CCISO Legal and Regulatory 2 — Questions and Answers
Question 1: Under the EU General Data Protection Regulation (GDPR), what is the maximum fine for the most serious violations?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 6% of global annual turnover
- €5 million or 1% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
GDPR's most serious violations can result in fines up to €20 million or 4% of global annual turnover, whichever is higher.
Question 2: Which US federal law specifically governs the privacy of student education records and limits disclosure without consent?
- COPPA
- FERPA (Correct answer)
- HIPAA
- GLBA
Correct answer: FERPA
FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records held by federally funded institutions.
Question 3: A CISO discovers that a vendor processes personal data on behalf of the company without a signed Data Processing Agreement. Which GDPR role distinction is most relevant?
- Data subject vs. data controller
- Data controller vs. data processor (Correct answer)
- Joint controller vs. sub-processor
- Data owner vs. data custodian
Correct answer: Data controller vs. data processor
GDPR requires a written Data Processing Agreement between a data controller and any data processor handling personal data on its behalf.
Question 4: Which principle under the GDPR requires that personal data be kept only as long as necessary for its stated purpose?
- Data minimization
- Purpose limitation
- Storage limitation (Correct answer)
- Integrity and confidentiality
Correct answer: Storage limitation
The storage limitation principle mandates that personal data not be retained longer than necessary for the purpose for which it was collected.
Question 5: An organization operating in California must comply with CCPA. Which right does CCPA grant to consumers regarding personal information held by businesses?
- Right to data portability only
- Right to know, delete, and opt-out of sale (Correct answer)
- Right to erasure and rectification
- Right to restrict automated processing
Correct answer: Right to know, delete, and opt-out of sale
CCPA grants California consumers the right to know what personal information is collected, the right to delete it, and the right to opt-out of its sale.
Question 6: Under HIPAA, which rule specifically establishes national standards for protecting electronic protected health information (ePHI)?
- Privacy Rule
- Security Rule (Correct answer)
- Breach Notification Rule
- Enforcement Rule
Correct answer: Security Rule
HIPAA's Security Rule sets national standards for safeguarding ePHI through administrative, physical, and technical safeguards.
Question 7: A company's board asks a CISO about Sarbanes-Oxley (SOX) Section 404 requirements. What does Section 404 primarily mandate?
- Mandatory cybersecurity incident disclosure within 72 hours
- Management assessment of internal controls over financial reporting (Correct answer)
- Annual penetration testing of financial systems
- CEO/CFO certification of cybersecurity posture
Correct answer: Management assessment of internal controls over financial reporting
SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting, with auditor attestation.
Under the EU General Data Protection Regulation (GDPR), what is the maximum fine for the most serious violations?