Exam objective

SY0-701 5.4: Security Compliance

Security+ Topic

Security Compliance for Security+

This Security+ topic covers compliance reporting: internal and external; Consequences of non-compliance: fines, sanctions, reputational damage, loss of license, and contractual impacts; Compliance monitoring: due diligence, due care, attestation, acknowledgement, internal and external monitoring, and automation; Privacy: legal implications at local/regional, national, and global scope; data subject; controller versus processor; ownership; data inventory and retention; and right to be forgotten.

Start first lesson

4 lessons in this topic

Common mistakes to avoid

1

Learners often confuse reporting with auditing. The correction: an audit evaluates or verifies; reporting communicates compliance status and evidence to an audience.

2

Learners often treat sanctions and fines as the same. The correction: a fine is money; a sanction can include restrictions, penalties, or required actions beyond money.

3

Learners often confuse attestation and acknowledgement. The correction: attestation asserts a condition is true; acknowledgement confirms receipt, understanding, or acceptance.

4

Learners often confuse data owner and data subject. The correction: the data subject is the person the data describes; ownership is accountability for managing the data.