6.1 Identify the impact of laws and regulations that relate to information securityÂ
» Identify applicable privacy lawsÂ
» Identify legal jurisdictions the organization andÂ
users operate within (e.g., trans-border data flow)Â
» Identify export lawsÂ
» Identify intellectual property (IP) lawsÂ
» Identify applicable industry regulationsÂ
» Identify and advise on non-compliance risksÂ
6.2 Adhere to the (ISC)2 Code of Ethics as related to management issuesÂ
6.3 Validate compliance in accordance with applicable laws, regulations and industryÂ
best practicesÂ
» Inform and advise senior managementÂ
» Evaluate and select compliance framework(s)Â
» Implement the compliance framework(s)Â
» Define and monitor compliance metricsÂ
6.4 Coordinate with auditors and regulators in support of the internal and externalÂ
audit processesÂ
» PlanÂ
» ScheduleÂ
» Coordinate audit activitiesÂ
» Evaluate and validate findingsÂ
» Formulate responseÂ
» Validate implemented mitigation and remediation actionsÂ
6.5 Document and manage compliance exceptionsÂ
» Identify and document compensating controls and workaroundsÂ
» Report and obtain authorized approval of risk waiverÂ