CISM Compliance and Regulatory Requirements 2 — Questions and Answers
Question 1: A CISM discovers that a new business initiative will require processing of EU citizen data. Which regulation MUST be considered?
- HIPAA
- GLBA
- GDPR (Correct answer)
- FISMA
Correct answer: GDPR
The General Data Protection Regulation (GDPR) applies to any organization processing personal data of EU residents, regardless of where the organization is located.
Question 2: Which of the following is the PRIMARY purpose of a compliance audit?
- To identify all technical vulnerabilities in the organization's systems
- To assess whether the organization's controls meet applicable requirements (Correct answer)
- To evaluate the efficiency of the IT department's operations
- To test employee knowledge of security policies
Correct answer: To assess whether the organization's controls meet applicable requirements
A compliance audit evaluates whether an organization's controls, processes, and practices meet the requirements of applicable laws, regulations, or standards.
Question 3: A CISM is informed that regulatory requirements in the organization's industry have changed. The MOST appropriate response is to:
- Wait until the next scheduled audit to assess the impact
- Immediately conduct a gap analysis to identify required changes to controls and processes (Correct answer)
- Outsource all compliance activities to a third-party firm
- Notify the board only after all required changes are implemented
Correct answer: Immediately conduct a gap analysis to identify required changes to controls and processes
A prompt gap analysis identifies what the new requirements demand and where current controls fall short, enabling timely and prioritized remediation.
Question 4: Which of the following BEST describes a 'control deficiency' in a compliance context?
- A security tool that has been deprecated by the vendor
- A failure of a control to operate as intended or meet a required standard (Correct answer)
- An employee who has violated an acceptable use policy
- A regulatory requirement that the organization believes is excessive
Correct answer: A failure of a control to operate as intended or meet a required standard
A control deficiency is a gap where a control either doesn't exist, fails to operate as designed, or fails to meet the required standard.
Question 5: The Federal Information Security Modernization Act (FISMA) PRIMARILY applies to:
- All US companies with more than 100 employees
- US federal agencies and contractors that handle federal information (Correct answer)
- Financial institutions regulated by the Federal Reserve
- Healthcare organizations billing Medicare or Medicaid
Correct answer: US federal agencies and contractors that handle federal information
FISMA applies to US federal agencies and contractors that handle federal information, requiring them to develop, document, and implement information security programs.
Question 6: A CISM is tasked with reducing compliance costs while maintaining all required standards. The BEST approach is to:
- Reduce the number of regulations the organization monitors
- Implement a common controls framework to satisfy multiple requirements simultaneously (Correct answer)
- Negotiate with regulators for reduced audit frequency
- Outsource all compliance functions to reduce internal headcount
Correct answer: Implement a common controls framework to satisfy multiple requirements simultaneously
A common controls framework identifies controls that satisfy multiple regulatory requirements simultaneously, reducing redundancy and overall compliance costs.
A CISM discovers that a new business initiative will require processing of EU citizen data.
Which regulation MUST be considered?