Cyber Intelligence
Security Program Management & Oversight · 20% of exam

L18. Compliance: GDPR, HIPAA, PCI-DSS & SOC 2

Course outlineLesson 18 of 20

Compliance frameworks translate legal and contractual requirements into specific security controls. The Security+ exam tests your ability to identify which framework applies to a given scenario and what key requirements it imposes.

GDPR (General Data Protection Regulation)

Scope: applies to any organization that processes personal data of EU residents, regardless of where the organization is located. Key requirements:
  • Lawful basis for processing personal data (consent, contract, legitimate interest, etc.)
  • Data subject rights: access, rectification, erasure ("right to be forgotten"), portability, objection
  • Privacy by design and default
  • Data Protection Officer (DPO) required for large-scale processing or processing of sensitive data
  • Breach notification to supervisory authority within 72 hours of discovery
  • Transfers of EU data outside the EU require adequate safeguards (SCCs, adequacy decisions)
Penalties: up to 4% of global annual turnover or €20 million, whichever is higher.

HIPAA (Health Insurance Portability and Accountability Act)

Scope: US healthcare. Applies to covered entities (providers, insurers, clearinghouses) and their business associates. Key rules:
  • Privacy Rule: governs use and disclosure of Protected Health Information (PHI) in all forms
  • Security Rule: requires administrative, physical, and technical safeguards for electronic PHI (ePHI)
  • Breach Notification Rule: requires notification to affected individuals, HHS, and (for large breaches) media

PCI-DSS (Payment Card Industry Data Security Standard)

Scope: any organization that stores, processes, or transmits cardholder data (credit/debit card numbers). 12 requirements grouped into 6 goals: build secure networks, protect cardholder data, manage vulnerabilities, implement strong access control, monitor networks, maintain an information security policy.

Assessment: small merchants may complete a Self-Assessment Questionnaire (SAQ); larger merchants require a Qualified Security Assessor (QSA) audit.

SOC 2 (Service Organization Control 2)

Scope: service organizations (cloud providers, SaaS companies) that handle customer data. Trust Service Criteria: Security (required), Availability, Confidentiality, Processing Integrity, Privacy.
  • Type I: point-in-time assessment of control design
  • Type II: assessment of control effectiveness over a period (typically 6-12 months); more rigorous and valued by enterprise customers
Exam Focus Points
  • GDPR applies to processing personal data of EU residents regardless of where the organization is based; breach notification within 72 hours
  • HIPAA Security Rule covers electronic PHI (ePHI); Privacy Rule covers PHI in all forms
  • PCI-DSS applies to any organization that stores, processes, or transmits cardholder data
  • SOC 2 Type I assesses control design at a point in time; Type II assesses effectiveness over 6-12 months
  • GDPR penalties: up to 4% of global annual turnover or €20 million (whichever is higher)
Knowledge Check

1. A US-based SaaS company processes personal data of EU customers. A data breach occurs. Within how many hours must the company notify the relevant EU supervisory authority?

2. A hospital uses a cloud-based electronic health records system. Under HIPAA, the cloud provider is considered what type of entity?

3. A SaaS company completes a SOC 2 audit that evaluates whether their security controls were actually effective over the past 12 months. What type of SOC 2 report is this?

Recommended: Pluralsight

Turn your CompTIA Security+ concepts into passing marks: Pluralsight adds structured study plans, practice exams, and hands-on scenario labs.

Start Security+ prep free10-day free trial available