CDIA Compliance Standards 2 — Questions and Answers
Question 1: Under HIPAA, what is the maximum civil monetary penalty per violation category for 'willful neglect — not corrected'?
- $10,000
- $50,000
- $1,000,000
- $1,919,173 (Correct answer)
Correct answer: $1,919,173
HIPAA civil penalties for willful neglect not corrected are capped at $1,919,173 per violation category per year (adjusted for inflation).
Question 2: Which NIST publication provides the Risk Management Framework (RMF) used to guide federal information system security compliance?
- NIST SP 800-53
- NIST SP 800-37 (Correct answer)
- NIST SP 800-171
- NIST SP 800-30
Correct answer: NIST SP 800-37
NIST SP 800-37 defines the Risk Management Framework (RMF) for federal information systems.
Question 3: A document imaging system must retain financial audit records for seven years to satisfy which US regulation?
- Gramm-Leach-Bliley Act
- Sarbanes-Oxley Act Section 802 (Correct answer)
- FISMA
- COPPA
Correct answer: Sarbanes-Oxley Act Section 802
SOX Section 802 mandates retention of audit-related records for seven years.
Question 4: What does the concept of 'legal hold' require in the context of document imaging compliance?
- Encrypting all documents at rest
- Suspending the routine disposition of documents relevant to litigation or investigation (Correct answer)
- Converting paper documents to TIFF format
- Applying retention schedules to all new records
Correct answer: Suspending the routine disposition of documents relevant to litigation or investigation
A legal hold suspends normal destruction and disposition schedules for records potentially relevant to litigation or government investigation.
Question 5: Which standard defines requirements for the trustworthiness of digital records specifically in a legal context, often cited in US court admissibility?
- ISO 15489
- ANSI/AIIM MS53
- Federal Rules of Evidence Rule 902(13) (Correct answer)
- DoD 5015.02
Correct answer: Federal Rules of Evidence Rule 902(13)
Federal Rules of Evidence Rule 902(13) addresses self-authentication of electronic records generated by an electronic process or system.
Question 6: In a CDIA context, what is the primary purpose of an audit trail in a document management system?
- To compress document file sizes
- To provide a chronological record of who accessed, modified, or deleted documents (Correct answer)
- To automatically apply OCR to scanned images
- To route documents through approval workflows
Correct answer: To provide a chronological record of who accessed, modified, or deleted documents
Audit trails create a tamper-evident chronological log of all document activities, supporting compliance and legal defensibility.
Question 7: Which regulation requires US federal agencies to manage their records according to approved schedules and transfer permanent records to the National Archives?
- FISMA
- Federal Records Act (44 U.S.C. Chapter 31) (Correct answer)
- Privacy Act of 1974
- E-Government Act
Correct answer: Federal Records Act (44 U.S.C. Chapter 31)
The Federal Records Act (44 U.S.C. Chapter 31) establishes requirements for federal records management including disposition and transfer to NARA.
Under HIPAA, what is the maximum civil monetary penalty per violation category for 'willful neglect — not corrected'?