CAP Compliance & Regulatory Standards 3 — Questions and Answers
Question 1: Which Executive Order directed the development of the Cybersecurity Framework (CSF) by NIST?
- EO 13526
- EO 13636 (Correct answer)
- EO 13800
- EO 14028
Correct answer: EO 13636
Executive Order 13636 (Improving Critical Infrastructure Cybersecurity, 2013) directed NIST to develop the Cybersecurity Framework.
Question 2: Under the Privacy Act of 1974, which of the following is NOT a right afforded to individuals?
- Right to access records about themselves
- Right to request amendment of inaccurate records
- Right to know why information is collected
- Right to financial compensation for all unauthorized disclosures (Correct answer)
Correct answer: Right to financial compensation for all unauthorized disclosures
While the Privacy Act provides civil remedies, it does not guarantee financial compensation for all unauthorized disclosures—damages must be proven and intentional violations established.
Question 3: NIST SP 800-37 defines the RMF. Which step immediately follows the Categorize step?
- Implement
- Select (Correct answer)
- Authorize
- Assess
Correct answer: Select
In the RMF, after categorizing the system (Step 1), the next step is to Select appropriate security controls (Step 2) based on the categorization.
Question 4: A contractor handling Controlled Unclassified Information (CUI) for DoD must comply primarily with which regulation?
- NIST SP 800-171 (Correct answer)
- NIST SP 800-53
- FIPS 200
- CMMC Level 1
Correct answer: NIST SP 800-171
NIST SP 800-171 specifies the security requirements for protecting CUI in nonfederal systems and organizations, making it the primary compliance standard for DoD contractors.
Question 5: Which standard defines the requirements for Payment Card Industry Data Security?
- ISO 27001
- PCI DSS (Correct answer)
- SOC 2 Type II
- COBIT 5
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is the global standard mandating security controls for organizations that store, process, or transmit cardholder data.
Question 6: Under FISMA, which role is responsible for authorizing the operation of an information system?
- Information System Security Officer (ISSO)
- System Owner
- Authorizing Official (AO) (Correct answer)
- Chief Information Security Officer (CISO)
Correct answer: Authorizing Official (AO)
The Authorizing Official (AO) is the senior official with the authority to accept the risk of operating an information system and formally issue an Authorization to Operate (ATO).
Question 7: Which compliance framework is specifically required for federal government cloud service providers and uses a 'do once, use many times' approach?
- StateRAMP
- FedRAMP (Correct answer)
- CMMC
- FISMA
Correct answer: FedRAMP
FedRAMP standardizes cloud security assessments so that cloud service providers undergo one assessment that can be reused (authorized) by multiple federal agencies.
Which Executive Order directed the development of the Cybersecurity Framework (CSF) by NIST?