CIAM Compliance Standards 2 — Questions and Answers
Question 1: Under HIPAA's Security Rule, which safeguard category requires covered entities to implement access control policies for electronic PHI?
- Physical safeguards
- Technical safeguards (Correct answer)
- Administrative safeguards
- Operational safeguards
Correct answer: Technical safeguards
HIPAA Technical Safeguards mandate access controls, audit controls, integrity controls, and transmission security for ePHI systems.
Question 2: Which PCI DSS requirement specifically addresses the need to assign a unique ID to each person with computer access?
- Requirement 6
- Requirement 8 (Correct answer)
- Requirement 10
- Requirement 12
Correct answer: Requirement 8
PCI DSS Requirement 8 covers identification and authentication of access to system components, including assigning unique IDs.
Question 3: SOX Section 404 compliance primarily requires organizations to do which of the following related to IAM?
- Encrypt all financial data at rest
- Assess and report on internal controls over financial reporting (Correct answer)
- Conduct annual penetration testing
- Implement multi-factor authentication for all users
Correct answer: Assess and report on internal controls over financial reporting
SOX Section 404 mandates management assessment and auditor attestation of internal controls over financial reporting, including access controls.
Question 4: The GDPR principle of 'data minimization' most directly influences which IAM practice?
- Password complexity requirements
- Least privilege access provisioning (Correct answer)
- Single sign-on implementation
- Identity federation across domains
Correct answer: Least privilege access provisioning
Data minimization aligns with least privilege by ensuring users only access the minimum data necessary for their role.
Question 5: Which compliance framework introduced the concept of 'segregation of duties' as a key control for preventing fraud in financial systems?
- ISO 27001
- NIST SP 800-53
- Sarbanes-Oxley Act (SOX) (Correct answer)
- FISMA
Correct answer: Sarbanes-Oxley Act (SOX)
SOX heavily emphasizes segregation of duties as an internal control to prevent a single individual from controlling all aspects of a financial transaction.
Question 6: Under FedRAMP, cloud service providers must implement identity controls based on which underlying framework?
- PCI DSS
- NIST SP 800-53 (Correct answer)
- ISO 27001
- CIS Controls
Correct answer: NIST SP 800-53
FedRAMP uses NIST SP 800-53 security controls as its foundation, including the AC (Access Control) and IA (Identification and Authentication) control families.
Question 7: A company must prove that terminated employees lose system access within 24 hours. Which compliance activity best demonstrates this?
- Firewall rule review
- User access recertification campaign
- Joiner-mover-leaver process audit log review (Correct answer)
- Vulnerability scan report
Correct answer: Joiner-mover-leaver process audit log review
Reviewing joiner-mover-leaver (JML) process audit logs shows the timestamps of deprovisioning actions relative to termination events.
Under HIPAA's Security Rule, which safeguard category requires covered entities to implement access control policies for electronic PHI?