CCISO Legal and Regulatory 5 — Questions and Answers
Question 1: Under the Children's Online Privacy Protection Act (COPPA), parental consent is required before collecting personal information from children under what age?
- 13 (Correct answer)
- 16
- 18
- 14
Correct answer: 13
COPPA requires verifiable parental consent before collecting, using, or disclosing personal information from children under age 13.
Question 2: A multinational company undergoes an M&A transaction. From a legal and compliance standpoint, which due diligence area is most critical from a CISO's perspective?
- Reviewing the target's marketing strategy
- Assessing inherited cybersecurity liabilities and regulatory obligations (Correct answer)
- Evaluating the target's hardware asset inventory
- Auditing the target's HR policies
Correct answer: Assessing inherited cybersecurity liabilities and regulatory obligations
During M&A due diligence, the acquiring company must assess inherited cybersecurity vulnerabilities, data breaches, regulatory violations, and compliance obligations of the target.
Question 3: Which US executive order significantly shaped federal cybersecurity requirements for critical infrastructure and established information-sharing between the private sector and government?
- EO 13556
- EO 13636
- EO 14028 (Correct answer)
- EO 13800
Correct answer: EO 14028
Executive Order 14028 (2021) on Improving the Nation's Cybersecurity modernized federal security standards, mandated zero trust architecture, and enhanced software supply chain security.
Question 4: The concept of 'privacy by design' requires organizations to embed privacy protections into systems from the outset. Which GDPR article explicitly codifies this requirement?
- Article 5
- Article 17
- Article 25 (Correct answer)
- Article 32
Correct answer: Article 25
GDPR Article 25 mandates Data Protection by Design and by Default, requiring controllers to integrate data protection into processing activities from the design stage.
Question 5: Under securities law, a CISO learns of a material cybersecurity incident affecting a publicly traded company. The SEC's 2023 cybersecurity disclosure rules require public disclosure within how many business days?
- 3 business days
- 4 business days (Correct answer)
- 10 business days
- 15 business days
Correct answer: 4 business days
The SEC's 2023 cybersecurity rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality.
Question 6: A CISO must understand e-discovery obligations. Under the Federal Rules of Civil Procedure (FRCP), electronically stored information (ESI) must be preserved when which obligation arises?
- When a lawsuit is filed in court
- When litigation is reasonably anticipated (Correct answer)
- When a regulatory investigation begins
- When a subpoena is formally received
Correct answer: When litigation is reasonably anticipated
The litigation hold duty to preserve ESI arises when litigation is reasonably anticipated, before a lawsuit is actually filed or a subpoena received.
Question 7: Which legal doctrine protects confidential communications between an attorney and client, and may shield legal counsel's cybersecurity assessments from disclosure in litigation?
- Work product doctrine
- Attorney-client privilege (Correct answer)
- Executive privilege
- Common interest privilege
Correct answer: Attorney-client privilege
Attorney-client privilege protects confidential communications between attorney and client made for the purpose of seeking or providing legal advice, potentially including security assessments.
Under the Children's Online Privacy Protection Act (COPPA), parental consent is required before collecting personal information from children under what age?