CGRC Regulatory Requirements 5 — Questions and Answers
Question 1: Which NIST publication provides a voluntary framework for organizations to manage and reduce cybersecurity risk, widely referenced in regulatory compliance contexts?
- NIST SP 800-53
- NIST SP 800-37
- NIST Cybersecurity Framework (CSF) (Correct answer)
- NIST SP 800-171
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) provides a voluntary, risk-based approach to managing cybersecurity risk, organized around five core functions: Identify, Protect, Detect, Respond, and Recover.
Question 2: Under GDPR, a Data Protection Impact Assessment (DPIA) is required when processing is likely to result in high risk. Which scenario most clearly triggers a mandatory DPIA?
- Processing employee payroll data
- Large-scale systematic monitoring of publicly accessible areas (Correct answer)
- Storing customer email addresses for marketing
- Processing data of fewer than 500 individuals
Correct answer: Large-scale systematic monitoring of publicly accessible areas
GDPR Article 35 requires a DPIA for large-scale systematic monitoring of publicly accessible areas, as this type of processing is likely to result in high risk to individuals' rights.
Question 3: The New York State Department of Financial Services (NYDFS) Cybersecurity Regulation (23 NYCRR 500) requires covered entities to designate which role?
- Chief Information Officer (CIO)
- Chief Security Officer (CSO)
- Chief Information Security Officer (CISO) (Correct answer)
- Data Protection Officer (DPO)
Correct answer: Chief Information Security Officer (CISO)
NYDFS 23 NYCRR 500 requires covered entities to designate a qualified Chief Information Security Officer (CISO) responsible for overseeing and implementing the cybersecurity program.
Question 4: Under the EU-U.S. Data Privacy Framework, what mechanism allows U.S. organizations to lawfully transfer personal data from the EU?
- Binding Corporate Rules
- Standard Contractual Clauses
- Self-certification to the DPF program (Correct answer)
- Adequacy decision by individual member states
Correct answer: Self-certification to the DPF program
U.S. organizations can lawfully receive personal data from the EU by self-certifying to the EU-U.S. Data Privacy Framework administered by the U.S. Department of Commerce.
Question 5: ISO/IEC 27001 requires organizations to establish, implement, maintain, and continually improve what type of system?
- Quality management system
- Information security management system (ISMS) (Correct answer)
- Business continuity management system
- Risk management framework
Correct answer: Information security management system (ISMS)
ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
Question 6: The Health Information Technology for Economic and Clinical Health (HITECH) Act strengthened HIPAA enforcement primarily by:
- Expanding the definition of covered entities
- Increasing civil and criminal penalties and extending requirements to business associates (Correct answer)
- Introducing new categories of PHI
- Mandating security risk assessments for all healthcare providers
Correct answer: Increasing civil and criminal penalties and extending requirements to business associates
HITECH significantly increased civil and criminal penalties for HIPAA violations and extended HIPAA's privacy and security requirements directly to business associates.
Question 7: Under the NIST Risk Management Framework (RMF), which step involves selecting and documenting the security controls for an information system?
- Categorize
- Select (Correct answer)
- Implement
- Assess
Correct answer: Select
The Select step in the NIST RMF involves choosing the appropriate security controls from NIST SP 800-53 based on the system's impact categorization and documenting them in the security plan.
Which NIST publication provides a voluntary framework for organizations to manage and reduce cybersecurity risk, widely referenced in regulatory compliance contexts?