BCI Regulatory Compliance & Legal Framework 2 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act (SOX), which section specifically requires management to assess and report on internal controls over financial reporting?
- Section 302
- Section 404 (Correct answer)
- Section 802
- Section 906
Correct answer: Section 404
SOX Section 404 mandates that management assess and report on the effectiveness of internal controls over financial reporting annually.
Question 2: Which U.S. federal regulation primarily governs business continuity requirements for federally insured depository institutions?
- HIPAA Security Rule
- FFIEC Business Continuity Planning Booklet (Correct answer)
- NIST SP 800-34
- GLBA Safeguards Rule
Correct answer: FFIEC Business Continuity Planning Booklet
The FFIEC Business Continuity Planning Booklet provides supervisory guidance specifically for federally insured depository institutions' BC programs.
Question 3: A company discovers that a contractual obligation conflicts with a new state privacy law. What is the FIRST step the BC manager should take?
- Immediately terminate the contract
- Notify the regulator before taking any action
- Escalate to legal counsel for guidance on compliance hierarchy (Correct answer)
- Amend the contract unilaterally
Correct answer: Escalate to legal counsel for guidance on compliance hierarchy
Legal counsel must determine which obligation takes precedence and advise on remediation steps before any action is taken.
Question 4: The EU's Network and Information Security (NIS2) Directive requires entities to report significant incidents within how many hours of detection?
- 12 hours
- 24 hours (Correct answer)
- 72 hours
- 96 hours
Correct answer: 24 hours
NIS2 requires an early warning notification to the relevant authority within 24 hours of becoming aware of a significant incident.
Question 5: Which legal concept holds a parent company responsible for the BC failures of its subsidiaries when those failures cause third-party harm?
- Force majeure
- Vicarious liability (Correct answer)
- Indemnification
- Sovereign immunity
Correct answer: Vicarious liability
Vicarious liability can make a parent company legally responsible for the acts or omissions of entities under its control.
Question 6: Under HIPAA, a covered entity must report a breach affecting 500 or more individuals to which authority within 60 days?
- The FTC
- HHS Office for Civil Rights (Correct answer)
- State Attorney General
- CISA
Correct answer: HHS Office for Civil Rights
HIPAA's Breach Notification Rule requires covered entities to notify HHS Office for Civil Rights within 60 days of discovering a breach affecting 500+ individuals.
Question 7: Which standard specifically addresses supply chain risk management within an information security framework and is relevant to BC compliance?
- ISO 22301
- ISO/IEC 27036 (Correct answer)
- ISO 31000
- ISO 9001
Correct answer: ISO/IEC 27036
ISO/IEC 27036 provides guidelines for information security in supplier relationships, directly addressing supply chain risk relevant to BC compliance.
Under the Sarbanes-Oxley Act (SOX), which section specifically requires management to assess and report on internal controls over financial reporting?