Compliance Standards Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Compliance Standards flashcards as text
Which NIST SP 800-53 control family directly governs identification and authentication requirements?
Answer: IA – Identification and Authentication
The IA control family in NIST SP 800-53 covers organizational identification and authentication policies, including multi-factor authentication.
Under CCPA, which right allows California consumers to request that a business delete their personal information?
Answer: Right to Delete
CCPA's Right to Delete allows consumers to request deletion of their personal information collected by a business, subject to certain exceptions.
ISO 27001 Annex A control A.9.2 specifically addresses which IAM process?
Answer: User access management (provisioning and deprovisioning)
ISO 27001 Annex A.9.2 covers user access management, including registration, deregistration, and review of access rights.
A quarterly access review where managers certify their team's entitlements is best described as which compliance control?
Answer: User access recertification (UAR)
User Access Recertification (UAR) is a periodic review process where data owners or managers certify that access rights remain appropriate.
Which regulation requires financial institutions to implement a comprehensive information security program and is enforced by the FTC?
Answer: GLBA Safeguards Rule
The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to protect customer financial information through a written security program.
In a GDPR context, what is the maximum timeframe for notifying supervisory authorities after discovering a personal data breach?
Answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Which CIS Control directly maps to managing access based on the principle of least privilege?
Answer: CIS Control 6 – Access Control Management
CIS Control 6 focuses on Access Control Management, including least privilege, limiting administrative rights, and centralizing access management.