CCISO Legal and Regulatory 4 — Questions and Answers
Question 1: A CISO must understand the concept of 'safe harbor' in data privacy law. In the context of GDPR, which mechanism serves as a safe harbor for transferring personal data to the US?
- Privacy Shield (currently valid)
- Standard Contractual Clauses (SCCs) (Correct answer)
- Binding Safe Harbor Agreement
- APEC Cross-Border Privacy Rules
Correct answer: Standard Contractual Clauses (SCCs)
Following the invalidation of Privacy Shield by Schrems II, Standard Contractual Clauses (SCCs) are the primary mechanism for lawful EU-to-US personal data transfers.
Question 2: Which legal concept holds that an organization can be held liable for damages caused by third-party vendors who handle their customers' data?
- Contributory negligence
- Vicarious liability (Correct answer)
- Strict liability
- Respondeat superior
Correct answer: Vicarious liability
Vicarious liability can hold an organization responsible for the actions or negligence of third parties acting on its behalf, including data processors and vendors.
Question 3: Under FISMA (Federal Information Security Management Act), federal agencies must categorize information systems using which framework?
- NIST CSF
- FIPS 199 (Correct answer)
- COBIT 5
- ISO 27005
Correct answer: FIPS 199
FIPS 199 (Standards for Security Categorization of Federal Information and Information Systems) provides the framework for categorizing systems as low, moderate, or high impact.
Question 4: A CISO at a healthcare organization learns of a breach affecting 600 unsecured PHI records. Under HIPAA Breach Notification Rule, what notification is required within 60 days of the end of the calendar year?
- Immediate individual notification
- Notification to HHS and prominent media outlets
- Annual summary to HHS only (Correct answer)
- Notification to HHS only
Correct answer: Annual summary to HHS only
For breaches affecting fewer than 500 individuals, HIPAA requires covered entities to notify HHS annually within 60 days of the end of each calendar year.
Question 5: The Electronic Communications Privacy Act (ECPA) restricts government access to electronic communications. Which part of ECPA specifically governs stored communications and data at rest?
- Title I – Wiretap Act
- Title II – Stored Communications Act (Correct answer)
- Title III – Pen Register Act
- Title IV – Electronic Surveillance Act
Correct answer: Title II – Stored Communications Act
Title II of ECPA, known as the Stored Communications Act (SCA), governs government access to stored electronic communications and subscriber data held by third-party providers.
Question 6: In the context of intellectual property law, which type of protection applies to software source code and documentation by default upon creation?
- Patent
- Trademark
- Copyright (Correct answer)
- Trade secret
Correct answer: Copyright
Copyright protection attaches automatically to original works including software source code the moment they are created and fixed in a tangible medium.
Question 7: A CISO is drafting a vendor contract and wants to include language addressing regulatory compliance failures. Which contract clause specifically allocates responsibility and financial exposure for compliance violations between parties?
- Indemnification clause (Correct answer)
- Force majeure clause
- Limitation of liability clause
- Service level agreement (SLA)
Correct answer: Indemnification clause
An indemnification clause allocates financial responsibility by requiring one party to compensate the other for losses arising from regulatory violations, breaches, or negligence.
A CISO must understand the concept of 'safe harbor' in data privacy law.
In the context of GDPR, which mechanism serves as a safe harbor for transferring personal data to the US?