The 2020 CCPA Definitive Guide - Applied NIST 800-171
The 2020 CCPA Definitive Guide - Applied NIST 800-171
Price subject to change. Tap below for current.
Couldn't load pickup availability
In this review of The 2020 California Consumer Privacy Act (CCPA) Definitive Guide, the bottom line is clear: this is a practical, plain-English manual for organizations that must align CCPA compliance with NIST 800-171 controls. Written by MARK A RUSSO CISSP-ISSAP CEH, the guide targets compliance officers, IT security managers and small legal teams who need an applied, programmatic approach rather than high-level theory. The greatest reason to buy is the author's experience and focus on mapping CCPA obligations to actionable NIST 800-171 steps, which makes the material immediately usable for program planning and implementation.
Key Features
- Applied NIST 800-171 mapping: Presents concrete guidance on how to use NIST 800-171 security controls to meet CCPA-related requirements and documentation needs.
- Plain-English interpretation: Breaks down legal amendments and regulatory language into readable recommendations that non-lawyers can follow.
- Updated 2021 release: Includes a new chapter covering 2019-2020 amendments and recent changes affecting business deadlines and obligations.
- Author expertise: Draws on the author's 25+ years in program management, intelligence operations, and cybersecurity to deliver practical program-level advice.
- How-to focus: Emphasizes step-by-step implementation so teams can move from assessment to documented actions and controls.
Who It's For
This guide suits small to mid-size organizations, compliance managers, IT security leads, and consultants who need to align privacy obligations with existing cybersecurity frameworks. It is especially useful for teams already familiar with NIST concepts who want a directed path for CCPA application.
It is less appropriate for readers seeking a comprehensive legal treatise or for consumers wanting a high-level summary of privacy rights; those audiences should consult a legal specialist or a general consumer primer instead.
Pros & Cons
Pros
- Practical mapping of NIST 800-171 controls to CCPA obligations that aids implementation planning.
- Clear, plain-English explanations that make regulatory changes understandable to technical teams.
- Timely coverage of 2019-2020 amendments so readers see recent compliance implications.
- Author brings extensive operational and cybersecurity experience to program guidance.
Cons
- The book is focused on applied implementation rather than in-depth legal analysis, so legal teams may need supplemental counsel.
- Content centers on NIST 800-171; organizations using a different framework will need to translate recommendations.
Specifications
| Title | The 2020 California Consumer Privacy Act (CCPA) Definitive Guide |
| Edition | 2021 release |
| Author/Brand | MARK A RUSSO CISSP-ISSAP CEH |
| Focus | Applied CCPA implementation using NIST 800-171 |
| Intended audience | Compliance officers, IT security managers, consultants |
| Content highlight | Chapter on 2019-2020 amendments and plain-English guidance |
Our Verdict
For organizations that must operationalize CCPA requirements, this guide is a practical, cost-effective resource that translates regulatory changes into NIST 800-171 tasks and program elements. It provides strong value to security and compliance teams seeking an implementation-minded reference, though legal counsel may still be needed for complex interpretations.
Frequently Asked Questions
Does this guide explain recent CCPA amendments?
Yes. The 2021 release includes an additional chapter reviewing 2019-2020 amendments and their practical implications.
Who authored the book and why does it matter?
MARK A RUSSO CISSP-ISSAP CEH authored the guide and his 25+ years of program and cybersecurity experience inform the applied approach.
Will it replace legal advice on CCPA?
No. It is intended as an implementation guide mapping CCPA to technical controls; complex legal questions should still be handled by attorneys.
Editor's Take
A practical, implementation-focused guide that maps CCPA obligations to NIST 800-171 controls, ideal for compliance and security teams who need actionable steps rather than legal theory.

Recently viewed
Recently viewed products will appear here as customers browse the store.