Cybersecurity Regulations & Legal Frameworks Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cybersecurity Regulations & Legal Frameworks flashcards as text
An organization subject to NERC CIP standards must complete a risk-based assessment to determine which cyber assets are classified as:
Answer: Bulk Electric System (BES) Cyber Systems
NERC CIP requires organizations to identify and classify Bulk Electric System (BES) Cyber Systems based on their impact on reliable operation of the bulk electric system.
The EU NIS2 Directive expanded cybersecurity requirements compared to NIS1 by:
Answer: Expanding scope to more sectors and increasing penalties up to €10 million or 2% of global turnover
NIS2 significantly expanded the original directive by covering more sectors, strengthening requirements, and increasing penalties to up to €10 million or 2% of global annual turnover.
Which provision of the Sarbanes-Oxley Act prohibits the destruction or alteration of records that may be relevant to a federal investigation?
Answer: Section 802
SOX Section 802 criminalizes the knowing destruction, alteration, or falsification of records with intent to impede or obstruct a federal investigation.
Under FERPA, which category of records may schools disclose without student consent?
Answer: Directory information, unless the student opts out
FERPA allows schools to disclose directory information (name, address, phone number, etc.) without consent unless the student has exercised their opt-out right.
The Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 requires defense contractors to:
Answer: Implement NIST SP 800-171 controls and report cyber incidents within 72 hours
DFARS 252.204-7012 requires contractors handling Controlled Unclassified Information (CUI) to implement NIST SP 800-171 and report cyber incidents to DoD within 72 hours.
Which legal theory holds organizations liable for cybersecurity failures when they knew or should have known about a vulnerability but failed to address it?
Answer: Negligence
Negligence theory applies when an organization fails to meet a reasonable duty of care — including addressing known security vulnerabilities — resulting in harm.
FedRAMP authorization requires cloud service providers to be authorized at which level BEFORE federal agencies can use their services?
Answer: Impact levels: Low, Moderate, or High based on data sensitivity
FedRAMP uses three impact levels (Low, Moderate, High) based on FIPS 199 categorization, and CSPs must achieve authorization at the appropriate level for the data they handle.