Identify any industry specific compliances that must be met (i.e., HIPAA, COPPA, DOD).

Identify any industry specific compliances that must be met (i.e., HIPAA, COPPA, DOD). Determine what overarching guidance they must comply with. Determine what overarching laws they must comply with.

2. Examine the requisite set of standards, frameworks, policies, and best practices most helpful in the development and implementation of the organizations objectives. 

3. Identify the organization’s critical data infrastructure assets (i.e., network, telecom, utilities, applications, computers and client data categories).

4. Identify human resources for technical, management and legal operations.

5. Identify requisite law enforcement entities required for reporting breaches to (i.e., local, state, and federal areas of compliance).