Jump to HeaderJump to Main ContentJump to Footer
Michigan State University
  • About
  • |
  • Clients
  • |
  • Team
  • |
  • Student Recruitment
  • |
  • Workforce Development
  • |
  • Resources
    • Government Resources
    • KUKA Case Study
    • Common Recommendations
    • DOE ITAC Grant
    • Topical Resources
    • Utility Rebates and Incentives
    • Energy Resilience
    • Emergency Demand Response
    • Cybersecurity
  • |
  • Related Programs
    • BTAC Program
    • Expansion Program
  • |
  • Research Projects
  • |
  • Privacy
Industrial Training and Assessment Center
  • About
  • Clients
  • Team
  • Student Recruitment
  • Workforce Development
  • Resources
  • Related Programs
  • Research Projects
  • Privacy

< About

< Clients

< Team

< Student Recruitment

< Workforce Development

< Resources

  • Government Resources
  • KUKA Case Study
  • Common Recommendations
  • DOE ITAC Grant
  • Topical Resources
  • Utility Rebates and Incentives
  • Energy Resilience
  • Emergency Demand Response
  • Cybersecurity

< Related Programs

  • BTAC Program
  • Expansion Program

< Research Projects

< Privacy

  • ITAC Program Website
  • Manufacturing and Energy Supply Chains
  • Advanced Manufacturing Office
Michigan State University
Industrial Training and Assessment Center

Apply:

  • Clients
  • Students
  • DOE ITAC Program

Industrial Training and Assessment Center

  • Clients
  • Students
  • DOE ITAC Program
Industrial Training and Assessment Center > Resources > Cybersecurity >

Federal Regulations

Federal Regulations

There are several federal regulations that small businesses need to be aware of when it comes to cybersecurity. Some of the key regulations include:

The Federal Trade Commission (FTC) Act: The FTC Act requires businesses to implement reasonable cybersecurity measures to protect sensitive customer information, such as financial data, health information, and social security numbers.

The Gramm-Leach-Bliley Act (GLBA): The GLBA requires financial institutions to protect the privacy and security of their customers' personal information, including financial data and social security numbers.

The Health Insurance Portability and Accountability Act (HIPAA): HIPAA applies to businesses in the healthcare industry and requires them to protect the privacy and security of patients' medical information.

The Payment Card Industry Data Security Standard (PCI DSS): PCI DSS applies to businesses that accept credit card payments and requires them to implement security measures to protect customer payment card data.

The General Data Protection Regulation (GDPR): GDPR applies to businesses that process the personal data of EU residents and requires them to implement strong data protection measures.

Small businesses must comply with these regulations, which can include implementing specific cybersecurity measures, conducting risk assessments, and reporting data breaches to the relevant authorities. Non-compliance can result in fines, legal action, and damage to the business's reputation.

Additional standards and regulations can be found at the following resources: 
 
Federal: Cybersecurity and Infrastructure Security Agency 

Michigan: Michigan Department of Technology

  • University Website
  • College of Engineering
  • School of Planning, Design and Construction

Contact us

itac@msu.edu

Address

Engineering Building 428 S. Shaw Lane East Lansing, MI 48824-1226

Follow Us

  • Visit our Instagram page
  • Visit our Facebook page
  • Visit our page on X
  • Visit our LinkedIn page

If you're having accessibility issues, please let us know.

  • Contact Information|
  • Site Map|
  • Privacy Statement|
  • Site Accessibility|
  • Call MSU: (517) 355-1855|
  • Visit: msu.edu|
  • Notice of Nondiscrimination|

SPARTANS WILL|© Michigan State University|