CGRC Compliance and Policy 3 — Questions and Answers
Question 1: What is the primary purpose of a Regulatory Change Management process within a compliance program?
- To lobby regulators for favorable rule changes
- To track, assess, and implement changes to applicable laws and regulations (Correct answer)
- To report compliance violations to regulators proactively
- To eliminate outdated internal policies
Correct answer: To track, assess, and implement changes to applicable laws and regulations
Regulatory Change Management ensures the organization identifies, evaluates, and responds to new or amended regulations affecting its operations.
Question 2: A healthcare organization must comply with both HIPAA and state privacy laws that are stricter than HIPAA. Which standard should govern their compliance program?
- HIPAA, because federal law preempts state law
- The state law, because it provides greater protection to individuals (Correct answer)
- Whichever standard is less costly to implement
- They must comply with HIPAA only and ignore stricter state requirements
Correct answer: The state law, because it provides greater protection to individuals
HIPAA allows states to enact stricter privacy protections, and organizations must comply with the more stringent standard.
Question 3: Which element is MOST critical to include in an organization's written information security policy?
- Specific vendor names and product versions
- Scope, roles, responsibilities, and enforcement mechanisms (Correct answer)
- A list of all known threats in the industry
- The organization's marketing strategy
Correct answer: Scope, roles, responsibilities, and enforcement mechanisms
Effective security policies must define scope, assign roles and responsibilities, and specify how the policy will be enforced.
Question 4: Under GDPR, what is the maximum timeframe for notifying a supervisory authority after discovering a personal data breach?
- 24 hours
- 72 hours (Correct answer)
- 7 days
- 30 days
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 5: An organization's compliance policy requires annual vendor due diligence reviews. A critical vendor's contract renews mid-year without a review. This BEST represents which type of compliance failure?
- A design deficiency in the policy
- An operational failure to execute a defined control (Correct answer)
- A regulatory gap in applicable law
- An approved policy exception
Correct answer: An operational failure to execute a defined control
The policy (design) is sound, but the failure to execute the review on schedule is an operational control failure.
Question 6: What is the role of 'tone at the top' in an effective compliance program?
- It refers to the volume level of compliance training sessions
- Senior leadership visibly demonstrating commitment to ethical conduct and compliance (Correct answer)
- The compliance officer's communication style with regulators
- The decibel level of security alarms in the facility
Correct answer: Senior leadership visibly demonstrating commitment to ethical conduct and compliance
Tone at the top means senior leadership models and champions ethical behavior, which is a foundational driver of organizational compliance culture.
Question 7: Which compliance framework is MOST commonly used as a baseline for US federal government contractors handling controlled unclassified information (CUI)?
- ISO 27001
- NIST SP 800-171 (Correct answer)
- PCI DSS
- COBIT 2019
Correct answer: NIST SP 800-171
NIST SP 800-171 defines the security requirements for protecting CUI in non-federal systems and is required for most federal contractors.
What is the primary purpose of a Regulatory Change Management process within a compliance program?