CRP Regulatory Compliance & Standards 3 — Questions and Answers
Question 1: A healthcare organization operating in the US must notify affected individuals of a PHI breach within how many days under HIPAA's Breach Notification Rule?
- 30 days
- 45 days
- 60 days (Correct answer)
- 90 days
Correct answer: 60 days
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals within 60 calendar days of discovering a breach of unsecured PHI.
Question 2: Which standard specifically addresses the recovery of IT systems and data and is most closely aligned with BCMS requirements under ISO 22301?
- ISO/IEC 27031 (Correct answer)
- ISO/IEC 27001
- ISO/IEC 20000-1
- ISO/IEC 27005
Correct answer: ISO/IEC 27031
ISO/IEC 27031 provides guidelines on concepts and principles for information and communication technology readiness for business continuity, directly complementing ISO 22301.
Question 3: Under NERC CIP standards, a 'high impact' bulk electric system (BES) cyber system must implement which control that 'medium impact' systems may not be required to have?
- Electronic Security Perimeters (ESP)
- Physical Security Perimeters (PSP)
- Transient Cyber Asset management
- Multi-factor authentication (MFA) for interactive remote access (Correct answer)
Correct answer: Multi-factor authentication (MFA) for interactive remote access
NERC CIP-006 and CIP-007 impose additional controls on high-impact BES cyber systems, including mandatory MFA for interactive remote access, which is not required for all medium-impact systems.
Question 4: The Payment Card Industry Data Security Standard (PCI DSS) requires penetration testing to be conducted at minimum how frequently?
- Every 6 months
- Annually and after significant infrastructure changes (Correct answer)
- Every 2 years
- Quarterly
Correct answer: Annually and after significant infrastructure changes
PCI DSS Requirement 11.4 mandates penetration testing at least annually and after any significant infrastructure or application upgrades or modifications.
Question 5: A multinational corporation discovers that its BCM program complies with ISO 22301 but not with a new national regulation in one country where it operates. What is the BEST approach?
- Apply for an exemption from the national regulation based on ISO 22301 certification
- Conduct a jurisdiction-specific gap analysis and develop localized compliance controls (Correct answer)
- Rely on the parent company's headquarters jurisdiction law to supersede local regulations
- Withdraw operations from the non-compliant country until regulations are aligned
Correct answer: Conduct a jurisdiction-specific gap analysis and develop localized compliance controls
When international standards and local regulations diverge, the best practice is a jurisdiction-specific gap analysis followed by targeted controls to meet local requirements without abandoning the overarching standard.
Question 6: Which element of the US National Preparedness System is most directly relevant to private sector organizations developing regulatory-compliant resilience programs?
- National Incident Management System (NIMS)
- National Response Framework (NRF)
- National Infrastructure Protection Plan (NIPP) (Correct answer)
- Emergency Support Functions (ESFs)
Correct answer: National Infrastructure Protection Plan (NIPP)
The NIPP provides the framework for how the public and private sectors work together to manage risks to critical infrastructure, directly guiding private sector resilience and compliance programs.
Question 7: In ISO 22301:2019, what does the term 'interested parties' refer to in the context of understanding the organization's context?
- Shareholders and investors only
- Individuals or organizations that can affect, be affected by, or perceive themselves to be affected by the BCMS (Correct answer)
- Government regulators who audit the organization
- Customers who have signed service level agreements
Correct answer: Individuals or organizations that can affect, be affected by, or perceive themselves to be affected by the BCMS
ISO 22301:2019 defines interested parties (stakeholders) broadly as any individual or organization that can affect, be affected by, or perceive themselves affected by the BCMS, requiring their needs and expectations to be understood.
A healthcare organization operating in the US must notify affected individuals of a PHI breach within how many days under HIPAA's Breach Notification Rule?