CGRC Compliance and Policy 2 — Questions and Answers
Question 1: Which regulation requires US federal agencies to implement risk-based information security programs and report to Congress annually?
- HIPAA
- FISMA (Correct answer)
- SOX
- GLBA
Correct answer: FISMA
FISMA (Federal Information Security Modernization Act) mandates risk-based security programs and annual congressional reporting for federal agencies.
Question 2: A company discovers that an employee has been sharing customer PII with an unauthorized third party. Under a compliance framework, what is the FIRST action the compliance officer should take?
- Terminate the employee immediately
- Notify law enforcement
- Invoke the incident response plan (Correct answer)
- Issue a press release
Correct answer: Invoke the incident response plan
Invoking the incident response plan ensures a structured, documented approach to containing and assessing the breach before other actions.
Question 3: What does the term 'policy exception' refer to in a compliance program?
- A permanent waiver of all policy requirements
- A documented deviation from policy with defined compensating controls and approval (Correct answer)
- An undocumented workaround approved verbally by management
- A policy that applies only to senior executives
Correct answer: A documented deviation from policy with defined compensating controls and approval
A policy exception is a formally documented, approved deviation that includes compensating controls and a defined expiration date.
Question 4: Which component ensures that employees understand their compliance obligations before they can access systems or data?
- Data loss prevention (DLP)
- Security awareness training and acknowledgment (Correct answer)
- Network segmentation
- Patch management
Correct answer: Security awareness training and acknowledgment
Security awareness training with acknowledgment signatures ensures employees are informed of and accountable for compliance obligations.
Question 5: Under SOX Section 302, who is primarily responsible for certifying the accuracy of financial disclosures?
- External auditors
- The board of directors
- CEO and CFO (Correct answer)
- The compliance officer
Correct answer: CEO and CFO
SOX Section 302 requires the CEO and CFO to personally certify the accuracy of financial statements and internal controls.
Question 6: A policy states that all passwords must be changed every 90 days. An employee with a disability cannot remember frequently changing passwords. What is the BEST compliance approach?
- Grant a permanent policy exception with no compensating controls
- Deny any accommodation and enforce the policy strictly
- Document a formal exception with compensating controls such as MFA (Correct answer)
- Remove the password requirement entirely for that employee
Correct answer: Document a formal exception with compensating controls such as MFA
A documented exception with compensating controls like MFA maintains security intent while accommodating the employee's needs.
Question 7: Which of the following BEST describes the purpose of a compliance monitoring program?
- To replace internal audits entirely
- To detect policy violations and assess control effectiveness on an ongoing basis (Correct answer)
- To create new compliance policies annually
- To train employees on regulatory requirements
Correct answer: To detect policy violations and assess control effectiveness on an ongoing basis
Compliance monitoring provides continuous assessment of whether controls are operating effectively and policies are being followed.
Which regulation requires US federal agencies to implement risk-based information security programs and report to Congress annually?