CCP IT Governance, Risk & Compliance Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCP IT Governance, Risk & Compliance flashcards as text
ISO/IEC 27001 is an international standard for:
Answer: Information security management systems (ISMS)
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system.
Which compliance regulation specifically protects the privacy of US patients' health information?
Answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) establishes national standards for protecting sensitive patient health information in the US.
A security audit trail is primarily used to:
Answer: Record user activities and system events for accountability and forensic review
Audit trails create a chronological record of system activities enabling detection of unauthorized actions and supporting incident investigation and compliance.
The principle of least privilege means:
Answer: Users should be granted only the minimum access rights necessary to perform their job
The principle of least privilege limits user and system access rights to the bare minimum required for their role, reducing the attack surface.
PCI DSS compliance is required for organizations that:
Answer: Store, process, or transmit payment card data
PCI DSS (Payment Card Industry Data Security Standard) applies to any entity that handles cardholder data to protect against payment fraud.
Which IT governance framework uses a balanced scorecard approach to measure IT performance across four perspectives?
Answer: COBIT
COBIT incorporates balanced scorecard concepts, measuring IT performance from financial, customer, internal process, and learning/growth perspectives.