covers nine such prominent legal requirements for sensitive information: the Gramm-Leach-Bliley Act Safeguards Rule for financial institutions, the New York Department of Financial Services cybersecurity regulations, and the Red Flags Rule for information for certain creditors and financial institutions. It also covers the Payment Card Industry Data Security Standard for credit and debit card information, California's Internet of Things cybersecurity law, and the Health Insurance Portability and Accountability Act Security Rule for certain health-related information. The chapter further covers Federal Energy Regulatory Commission guidelines for electric grid cybersecurity, Nuclear Regulatory Commission cybersecurity requirements for nuclear reactor licensees, and South Carolina's insurance industry cybersecurity regulations.

Read the paper · More papers on PaperTik