CISM Compliance and Regulatory Requirements 1 — Questions and Answers
Question 1: Which US federal law PRIMARILY governs the protection of personal health information in the healthcare industry?
- Sarbanes-Oxley Act (SOX)
- Health Insurance Portability and Accountability Act (HIPAA) (Correct answer)
- Gramm-Leach-Bliley Act (GLBA)
- Children's Online Privacy Protection Act (COPPA)
Correct answer: Health Insurance Portability and Accountability Act (HIPAA)
HIPAA establishes federal standards for protecting the privacy and security of individually identifiable health information in the US healthcare industry.
Question 2: A CISM is developing a compliance program. The FIRST step should be to:
- Purchase GRC (governance, risk, compliance) software
- Identify all applicable laws, regulations, and contractual obligations (Correct answer)
- Conduct an internal audit of all existing controls
- Assign compliance responsibilities to the legal team only
Correct answer: Identify all applicable laws, regulations, and contractual obligations
Identifying all applicable regulatory, legal, and contractual requirements is the foundational step before any compliance program activities can be structured.
Question 3: Under the Sarbanes-Oxley Act (SOX), which of the following is a KEY information security requirement?
- Encryption of all employee communications
- Internal controls over financial reporting, including IT general controls (Correct answer)
- Annual penetration testing of all public-facing systems
- Mandatory security awareness training for all employees
Correct answer: Internal controls over financial reporting, including IT general controls
SOX requires organizations to establish and maintain internal controls over financial reporting, which includes IT general controls that protect the integrity of financial systems.
Question 4: Which of the following is MOST important when mapping security controls to regulatory requirements?
- Implementing a separate set of controls for each regulation
- Using a unified control framework to address multiple requirements efficiently (Correct answer)
- Delegating control mapping entirely to external auditors
- Focusing only on the most recent regulatory guidance
Correct answer: Using a unified control framework to address multiple requirements efficiently
A unified control framework maps controls to multiple regulations simultaneously, reducing duplication and improving efficiency across compliance programs.
Question 5: Which of the following BEST describes the difference between a regulation and a standard in the context of compliance?
- Regulations are optional; standards are mandatory
- Regulations are legally mandated by governments; standards are typically voluntary industry guidelines (Correct answer)
- Standards are enforced by government agencies; regulations are created by industry groups
- There is no practical difference between regulations and standards
Correct answer: Regulations are legally mandated by governments; standards are typically voluntary industry guidelines
Regulations are legally enforceable requirements imposed by government authorities, while standards are generally voluntary guidelines developed by industry bodies.
Question 6: The Payment Card Industry Data Security Standard (PCI DSS) applies to organizations that:
- Process payroll for more than 500 employees
- Store, process, or transmit cardholder data (Correct answer)
- Operate in the financial services sector only
- Issue credit cards directly to consumers
Correct answer: Store, process, or transmit cardholder data
PCI DSS applies to any organization that stores, processes, or transmits payment card data, regardless of industry or size.
Which US federal law PRIMARILY governs the protection of personal health information in the healthcare industry?