Exam objective
SY0-701 5.4: Security Compliance
Security Compliance for Security+
This Security+ topic covers compliance reporting: internal and external; Consequences of non-compliance: fines, sanctions, reputational damage, loss of license, and contractual impacts; Compliance monitoring: due diligence, due care, attestation, acknowledgement, internal and external monitoring, and automation; Privacy: legal implications at local/regional, national, and global scope; data subject; controller versus processor; ownership; data inventory and retention; and right to be forgotten.
Start first lesson4 lessons in this topic
Common mistakes to avoid
Learners often confuse reporting with auditing. The correction: an audit evaluates or verifies; reporting communicates compliance status and evidence to an audience.
Learners often treat sanctions and fines as the same. The correction: a fine is money; a sanction can include restrictions, penalties, or required actions beyond money.
Learners often confuse attestation and acknowledgement. The correction: attestation asserts a condition is true; acknowledgement confirms receipt, understanding, or acceptance.
Learners often confuse data owner and data subject. The correction: the data subject is the person the data describes; ownership is accountability for managing the data.