← All CCISO Flashcard Decks

Legal and Regulatory Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Legal and Regulatory flashcards as text
  1. A CISO must understand the concept of 'safe harbor' in data privacy law. In the context of GDPR, which mechanism serves as a safe harbor for transferring personal data to the US?

    Answer: Standard Contractual Clauses (SCCs)

    Following the invalidation of Privacy Shield by Schrems II, Standard Contractual Clauses (SCCs) are the primary mechanism for lawful EU-to-US personal data transfers.

  2. Which legal concept holds that an organization can be held liable for damages caused by third-party vendors who handle their customers' data?

    Answer: Vicarious liability

    Vicarious liability can hold an organization responsible for the actions or negligence of third parties acting on its behalf, including data processors and vendors.

  3. Under FISMA (Federal Information Security Management Act), federal agencies must categorize information systems using which framework?

    Answer: FIPS 199

    FIPS 199 (Standards for Security Categorization of Federal Information and Information Systems) provides the framework for categorizing systems as low, moderate, or high impact.

  4. A CISO at a healthcare organization learns of a breach affecting 600 unsecured PHI records. Under HIPAA Breach Notification Rule, what notification is required within 60 days of the end of the calendar year?

    Answer: Annual summary to HHS only

    For breaches affecting fewer than 500 individuals, HIPAA requires covered entities to notify HHS annually within 60 days of the end of each calendar year.

  5. The Electronic Communications Privacy Act (ECPA) restricts government access to electronic communications. Which part of ECPA specifically governs stored communications and data at rest?

    Answer: Title II – Stored Communications Act

    Title II of ECPA, known as the Stored Communications Act (SCA), governs government access to stored electronic communications and subscriber data held by third-party providers.

  6. In the context of intellectual property law, which type of protection applies to software source code and documentation by default upon creation?

    Answer: Copyright

    Copyright protection attaches automatically to original works including software source code the moment they are created and fixed in a tangible medium.

  7. A CISO is drafting a vendor contract and wants to include language addressing regulatory compliance failures. Which contract clause specifically allocates responsibility and financial exposure for compliance violations between parties?

    Answer: Indemnification clause

    An indemnification clause allocates financial responsibility by requiring one party to compensate the other for losses arising from regulatory violations, breaches, or negligence.