Cybersecurity Regulations & Legal Frameworks Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity Regulations & Legal Frameworks flashcards as text
Under HIPAA, which entity is directly required to comply with the Security Rule?
Answer: Covered entities and their business associates
HIPAA's Security Rule applies to covered entities (healthcare providers, health plans, clearinghouses) and business associates who handle protected health information on their behalf.
Which law establishes the federal framework for protecting consumer financial information and requires financial institutions to implement safeguards?
Answer: Gramm-Leach-Bliley Act (GLBA)
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices and protect sensitive consumer data.
GDPR's 'right to erasure' (right to be forgotten) allows individuals to request deletion of their personal data EXCEPT when:
Answer: Processing is necessary for compliance with a legal obligation
GDPR permits refusal of erasure requests when processing is required to comply with a legal obligation under EU or member state law.
Which federal agency enforces Section 5 of the FTC Act against unfair or deceptive cybersecurity practices by companies?
Answer: Federal Trade Commission
The FTC enforces Section 5 of the FTC Act, which prohibits unfair or deceptive practices including failing to implement reasonable data security measures.
Under the Cybersecurity Information Sharing Act (CISA 2015), sharing cyber threat indicators with the federal government grants organizations:
Answer: Certain antitrust and liability protections with privacy scrubbing requirements
CISA 2015 provides liability protections for private entities sharing cyber threat indicators, but requires scrubbing personally identifiable information before sharing.
New York's SHIELD Act primarily expands which existing state law?
Answer: New York data breach notification law
The SHIELD Act expanded New York's data breach notification law by broadening the definition of private information and adding reasonable cybersecurity requirements.
Which international framework is specifically designed to address cybersecurity for industrial control systems (ICS) and critical infrastructure?
Answer: IEC 62443
IEC 62443 is the international standard series specifically addressing cybersecurity for industrial automation and control systems (IACS).