From the course: CompTIA Security+ (SY0-601) Cert Prep: 10 Governance, Risk, and Compliance

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Legal and compliance risks

Legal and compliance risks

From the course: CompTIA Security+ (SY0-601) Cert Prep: 10 Governance, Risk, and Compliance

Start my 1-month free trial

Legal and compliance risks

- [Narrator] Whenever we work with sensitive information, we encounter laws and regulations that govern the ways that we store, process, and transmit that information. One of the first things that we need to figure out when working with sensitive data is what specific laws and regulations apply to us. While that might sound straightforward at first glance, the question of which jurisdictions have the authority to regulate data is actually quite complicated and compliance risks can impact an organization's risk posture. Let's take a look at a simple example. Imagine that we have a company with all of their operations located in the state of California. It's clear in this case that California state law applies to them and so does federal law written at the national level in the United States. But what if the company has a customer located in New York? Does New York law now apply as well? And if they're using a cloud provider…

Contents