Course Content
Cybersecurity Awareness for Corporate Teams

4.2 Regulatory Standards: The Big Three

  • GDPR (EU – General Data Protection Regulation):

    • Scope: Any data related to EU citizens.

    • Key Concept: “Privacy by Design.”

    • Penalty: Up to €20 Million or 4% of global annual turnover (whichever is higher).

  • HIPAA (US – Health Insurance Portability and Accountability Act):

    • Scope: Protected Health Information (PHI).

    • Key Concept: Minimum Necessary Rule (only access what you need to treat the patient).

    • Penalty: Up to $1.5 Million/year; criminal charges for willful neglect.

  • ISO 27001:

    • Scope: International standard for Information Security Management Systems (ISMS).

    • Key Concept: Continuous improvement of the security posture. It is a commercial differentiator in B2B contracts.