CISSP CISSP Legal and Compliance 2 — Questions and Answers
Question 1: What does the term 'due diligence' mean in the context of information security governance?
- Implementing security controls after a breach occurs
- Investigating and verifying security practices before entering a business relationship (Correct answer)
- Conducting annual security awareness training
- Following the minimum legal requirements for data protection
Correct answer: Investigating and verifying security practices before entering a business relationship
Due diligence involves proactively investigating security posture, risks, and controls before a merger, acquisition, or vendor engagement.
Question 2: Which US law requires publicly traded companies to maintain accurate financial records and internal controls, with CISOs often accountable for IT controls?
- GLBA
- SOX (Sarbanes-Oxley Act) (Correct answer)
- FISMA
- COPPA
Correct answer: SOX (Sarbanes-Oxley Act)
SOX Section 404 requires management to assess internal controls over financial reporting, which heavily involves IT systems and access controls.
Question 3: Under the EU GDPR, what is the maximum fine for the most serious violations?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 5% of global annual turnover
- $100 million flat fine
Correct answer: €20 million or 4% of global annual turnover
GDPR's highest tier penalty is €20 million or 4% of global annual turnover, whichever is higher, for severe violations.
Question 4: What is the main purpose of a privacy impact assessment (PIA)?
- To document all data breaches over the past year
- To identify and mitigate privacy risks before deploying new systems or processes (Correct answer)
- To verify compliance with PCI DSS requirements
- To classify all data assets by sensitivity level
Correct answer: To identify and mitigate privacy risks before deploying new systems or processes
A PIA proactively identifies privacy risks in new projects and recommends controls before the system is built or deployed.
Question 5: Which regulation governs the security and privacy of student education records in the US?
- HIPAA
- COPPA
- FERPA (Correct answer)
- GLBA
Correct answer: FERPA
The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records and grants parents/students access rights.
Question 6: What is the primary purpose of intellectual property (IP) law in information security?
- To protect organizations from data breaches
- To grant exclusive rights over creative works and inventions, protecting them from unauthorized use (Correct answer)
- To regulate how organizations collect customer data
- To establish criminal penalties for hacking
Correct answer: To grant exclusive rights over creative works and inventions, protecting them from unauthorized use
IP law (including copyright, patents, and trade secrets) protects ownership rights over software, inventions, and proprietary information.
What does the term 'due diligence' mean in the context of information security governance?