CGRC Regulatory Requirements 2 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act (SOX), which section requires management to assess and report on the effectiveness of internal controls over financial reporting?
- Section 302
- Section 404 (Correct answer)
- Section 409
- Section 906
Correct answer: Section 404
SOX Section 404 mandates that management assess and report on the effectiveness of internal controls over financial reporting, with external auditor attestation.
Question 2: Which regulation primarily governs the privacy and security of protected health information (PHI) held by covered entities in the United States?
- GLBA
- FERPA
- HIPAA (Correct answer)
- COPPA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) establishes national standards for protecting PHI held by covered entities and their business associates.
Question 3: The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to implement which type of program?
- Business continuity program
- Information security program (Correct answer)
- Anti-money laundering program
- Vendor management program
Correct answer: Information security program
The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security program to protect customer financial data.
Question 4: Under GDPR, what is the maximum timeframe within which a data breach must be reported to the supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires that personal data breaches be reported to the supervisory authority within 72 hours of becoming aware of the breach, where feasible.
Question 5: Which federal law requires U.S. federal agencies to develop, document, and implement agency-wide programs to secure their information systems?
- FISMA (Correct answer)
- CISA
- NIST CSF
- FedRAMP
Correct answer: FISMA
The Federal Information Security Management Act (FISMA) requires federal agencies to develop, implement, and maintain information security programs for their systems.
Question 6: PCI DSS Requirement 6 focuses on which security domain?
- Restricting access to cardholder data
- Developing and maintaining secure systems and software (Correct answer)
- Encrypting transmission of cardholder data
- Protecting stored cardholder data
Correct answer: Developing and maintaining secure systems and software
PCI DSS Requirement 6 addresses developing and maintaining secure systems and applications, including patch management and secure coding practices.
Question 7: Which HIPAA rule specifically addresses the electronic exchange of health information and establishes national standards for electronic healthcare transactions?
- Privacy Rule
- Security Rule
- Transactions and Code Sets Rule (Correct answer)
- Breach Notification Rule
Correct answer: Transactions and Code Sets Rule
The HIPAA Transactions and Code Sets Rule establishes standardized formats for electronic health information exchange, such as claims and remittance advices.
Under the Sarbanes-Oxley Act (SOX), which section requires management to assess and report on the effectiveness of internal controls over financial reporting?