CISSP Legal and Compliance Flashcards
6 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CISSP Legal and Compliance flashcards as text
Which US federal law established privacy rights and restrictions on the collection of personal data by federal agencies?
Answer: The Privacy Act of 1974
The Privacy Act of 1974 governs how US federal agencies collect, maintain, use, and disseminate personally identifiable information.
Under HIPAA, what term describes organizations that handle protected health information on behalf of a covered entity?
Answer: Business associate
A business associate is a third party that creates, receives, maintains, or transmits PHI on behalf of a HIPAA-covered entity.
What is the primary goal of the Gramm-Leach-Bliley Act (GLBA) in the context of information security?
Answer: To protect the personal financial information of consumers held by financial institutions
GLBA requires financial institutions to explain how they share and protect customers' private financial information.
Which legal concept determines which country's laws apply when a crime involves actors or systems in multiple jurisdictions?
Answer: Jurisdiction
Jurisdiction defines the legal authority of a court or government to hear cases and enforce laws, which becomes complex in cross-border cybercrime.
What type of law in the US covers crimes committed against computer systems or using computer systems?
Answer: Computer crime law (e.g., CFAA)
The Computer Fraud and Abuse Act (CFAA) is the primary US federal statute criminalizing unauthorized access to computer systems.
Which principle requires organizations to retain data only as long as necessary for its intended purpose?
Answer: Data minimization
Data minimization limits collection and retention to what is strictly necessary, reducing risk and compliance exposure.