CCISO Legal and Regulatory 3 — Questions and Answers
Question 1: Which international standard provides a framework for information security management systems (ISMS) and is most commonly cited in regulatory compliance contexts?
- ISO 27001 (Correct answer)
- ISO 31000
- ISO 22301
- ISO 9001
Correct answer: ISO 27001
ISO 27001 is the international standard specifying requirements for establishing, implementing, maintaining, and continually improving an ISMS.
Question 2: The Computer Fraud and Abuse Act (CFAA) primarily criminalizes which type of activity?
- Unauthorized access to protected computers (Correct answer)
- Failure to encrypt sensitive data
- Non-disclosure of data breaches
- Misuse of intellectual property
Correct answer: Unauthorized access to protected computers
The CFAA makes it a federal crime to access a protected computer without authorization or in excess of authorized access.
Question 3: Under GDPR, a data breach must be reported to the supervisory authority within what timeframe after the controller becomes aware of it?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires data controllers to notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it.
Question 4: Which US federal law established the framework for protecting critical infrastructure information shared between the private sector and the government?
- FISMA
- CISA 2015 (Correct answer)
- PATRIOT Act
- E-Government Act
Correct answer: CISA 2015
The Cybersecurity Information Sharing Act (CISA) of 2015 established protections and procedures for sharing cyber threat indicators between private entities and the federal government.
Question 5: A CISO must ensure compliance with PCI DSS. Which entity mandates PCI DSS compliance for organizations handling cardholder data?
- Federal Trade Commission (FTC)
- Payment Card Industry Security Standards Council (PCI SSC) (Correct answer)
- National Institute of Standards and Technology (NIST)
- Department of Homeland Security (DHS)
Correct answer: Payment Card Industry Security Standards Council (PCI SSC)
The PCI SSC, founded by major card brands, develops and manages PCI DSS, which applies to all entities that store, process, or transmit cardholder data.
Question 6: The EU NIS2 Directive expanded the scope of cybersecurity obligations compared to the original NIS Directive. Which new obligation does NIS2 specifically add for top management?
- Mandatory ISO 27001 certification
- Personal liability of executives for cybersecurity failures (Correct answer)
- Annual board-level penetration testing reviews
- Mandatory CISO appointment in all sectors
Correct answer: Personal liability of executives for cybersecurity failures
NIS2 holds top management personally liable and can impose temporary bans on managerial roles for cybersecurity negligence causing serious incidents.
Question 7: Under GLBA (Gramm-Leach-Bliley Act), which rule requires financial institutions to develop, implement, and maintain a comprehensive information security program?
- Financial Privacy Rule
- Safeguards Rule (Correct answer)
- Pretexting Provisions
- Fair Credit Rule
Correct answer: Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to implement a written comprehensive information security program to protect customer financial information.
Which international standard provides a framework for information security management systems (ISMS) and is most commonly cited in regulatory compliance contexts?