CGRC Compliance and Policy 5 — Questions and Answers
Question 1: Under the NIST Cybersecurity Framework, which function focuses on developing an organizational understanding of cybersecurity risk to systems, assets, data, and capabilities?
- Protect
- Detect
- Identify (Correct answer)
- Respond
Correct answer: Identify
The Identify function encompasses asset management, business environment, governance, risk assessment, and risk management strategy.
Question 2: A financial services firm is subject to the Gramm-Leach-Bliley Act (GLBA). Which rule requires the firm to implement a comprehensive information security program?
- The Privacy Rule
- The Safeguards Rule (Correct answer)
- The Pretexting Rule
- The Disclosure Rule
Correct answer: The Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security program.
Question 3: What is the PRIMARY goal of a compliance training needs assessment?
- To determine the compliance officer's salary requirements
- To identify which employee groups face which compliance risks and tailor training accordingly (Correct answer)
- To assess how much time employees spend on compliance activities
- To evaluate the effectiveness of the legal department
Correct answer: To identify which employee groups face which compliance risks and tailor training accordingly
A training needs assessment maps compliance risk exposure by role or function so training content and frequency can be appropriately targeted.
Question 4: When documenting a compliance policy, which attribute is MOST important to include to ensure the policy remains enforceable and current?
- The names of all employees who reviewed the policy
- Version number, effective date, review date, and policy owner (Correct answer)
- The full text of all applicable regulations
- A list of every system the policy governs
Correct answer: Version number, effective date, review date, and policy owner
Version control, effective and review dates, and an identified owner ensure the policy can be tracked, maintained, and enforced over time.
Question 5: Which of the following is an example of a preventive compliance control?
- Reviewing access logs after a data breach
- Conducting a post-incident lessons-learned session
- Requiring dual authorization for wire transfers over a threshold (Correct answer)
- Generating monthly compliance reports for management
Correct answer: Requiring dual authorization for wire transfers over a threshold
Dual authorization prevents unauthorized transactions from occurring in the first place, making it a preventive rather than detective or corrective control.
Question 6: A compliance officer is assessing third-party risk. Which factor MOST significantly increases the compliance risk associated with a vendor?
- The vendor is located in the same city as the organization
- The vendor has access to sensitive customer data and operates in a jurisdiction with weak data protection laws (Correct answer)
- The vendor provides a commodity service such as office supplies
- The vendor has been a business partner for more than ten years
Correct answer: The vendor has access to sensitive customer data and operates in a jurisdiction with weak data protection laws
Access to sensitive data combined with weak jurisdictional protections creates the highest compliance and data protection risk in third-party relationships.
Question 7: Under PCI DSS, which of the following entities is responsible for validating compliance of service providers that store, process, or transmit cardholder data on behalf of merchants?
- The merchant alone bears all responsibility
- The service provider must validate its own compliance, often through a QSA assessment or SAQ (Correct answer)
- The card brands validate compliance directly with no involvement from the merchant
- Compliance validation is optional for service providers
Correct answer: The service provider must validate its own compliance, often through a QSA assessment or SAQ
PCI DSS requires service providers to validate their own compliance status, typically via a Qualified Security Assessor (QSA) Report on Compliance or applicable SAQ.
Under the NIST Cybersecurity Framework, which function focuses on developing an organizational understanding of cybersecurity risk to systems, assets, data, and capabilities?