Quiz 6 1. Define an SLA and state why it is required in a risk adverse Organization? A service level agreement (SLA) is a document that identifies an expected level of performance. It identifies the minimum uptime or the maximum downtime. Organizations use SLAs as contracts between a service provider and a customer. An SLA can identify monetary penalties if the terms are not met. If your organization has SLAs with other organizations, these should be included in the risk management review. You should pay special attention to monetary penalties. For example, an SLA could specify a maximum downtime of four hours. After four hours, hourly penalties will start to accrue. You can relate this to the maximum acceptable outage (MAO). 2. Using…show more content…
Family Educational Rights and Privacy Act (FERPA) FERPA applies to all education institutions and agencies that receive funding under any program administered by the U.S. Department of Education (ED). The obvious examples are any public schools from grades K through 12. However, many other entities can receive funding from ED. This includes any school or agency offering preschool programs. It includes any institution of higher education. It can also include community colleges or any other education institution. Children’s Internet Protection Act (CIPA) CIPA applies to any school or library that receives funding from the U.S. E-Rate program. The Federal Communications Commission (FCC) sponsors the E-Rate program. It provides discounts for Internet access. Schools and libraries are not required to use the E-Rate program. However, if they choose to take advantage of the discounts, they are governed by CIPA. The annual E-Rate application requires schools and libraries to certify they are complying with CIPA. Payment Card Industry Data Security Standard (PCI DSS) PCI DSS is not a law. Instead, it is a standard that was jointly created by several credit card companies. Any organization that accepts credit card payments over the Internet needs to comply with PCI DSS.. 5. Define risk with formula. Explain what each variable means? One of the methods you can use to determine if countermeasures overlap is to map

