CGEIT IT Compliance and Assurance 2 — Questions and Answers
Question 1: HIPAA compliance MOST directly impacts IT governance in organizations that handle:
- Protected health information (PHI) stored or transmitted electronically (Correct answer)
- Financial transaction data for public companies
- Federal government classified data
- Consumer credit reporting data
Correct answer: Protected health information (PHI) stored or transmitted electronically
HIPAA's Security Rule specifically governs IT controls over electronic protected health information, requiring encryption, access controls, and audit trails.
Question 2: An organization's IT governance framework should treat compliance MOST appropriately as:
- A minimum baseline, with governance aiming to deliver additional value beyond compliance (Correct answer)
- The ultimate goal of IT governance efforts
- A task solely delegated to the legal department
- An obstacle that limits IT innovation
Correct answer: A minimum baseline, with governance aiming to deliver additional value beyond compliance
Compliance represents the floor, not the ceiling — good IT governance meets compliance requirements while also driving value creation and strategic alignment.
Question 3: Which IT governance practice BEST demonstrates proactive compliance management?
- Continuously monitoring regulatory changes and updating controls before deadlines (Correct answer)
- Responding to compliance findings only after an external audit
- Delegating all compliance responsibilities to IT staff
- Conducting compliance assessments every three years
Correct answer: Continuously monitoring regulatory changes and updating controls before deadlines
Proactive compliance management means staying ahead of regulatory changes and updating controls before requirements take effect, not reacting after audits.
Question 4: An IT organization is found to be SOX-compliant but experiences repeated data breaches. This MOST likely indicates:
- Compliance does not guarantee adequate security controls beyond regulatory minimums (Correct answer)
- SOX requirements are too strict for practical implementation
- The organization needs to abandon its IT governance framework
- Data breach responsibility lies entirely with the cybersecurity team
Correct answer: Compliance does not guarantee adequate security controls beyond regulatory minimums
SOX compliance addresses financial reporting controls, not comprehensive cybersecurity — meeting one compliance standard does not ensure security in all areas.
Question 5: A third-party SOC 2 report PRIMARILY provides assurance about a service provider's:
- Controls over security, availability, processing integrity, confidentiality, and privacy (Correct answer)
- Financial performance and profitability
- Staff qualifications and training certifications
- Physical data center locations
Correct answer: Controls over security, availability, processing integrity, confidentiality, and privacy
A SOC 2 report provides independent assurance that a service provider's controls meet the Trust Services Criteria covering security, availability, and related principles.
Question 6: Which role is MOST responsible for ensuring IT governance compliance with regulatory requirements?
- Chief Information Officer (CIO) and senior IT governance leadership (Correct answer)
- Individual IT developers
- External auditors who conduct annual reviews
- Network operations center staff
Correct answer: Chief Information Officer (CIO) and senior IT governance leadership
The CIO and senior IT governance leadership are accountable for ensuring IT practices meet regulatory requirements — they cannot delegate that accountability.
HIPAA compliance MOST directly impacts IT governance in organizations that handle: