CRP Regulatory Compliance & Standards 2 — Questions and Answers
Question 1: Which NIST publication provides the framework most commonly used for cybersecurity risk management in US critical infrastructure?
- NIST SP 800-53
- NIST Cybersecurity Framework (CSF) (Correct answer)
- NIST SP 800-137
- NIST SP 800-34
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) was specifically developed to help critical infrastructure organizations manage cybersecurity risk using a voluntary, risk-based approach.
Question 2: Under HIPAA's Security Rule, which of the following is classified as an 'addressable' implementation specification rather than a 'required' one?
- Assigning a security official
- Workforce training on security policies (Correct answer)
- Implementing audit controls
- Conducting a risk analysis
Correct answer: Workforce training on security policies
Workforce security training is an addressable specification, meaning organizations must assess whether it is reasonable and appropriate, whereas risk analysis and audit controls are required.
Question 3: The Sarbanes-Oxley Act (SOX) Section 404 primarily requires publicly traded companies to do which of the following?
- Maintain offsite data backups for 7 years
- Assess and report on the effectiveness of internal controls over financial reporting (Correct answer)
- Encrypt all financial data at rest
- Test business continuity plans annually
Correct answer: Assess and report on the effectiveness of internal controls over financial reporting
SOX Section 404 mandates that management and external auditors assess and report on the effectiveness of internal controls over financial reporting.
Question 4: ISO 22313 serves what role in relation to ISO 22301?
- It replaces ISO 22301 for small organizations
- It provides guidance and interpretation for implementing ISO 22301 (Correct answer)
- It certifies auditors who assess ISO 22301 compliance
- It defines terminology only for ISO 22301
Correct answer: It provides guidance and interpretation for implementing ISO 22301
ISO 22313 is the guidance document that supports ISO 22301 by explaining its requirements and providing best practice advice for implementing a BCMS.
Question 5: Which US federal regulation specifically governs business continuity and disaster recovery planning for federally regulated financial institutions?
- FFIEC Business Continuity Management Booklet
- FDIC Rule 12 CFR Part 364
- OCC Bulletin 2019-52
- All of the above represent applicable guidance (Correct answer)
Correct answer: All of the above represent applicable guidance
Federally regulated financial institutions are subject to multiple overlapping guidelines including FFIEC booklets, FDIC rules, and OCC bulletins that collectively govern BCM programs.
Question 6: In the context of the EU's DORA (Digital Operational Resilience Act), which financial entities are primarily subject to its requirements?
- Only banks with assets exceeding €10 billion
- A broad range of financial entities including banks, insurance firms, and ICT third-party service providers (Correct answer)
- Only systemically important financial institutions (SIFIs)
- Only fintech startups operating across EU member states
Correct answer: A broad range of financial entities including banks, insurance firms, and ICT third-party service providers
DORA applies broadly to financial entities such as banks, insurance companies, investment firms, crypto-asset service providers, and their critical ICT third-party providers.
Question 7: What is the primary purpose of a compliance gap analysis in a business continuity program?
- To identify differences between current BCM practices and required regulatory or standards-based requirements (Correct answer)
- To calculate the financial penalties for non-compliance
- To assign accountability for compliance failures to specific employees
- To document all historical compliance violations for regulators
Correct answer: To identify differences between current BCM practices and required regulatory or standards-based requirements
A compliance gap analysis compares existing BCM program elements against applicable regulations or standards to identify deficiencies that must be remediated.
Which NIST publication provides the framework most commonly used for cybersecurity risk management in US critical infrastructure?