← All Cloud Engineer Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. A cloud engineer is designing a system for a bank. Which compliance framework specifically addresses IT controls for financial institutions in the US?

    Answer: SOX (Sarbanes-Oxley Act)

    SOX requires publicly traded companies, including banks, to implement strong IT controls around financial reporting and data integrity.

  2. Which NIST framework provides a risk-based approach to managing cybersecurity risk across an organization?

    Answer: NIST Cybersecurity Framework (CSF)

    The NIST Cybersecurity Framework (CSF) provides five core functions—Identify, Protect, Detect, Respond, Recover—as a flexible, risk-based approach to cybersecurity.

  3. In cloud compliance, what is the primary purpose of a Business Associate Agreement (BAA)?

    Answer: To define HIPAA responsibilities between a covered entity and cloud provider

    A BAA is a HIPAA-required contract between a covered entity and a business associate that outlines each party's responsibilities for protecting PHI.

  4. Under GDPR, what is the maximum time frame for notifying supervisory authorities of a personal data breach?

    Answer: 72 hours

    GDPR Article 33 requires that data controllers notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it.

  5. Which cloud compliance concept refers to the division of compliance responsibilities between a cloud provider and its customer?

    Answer: Shared Responsibility Model

    The Shared Responsibility Model defines which security and compliance obligations belong to the cloud provider versus the customer, varying by service type (IaaS, PaaS, SaaS).

  6. An organization processes data from children under 13 in the US. Which regulation governs their online data collection practices?

    Answer: COPPA

    COPPA (Children's Online Privacy Protection Act) requires parental consent before collecting personal information from children under 13 in the US.

  7. Which ISO standard is specifically focused on information security management systems (ISMS)?

    Answer: ISO 27001

    ISO 27001 is the internationally recognized standard for establishing, implementing, maintaining, and continually improving an ISMS.