Cybersecurity Regulations & Legal Frameworks Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity Regulations & Legal Frameworks flashcards as text
Under GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing:
Answer: Data that is likely to result in high risk to individuals' rights and freedoms
GDPR Article 35 requires a DPIA when processing is likely to result in high risk to the rights and freedoms of natural persons, particularly for large-scale processing or systematic monitoring.
The SEC's cybersecurity disclosure rules (effective 2023) require public companies to disclose material cybersecurity incidents within:
Answer: 4 business days of determining materiality
The SEC's 2023 rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining the incident is material.
Which act created the Cybersecurity and Infrastructure Security Agency (CISA) as an independent agency within DHS?
Answer: CISA Act of 2018
The Cybersecurity and Infrastructure Security Agency Act of 2018 elevated the NPPD to create CISA as a standalone operational component within DHS.
Under COPPA, operators of websites directed to children under 13 must obtain verifiable parental consent before:
Answer: Collecting, using, or disclosing personal information from children
COPPA requires verifiable parental consent before collecting, using, or disclosing personal information from children under 13, with limited exceptions for certain types of internal operations.
A company experiences a breach affecting 600 California residents' unencrypted SSNs. Under California law, the company must notify affected individuals:
Answer: In the most expedient time possible and without unreasonable delay
California's data breach notification law (Civil Code 1798.82) requires notification in the most expedient time possible and without unreasonable delay following discovery.
Executive Order 14028 ('Improving the Nation's Cybersecurity') directed federal agencies to adopt which security model for their networks?
Answer: Zero Trust Architecture
EO 14028, issued in May 2021, directed federal agencies to develop plans to implement Zero Trust Architecture as a core security model.
Under the Stored Communications Act (SCA), law enforcement generally requires which legal process to compel disclosure of stored electronic communications content from a provider?
Answer: A search warrant based on probable cause
For content of stored electronic communications, the SCA generally requires law enforcement to obtain a search warrant supported by probable cause, especially for communications stored 180 days or less.