Microsoft Windows 98 Regulatory Frameworks & Compliance 5 — Questions and Answers
Question 1: The Gramm-Leach-Bliley Act (GLBA), enacted in 1999 and relevant to late Windows 98 deployments, required financial institutions to do what regarding customer data stored on Windows 98 systems?
- Migrate all data off Windows 98 within 90 days of the law's passage
- Implement safeguards to protect the security and confidentiality of customer financial information (Correct answer)
- Submit all Windows 98 system configurations to the SEC for review
- Use only FIPS 140-1 certified hardware to store financial records
Correct answer: Implement safeguards to protect the security and confidentiality of customer financial information
GLBA's Safeguards Rule required financial institutions to develop security programs protecting customer financial information, affecting how Windows 98 systems storing such data were configured.
Question 2: Under the Federal Trade Commission Act, misleading consumers about software privacy practices (e.g., falsely claiming Windows 98 didn't collect user data) would be investigated as:
- A CFAA violation requiring criminal prosecution
- An unfair or deceptive act or practice under Section 5 of the FTC Act (Correct answer)
- A DMCA circumvention claim filed by Microsoft
- A breach of contract under state commercial codes
Correct answer: An unfair or deceptive act or practice under Section 5 of the FTC Act
The FTC's Section 5 authority over unfair or deceptive practices covered software makers who made false privacy claims to consumers.
Question 3: The EU's Safe Harbor framework (2000), which followed the Windows 98 era, addressed what compliance challenge for U.S. companies transferring EU citizens' data processed on Windows 98 systems?
- Ensuring Windows 98 used European keyboard layouts by default
- Providing an adequate level of data protection to satisfy the EU Data Protection Directive (Correct answer)
- Certifying Windows 98 met EU product safety standards (CE marking)
- Translating all Windows 98 error messages into EU official languages
Correct answer: Providing an adequate level of data protection to satisfy the EU Data Protection Directive
Safe Harbor allowed U.S. companies to self-certify adequate protection for EU personal data, bridging the gap between U.S. practices and the EU's strict Data Protection Directive.
Question 4: Which software licensing model, common in the Windows 98 era, granted organizations the right to install Windows 98 on a defined number of machines under one agreement rather than purchasing individual boxed copies?
- Shareware licensing
- Open-source copyleft licensing
- Microsoft Select or Open Volume License Agreement (Correct answer)
- Freeware public domain dedication
Correct answer: Microsoft Select or Open Volume License Agreement
Microsoft's Select and Open volume license programs let organizations license Windows 98 for multiple machines under a single agreement, simplifying compliance tracking.
Question 5: A Windows 98 system used to process credit card transactions in 1998 would have needed to consider early versions of which payment security framework that later evolved into PCI DSS?
- SWIFT Customer Security Programme
- Visa's Cardholder Information Security Program (CISP) and similar card-brand rules (Correct answer)
- NACHA ACH security guidelines
- ISO 8583 financial transaction messaging standards
Correct answer: Visa's Cardholder Information Security Program (CISP) and similar card-brand rules
Before PCI DSS (2004), individual card brands like Visa (CISP) and Mastercard (SDP) had their own cardholder data security requirements that merchants had to follow.
Question 6: An open-source program (e.g., distributed under the GNU GPL) running on Windows 98 created a compliance obligation requiring the distributor to:
- Pay Microsoft a royalty for using Windows 98 as the host OS
- Provide access to the source code of the GPL-licensed component upon request (Correct answer)
- Obtain written permission from the Free Software Foundation before distribution
- Register the software with the U.S. Copyright Office within 90 days
Correct answer: Provide access to the source code of the GPL-licensed component upon request
The GPL (General Public License) required anyone distributing GPL-licensed software — even on a proprietary OS like Windows 98 — to make the source code available.
Question 7: In a corporate Windows 98 environment, conducting a software compliance self-audit before a BSA or SIIA inspection was recommended primarily because:
- Microsoft offered a discount on new licenses discovered during self-audits
- Self-disclosure typically resulted in reduced penalties compared to facing an external audit with violations (Correct answer)
- The FTC required annual self-audits of all commercial software deployments
- WHQL certification automatically triggered a compliance review by BSA
Correct answer: Self-disclosure typically resulted in reduced penalties compared to facing an external audit with violations
Industry groups like BSA encouraged self-audits because companies that proactively identified and remediated violations typically negotiated significantly lower settlements.
The Gramm-Leach-Bliley Act (GLBA), enacted in 1999 and relevant to late Windows 98 deployments, required financial institutions to do what regarding customer data stored on Windows 98 systems?