L18. Compliance: GDPR, HIPAA, PCI-DSS & SOC 2
Course outlineLesson 18 of 20
Compliance frameworks translate legal and contractual requirements into specific security controls. The Security+ exam tests your ability to identify which framework applies to a given scenario and what key requirements it imposes.
GDPR (General Data Protection Regulation)
Scope: applies to any organization that processes personal data of EU residents, regardless of where the organization is located. Key requirements:- Lawful basis for processing personal data (consent, contract, legitimate interest, etc.)
- Data subject rights: access, rectification, erasure ("right to be forgotten"), portability, objection
- Privacy by design and default
- Data Protection Officer (DPO) required for large-scale processing or processing of sensitive data
- Breach notification to supervisory authority within 72 hours of discovery
- Transfers of EU data outside the EU require adequate safeguards (SCCs, adequacy decisions)
HIPAA (Health Insurance Portability and Accountability Act)
Scope: US healthcare. Applies to covered entities (providers, insurers, clearinghouses) and their business associates. Key rules:- Privacy Rule: governs use and disclosure of Protected Health Information (PHI) in all forms
- Security Rule: requires administrative, physical, and technical safeguards for electronic PHI (ePHI)
- Breach Notification Rule: requires notification to affected individuals, HHS, and (for large breaches) media
PCI-DSS (Payment Card Industry Data Security Standard)
Scope: any organization that stores, processes, or transmits cardholder data (credit/debit card numbers). 12 requirements grouped into 6 goals: build secure networks, protect cardholder data, manage vulnerabilities, implement strong access control, monitor networks, maintain an information security policy.Assessment: small merchants may complete a Self-Assessment Questionnaire (SAQ); larger merchants require a Qualified Security Assessor (QSA) audit.
SOC 2 (Service Organization Control 2)
Scope: service organizations (cloud providers, SaaS companies) that handle customer data. Trust Service Criteria: Security (required), Availability, Confidentiality, Processing Integrity, Privacy.- Type I: point-in-time assessment of control design
- Type II: assessment of control effectiveness over a period (typically 6-12 months); more rigorous and valued by enterprise customers
- ✓GDPR applies to processing personal data of EU residents regardless of where the organization is based; breach notification within 72 hours
- ✓HIPAA Security Rule covers electronic PHI (ePHI); Privacy Rule covers PHI in all forms
- ✓PCI-DSS applies to any organization that stores, processes, or transmits cardholder data
- ✓SOC 2 Type I assesses control design at a point in time; Type II assesses effectiveness over 6-12 months
- ✓GDPR penalties: up to 4% of global annual turnover or €20 million (whichever is higher)
1. A US-based SaaS company processes personal data of EU customers. A data breach occurs. Within how many hours must the company notify the relevant EU supervisory authority?
2. A hospital uses a cloud-based electronic health records system. Under HIPAA, the cloud provider is considered what type of entity?
3. A SaaS company completes a SOC 2 audit that evaluates whether their security controls were actually effective over the past 12 months. What type of SOC 2 report is this?
Recommended: Pluralsight
Turn your CompTIA Security+ concepts into passing marks: Pluralsight adds structured study plans, practice exams, and hands-on scenario labs.