CAP Compliance & Regulatory Standards 2 — Questions and Answers
Question 1: Which federal law requires agencies to report major information security incidents to Congress and OMB within a specific timeframe?
- FISMA (Correct answer)
- HIPAA
- Sarbanes-Oxley
- GLBA
Correct answer: FISMA
FISMA requires federal agencies to report major incidents to Congress and OMB, establishing accountability for information security.
Question 2: Under NIST SP 800-53, which control family specifically addresses audit and accountability requirements?
- Access Control (AC)
- Audit and Accountability (AU) (Correct answer)
- Configuration Management (CM)
- Incident Response (IR)
Correct answer: Audit and Accountability (AU)
The AU (Audit and Accountability) control family in NIST SP 800-53 covers audit log generation, review, and retention requirements.
Question 3: Which Privacy Act requirement mandates that agencies publish notice of their records systems in the Federal Register?
- Data minimization notice
- System of Records Notice (SORN) (Correct answer)
- Privacy Impact Assessment
- Data Breach Notification
Correct answer: System of Records Notice (SORN)
A System of Records Notice (SORN) must be published in the Federal Register before an agency can create or modify a system that retrieves records by personal identifier.
Question 4: A healthcare organization subject to HIPAA must conduct a risk analysis under which specific rule?
- HIPAA Privacy Rule
- HIPAA Security Rule (Correct answer)
- HIPAA Enforcement Rule
- HIPAA Breach Notification Rule
Correct answer: HIPAA Security Rule
The HIPAA Security Rule requires covered entities to conduct a thorough assessment of the potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability.
Question 5: Under FedRAMP, what is the minimum assessment frequency for systems with a Moderate impact level?
- Monthly vulnerability scans and annual assessment
- Continuous monitoring with annual authorization review (Correct answer)
- Quarterly assessments with bi-annual pen testing
- Bi-annual assessments with monthly reporting
Correct answer: Continuous monitoring with annual authorization review
FedRAMP Moderate systems require continuous monitoring with an annual authorization review to maintain an Authorization to Operate (ATO).
Question 6: Which OMB circular establishes the requirement for agencies to develop and maintain an information security program?
- OMB Circular A-11
- OMB Circular A-123
- OMB Circular A-130 (Correct answer)
- OMB Circular A-76
Correct answer: OMB Circular A-130
OMB Circular A-130 establishes policy for the planning, budgeting, governance, acquisition, and management of federal information, including information security programs.
Question 7: The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to implement which type of program?
- Business Continuity Program
- Information Security Program (Correct answer)
- Vendor Management Program
- Privacy Compliance Program
Correct answer: Information Security Program
The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security program to protect customer financial data.
Which federal law requires agencies to report major information security incidents to Congress and OMB within a specific timeframe?